HackerOne has introduced h1 Validation, a new tool aimed at helping companies navigate the rising challenges posed by vulnerabilities identified by advanced AI technologies.
This addition from the Continuous Threat Exposure Management (CTEM) firm addresses the widening gap between the discovery of these vulnerabilities and their subsequent resolution, an issue that intensifies as AI systems like Claude Mythos and OpenAI's GPT-5.4-Cyber enhance the speed and scale of vulnerability detection. Meanwhile, adversaries are exploiting these gaps at an accelerated pace.
High-Severity Vulnerabilities
Data from the HackerOne platform indicates a significant increase in vulnerability submissions, with a 76% year-over-year rise, culminating in a peak in March 2026. Approximately 25% of these findings have been verified as exploitable, a consistent rate despite the overall increase in submissions, reflecting a sustained rise in absolute vulnerability numbers.
The incidence of critical and high-severity vulnerabilities has escalated to 32%, compared to a historical average of 26-28%. Concurrently, the timeframe between disclosure and exploitation is narrowing rapidly, now a matter of hours, outpacing the annual remediation improvement rate of just 19% and leading to unprecedented vulnerability backlogs.
Measurable Risk Reduction
The h1 Validation service is specifically designed for managing large volumes of vulnerabilities
“AI is accelerating both the volume and the sophistication of vulnerabilities,” noted Nidhi Aggarwal, Chief Product Officer at HackerOne.
“AI is increasingly exploiting complex attack paths and multi-step chains, and the time to exploit them is shrinking. h1 Validation helps organizations keep up by combining agentic AI and human expertise to quickly determine what is actually exploitable, deliver clear remediation steps, and reduce the time from find to fix.”
The h1 Validation service is specifically designed for managing large volumes of vulnerabilities and handling complex attack vectors at scale. By swiftly assessing exploitability and focusing on genuine threats, this tool aids security and engineering teams in responding more efficiently to potential adversarial exploits. As artificial intelligence advances both the identification of vulnerabilities and the capabilities of adversaries, organizations are urged to progress beyond mere discovery towards continuous validation and remediation. h1 Validation aims to bridge this gap by enhancing the cycle from discovery through to validation and fixing, effectively transforming increasing volumes into prompt, measurable decreases in risk.
