
Horizon3 has raised $250 million at a valuation of more than $2 billion, a sign that cybersecurity buyers are moving faster toward tools that can test their defences before attackers do it for them.
The San Francisco company announced the Series E in an official release, saying the round was co-led by NightDragon and NEA. The company says its valuation has tripled from $650 million at its Series D just over a year ago, and that it now has more than 7,000 customers and 120 percent annual recurring revenue growth.
Horizon3 is best known for NodeZero, its autonomous penetration-testing platform. The idea is simple enough: instead of waiting for an annual manual assessment, companies can continuously test real attack paths across their networks, cloud systems and identity environments. In practice, that is becoming more important because AI is making both attackers and defenders faster.
This is why the funding round feels well-timed. Over the last two weeks, AI security has moved from a specialist topic into mainstream tech news. OpenAI disclosed that a test model breached Hugging Face during a cyber evaluation, and Anthropic later said Claude models accessed real systems during cyber tests. Those incidents were not ordinary customer attacks, but they showed how quickly tool-using AI can become dangerous when boundaries fail.
Enterprise security teams are also dealing with a more ordinary but equally serious problem. They have too many vulnerabilities, too many alerts and too few people who can decide what actually matters. A tool that can show a real exploit chain, not just a theoretical weakness, helps security leaders prioritize what would hurt the business most.
That is the attraction of AI-driven pentesting. It turns security from a checklist into a more active exercise. If a platform can safely simulate how an attacker would move from one exposed system to another, companies get a clearer picture of risk. Banks, hospitals, public agencies and large enterprises increasingly need that evidence for boards, insurers and regulators.
There is a wider market signal too. We recently wrote about Mirage Kitten malware targeting Middle East and African networks, and the lesson is the same: cyber risk is no longer seasonal. It is continuous. The companies that can prove they are testing continuously will look more prepared than those relying on static audits.
The caution is that autonomous security tools also need strong guardrails. Testing production environments can be valuable, but it must not become careless. The same industry that wants AI to find attack paths faster must also prove that AI tools will not create new disruption while trying to help.
For Horizon3, the new money gives it room to grow internationally, invest in research and development and sell into bigger regulated industries. For the wider market, the round says something bigger. AI security is no longer just about stopping AI-generated phishing emails. It is becoming a race between automated attackers and automated defenders, and penetration testing is moving closer to the centre of that race.







