Horizon3 Собирает 250 миллионов долларов, поскольку Следующая война в сфере кибербезопасности идет между искусственным интеллектом и ИИ

03.08.2026

Компания по кибербезопасности Horizon3 привлекла 250 миллионов долларов для финансирования серии E, увеличив свою оценку более чем на 2 миллиарда долларов, исходя из того, что атаки, управляемые искусственным интеллектом, ускоряются быстрее, чем защита человека. Компания выступает за будущее, в котором "искусственный интеллект борется с искусственным интеллектом", когда автономные системы управляют всем циклом атаки и защиты. Платформа NodeZero выполняет автономное тестирование на проникновение, безопасно работая в реальных производственных средах крупных организаций, таких как банки и больницы. Генеральный директор Снехал Антани подчеркивает, что их уникальные собственные данные об обучении, собранные с брандмауэров клиентов, являются важным преимуществом по сравнению с использованием стандартных моделей ИИ. Horizon3 планирует глобальную экспансию и разработку автономных агентов blue-team для исправления ошибок, создавая циклы обучения ИИ между атакующими и защитниками. Эта стратегия направлена на удовлетворение насущной потребности в быстродействии в сфере кибербезопасности, где атаки, управляемые ИИ, часто опережают реакцию человека. Рост компании зависит от укрепления доверия к ИИ для безопасной работы в чувствительных системах.

Когда в прошлом году Horizon3 сообщила, что ее автономный искусственный интеллект взломал банк за 77 секунд во время выступления Black Hat с Агентством национальной безопасности, генеральный директор Снехал Антани заявил, что результат отражает то, что, по его мнению, является следующим переломным моментом в кибербезопасности: атаки ускоряются быстрее, чем организации могут реально реагировать.

Эта идея в настоящее время привлекает серьезных инвесторов.

Компания, занимающаяся кибербезопасностью, базирующаяся в Сан-Франциско, привлекла 250 миллионов долларов для финансирования серии E, стоимость которой превышает 2 миллиарда долларов, что более чем в три раза больше, чем примерно 650 миллионов долларов чуть более года назад. Раунд с избыточной подпиской, проводимый совместно NightDragon и NEA, сопровождается ежегодным ростом выручки на 120%, а клиентская база превышает 6500 организаций, включая NSA, CISA и четыре предприятия из списка Fortune 10. Основатель NightDragon Дэйв Деволт, который руководил McAfee и сделал FireEye публичным, входит в совет директоров.

Компания считает, что вместо того, чтобы рассматривать искусственный интеллект как инструмент повышения производительности для служб безопасности, автономные системы будут участвовать в каждом этапе цикла атаки и защиты, начиная с поиска уязвимых путей и заканчивая их устранением.

"Будущее кибервойн - это, по сути, борьба искусственного интеллекта с искусственным интеллектом, когда люди действуют в порядке исключения, а не контролируют каждое действие напрямую", - сказал мне Антани. "Каждый важный компонент системы кибербезопасности в настоящее время готов к сбою, поскольку скорость атаки резко меняется".

Антани не является типичным основателем ИИ. Инженер, который начинал в IBM, а затем занимал руководящие технические должности в GE Capital и Splunk, он ушел из отрасли, чтобы стать первым техническим директором Объединенного командования специальных операций, где тесно сотрудничал с командой Министерства обороны по проекту Maven в области ИИ. Этот опыт вызвал у него аллергию на серебряные пули. "Не существует какой-то волшебной кнопки с искусственным интеллектом, которая решит все ваши проблемы с безопасностью", - говорит он. "Все дело в освоении основ". Он отмечает, что в каждом плане специальных операций есть "красная ячейка", которая должна атаковать его с точки зрения противника — дисциплина, которую Horizon3 фактически превратил в продукт.

Asked what justified a valuation north of $2 billion, Antani began with a warning rather than a pitch. "It starts with execution," he says, citing 120% revenue growth "at meaningful scale," strong sales efficiency and gross margins he says exceed those of many comparable public companies.

The company’s longer-term advantage, he shared, lies in the proprietary operational data it has amassed by running hundreds of thousands of production penetration tests.

"Every single time our AI hacker runs a penetration test, it's collecting training data that literally nobody else has," Antani said. "It's incredibly high-resolution operational data that's exactly what you need to build the next generation of offensive and defensive cyber algorithms. In many ways, I think of us as a data company."

The Race Between AI Attackers and Defenders

Antani asserts that the same attack that took about 7 minutes and 19 seconds three years ago fell to 4 minutes and 12 seconds last year and now takes 77 seconds. He expects the compression to continue—to as little as 30 seconds—at which point the limiting factor won't be the attack itself but an organization's ability to decide fast enough to contain it. "If your security organization can't detect and stop me within seventy-six seconds, the game is already over," he says. "By second seventy-seven, I've taken full control of your network."

He also shared what he sees as a weakness in today’s AI attackers. Because many models are trained primarily on public vulnerability databases, cyber ranges and platforms such as Hack The Box, they often struggle with the messiness of real enterprise environments. Horizon3’s research claims that human hackers clicked on decoy credentials about 37% of the time, while leading AI models followed the same traps roughly 90% of the time.

Antani expects that gap to narrow as models improve, setting up a cat-and-mouse race between AI attackers and AI-powered defenses. As NodeZero, the company's autonomous penetration testing and security validation platform, assesses customer environments, it can also deploy decoys designed to lure and expose AI-driven intruders already inside a network. "That completely changes the defensive equation," he says. "Deception becomes one of the cheapest, fastest and most effective ways to detect AI-driven attackers."

Why Horizon3 Is Betting on Data Over Models

Horizon3 isn’t entering an empty market. Pentera has spent years automating penetration testing inside enterprise networks, while Picus, AttackIQ and SafeBreach validate whether security controls catch known attack techniques. A newer generation of startups, led by XBOW, applies large language models directly to offensive security, and climbed HackerOne's rankings this year by finding vulnerabilities that once required experienced penetration testers.

The split reflects two assumptions about where offensive AI is heading. The newest entrants start with large language models and ask how autonomous agents can become better hackers. Horizon3 started with production environments and asked a harder question: how do you let autonomous software attack a Fortune 10 company, a hospital or a defense contractor without breaking anything?

"When I was at the Department of Defense working closely with the Project Maven team, one of the biggest lessons we learned was that the models themselves don't matter nearly as much as people think," Antani says. "Models are disposable. New foundation models are going to come out all the time. If you've designed your company around one model, you've already made a strategic mistake."

The durable advantage, he argues, lies in what surrounds the model. "The workflow harness is what actually executes the work," he says. "Then you combine that with proprietary training data. Those are the things that continue creating value regardless of which model happens to be leading the benchmarks."

That philosophy shapes how NodeZero is built. Rather than handing control to a single AI model, the platform combines deterministic attack logic and graph-based reasoning with multiple AI models working in concert. In practice, it behaves the way a human intruder would — stealing credentials, hijacking identities and moving through cloud systems toward whatever matters most — while keeping every action explainable enough for enterprises to trust it inside live environments. Whether the data moat holds is an open question as proprietary data has looked insurmountable before, until foundation models closed the gap.

Production Pentests Matter More Than AI Benchmarks

Horizon3's data advantage exists only because thousands of companies let its software attack the systems they run their businesses on. That is a far higher bar than showing off an AI agent in a lab. NodeZero operates inside live networks at banks, hospitals, defense contractors and logistics providers, and the company says it has conducted more than 300,000 production-safe penetration tests. "We ran more penetration tests last year than the entire history of computing before us," Antani claims, and every engagement feeds a reinforcement-learning loop sharpening the platform's judgment.

He describes building AI that can safely operate inside live enterprise environments as the hardest engineering challenge of his career. The difficulty isn’t identifying an exploitable attack path, rather, it’s knowing when not to pursue one because of the potential operational consequences.

NodeZero weighs whether each action is safe, potentially disruptive or too risky to attempt. "There are certain actions that we simply will not perform because they're reckless," Antani says. "The system is designed to recognize those contextual differences and always bias toward safety rather than aggression." Customers typically start with narrowly scoped deployments before gradually expanding. Trust, he argues, is earned through operational experience rather than marketing.

The platform grew into web application testing this year, and Horizon3 joined Anthropic's Project Glasswing initiative to help secure critical infrastructure. The Series E will fund entry into Singapore and Australia, a deeper push across EMEA and autonomous blue-team agents that remediate vulnerabilities directly from NodeZero's findings—AI attackers identifying the paths that matter, AI defenders validating the fixes.

"We started with pentesting because it was the hardest problem to solve," Antani says. "We've evolved into a proactive security platform, and now we'll accelerate remediation by creating AI learning loops between attackers and defenders."

Autonomous remediation carries obvious risks of its own, as a bad fix can break production. But Antani frames the alternative as worse. "The enemy always has a vote," he says. Attackers probe constantly, and a weakness left untested gets discovered on their timetable, not yours.

That logic extends to one of cybersecurity’s longest-held assumptions that good security means fixing every vulnerability. Antani argues attackers often don't need one—stolen credentials or a single weak password among a thousand employees can be enough—so organizations should assume breach, contain intrusions quickly and reserve urgency for the small number of flaws that are actually exploitable. Whether enterprises, regulators and cyber insurers embrace that shift remains an open question, particularly as autonomous AI moves from testing systems to fixing them.

For now, Horizon3's investors are betting that six years inside live production networks will prove harder to replicate than whichever model leads the benchmarks next year.

>

Читать на сайте источника »