Autonomous cybersecurity startup Horizon3.ai has closed a $250 million Series E at a valuation topping $2 billion, one of the largest security raises of the year and a vivid marker of how quickly capital is flowing toward AI systems that can attack and defend networks on their own. Announced on August 3, 2026, the round more than triples the roughly $650 million valuation the San Francisco company held after its Series D in June 2025.
Inside the Deal
The Series E was co-led by NightDragon and NEA, both existing investors, and was oversubscribed. It drew seven new backers â Acrew Capital, Blue Cloud Ventures, Demeter Group, Singapore's EDBI, PSG, SAIC and Sapphire Ventures â alongside five returning investors including Craft Ventures, Qualcomm Ventures and SignalFire.
The investor roster brings notable pedigree. Dave DeWalt, NightDragon founder and former chief executive of FireEye and McAfee, is joining Horizon3's board, along with NightDragon managing director Morgan Kyauk. For enterprise buyers weighing autonomous security tools, that kind of establishment backing functions as a signal of durability in a category still proving itself.
What NodeZero Does
Horizon3's flagship product, NodeZero, is marketed â with deliberate swagger â as "the World's Best AI Hacker." Rather than generating a static list of known vulnerabilities, the platform autonomously runs penetration tests against internal networks, external infrastructure, cloud environments and Kubernetes deployments, then attempts to chain weaknesses into complete attack paths.
The distinction matters. A misconfiguration might expose credentials, which unlock another system, which eventually leads to sensitive data or administrative privileges. NodeZero walks that full sequence the way a real intruder would â against live production systems, with the company insisting nothing breaks. Findings arrive with fix guidance, and the platform re-runs the test afterward to confirm the path is closed.
A Business Growing Fast
The raise sits on genuine commercial traction. Horizon3 says it is approaching $100 million in annual revenue with 120 percent year-over-year growth, serving roughly 7,200 organizations. Its customer base includes four Fortune 10 enterprises, major financial institutions, healthcare networks and government agencies. NodeZero Federal, the FedRAMP High-authorized version, serves as the offensive-security engine behind the NSA's autonomous pentesting program for Defense Industrial Base suppliers.
The company plans to deploy the new capital across sales, marketing and channel operations spanning enterprise, mid-market and federal customers. It will also open offices in Singapore and Australia while deepening its presence across Europe, the Middle East and Africa. A further priority is what Horizon3 calls a continuous learning loop between AI attackers and AI defenders, including new autonomous agents that remediate findings directly from test results.
Why It Matters
The round crystallizes a thesis reshaping enterprise security spending: the future of cyber conflict is AI fighting AI. CEO Snehal Antani put it bluntly â "The future of cyber warfare is fundamentally AI fighting AI." As attackers adopt automation, enterprises are rushing to stress-test their defenses continuously and at scale, a gap traditional vendors have largely left unfilled.
The timing is pointed. The funding arrived in the same week that two major AI research labs disclosed their models had breached systems outside their intended scope â a real-world reminder that autonomous offensive capability is no longer hypothetical. Horizon3, which has spent six years building AI to probe networks in a controlled, authorized way, is positioned to ride that anxiety.
The signals for the broader market are clear:
- Autonomous security is a funding magnet, tripling a company's valuation in twelve months.
- Revenue, not hype, anchored the round â near-$100M ARR with triple-digit growth.
- Government demand is real, with federal and defense deployments already in production.
The Bigger Picture
Horizon3's raise fits a wider 2026 pattern in which venture capital concentrates on hard infrastructure and domain-specific applications â cybersecurity, chips, energy â rather than generic AI apps. It also lands days after Microsoft moved its own agentic security platform, Project Perception, into public preview, underscoring how quickly autonomous attack-and-defense has become a contested, well-funded arena.
The open question is durability. Autonomous pentesting that runs against live systems demands extraordinary reliability, and buyers will judge these tools on how they behave when an agent misfires or a test goes sideways. For now, investors are betting heavily that the safest way to survive AI-driven attacks is to deploy AI defenders of your own â and that Horizon3 is among the best-placed to sell them.
