HackerOne - Experts & Thought Leaders
Latest HackerOne news & announcements
HackerOne, a pioneer in Continuous Threat Exposure Management (CTEM), announces the appointment of Naveen Bhateja as Chief People Officer. Bhateja joins the executive leadership team to lead the company's people strategy, leadership development and culture. Bhateja brings more than 25 years of experience building leadership and talent in global technology companies through periods of fast growth and change. At HackerOne, he will focus on developing the company's leaders, deepening its bench and helping employees grow as the business scales, strengthening the foundation beneath everything HackerOne builds for its customers and the researcher community. Strengthened executive capabilities "The pace of change in security has never been higher, and the organizations pulling ahead are the ones that invest as much in their people as they do in their technology," said Kara Sprague, CEO of HackerOne. "Naveen has spent his career guiding high-performing teams through exactly this kind of change. We're building an AI-native company where exceptional people grow together and shape the future of security." Bhateja has held senior people leadership roles at companies including Medidata, Juniper Networks, Amazon and JPMorgan Chase, where he shaped enterprise-wide talent and leadership strategies, organizational effectiveness, and strengthened executive capabilities during periods of significant business growth and change. “I have always believed talent is one of the greatest differentiators between good and great organizations because it unlocks everything else,” said Bhateja. “What drew me to HackerOne is that the company has built something genuinely difficult: a model where AI and human expertise make each other stronger. My role is to help build an AI-native organization that equips our people to move faster, innovate and deliver greater customer impact.”
HackerOne, a global pioneer in Continuous Threat Exposure Management (CTEM), has joined Project Glasswing, Anthropic's controlled-access program for Claude Mythos 5. HackerOne will share what it learns about applying frontier AI to real-world exposure management to advance cyber defense at scale. Consistent with Project Glasswing’s mandate, HackerOne is using Mythos to strengthen its defenses. While doing so, HackerOne will benchmark Mythos’ performance in use cases beyond discovery: confirming exploitability with evidence, prioritising findings by business impact, and generating developer-ready fixes that integrate directly into engineering workflows. Different vantage point “Attackers are already using frontier AI to find and weaponise vulnerabilities faster than defenders can respond. The only viable answer is for defenders to operate on better models, faster. HackerOne's mission is to empower the world to build a safer internet. Anthropic's is safer software at scale. Same goal, different vantage point. Project Glasswing lets us put the most capable model available to work on our infrastructure and share what we learn across the full CTEM workflow," said Kara Sprague, Chief Executive Officer, HackerOne. "Building more resilient software requires continuous innovation in how we identify, understand, and remediate risk," said Nidhi Aggarwal, Chief Product Officer, HackerOne. "We are excited to use Claude Mythos to strengthen the security of our internal systems, explore how frontier AI can strengthen every stage of the CTEM workflow from discovery to remediation, and contribute insights that help the security industry move toward continuous cyber defense." HackerOne's participation in Project Glasswing is scoped exclusively to improve the security of its infrastructure and solutions. Claude Mythos 5 is not being applied to customer programs or external-facing agentic use cases.
HackerOne, a global pioneer in Continuous Threat Exposure Management (CTEM), announces the H1 Platform, an agentic AI platform designed to help enterprises eliminate exploitable risk with continuous discovery, validation, prioritisation and remediation at AI scale. The launch comes as the discovery-remediation gap becomes the defining security problem of the AI era. AI is now writing meaningful portions of enterprise code. Recent surveys indicate 73% of engineering teams now use AI coding tools daily, and AI-powered security tools are surfacing vulnerabilities faster than security teams can validate and remediate them. H1 Platform data shows vulnerability submissions up 92% year over year, with critical and high-severity findings climbing while remediation throughput lags by a wide margin. Remediate exploitable vulnerabilities The H1 Platform addresses this challenge by applying agentic AI capabilities throughout the CTEM lifecycle to validate and remediate exploitable vulnerabilities. Powered by Hai, HackerOne’s agentic AI orchestrator, the platform correlates exploitability signals, remediation intelligence, and observed attack trends to help organizations prioritise high-impact risk. “In a world reshaped by frontier AI models, security can’t afford to be static, theoretical, or siloed. It must be continuous, validated, and tied to business impact,” said Nidhi Aggarwal, Chief Product Officer at HackerOne. “As exploit windows shrink and vulnerability volume accelerates, organizations need security systems that can continuously discover and validate what matters, prioritise action, and operationalise remediation at AI scale to continuously reduce cyber risk.” Finding individual vulnerabilities "The AI era demands a new kind of security platform: agentic, continuous, and operating at the speed of the threat. The H1 Platform closes the discovery-remediation gap that defines this moment, built on the only foundation that could make it work: the simultaneous trust of the Fortune 500 and the world's largest community of security researchers, sustained over more than a decade,” said Kara Sprague, HackerOne’s Chief Executive Officer. “As enterprises move from securing code to securing AI itself, the researcher community's role on this platform will only deepen." Central to the H1 Platform is the global community of security researchers, who bring adversarial depth that no automated system replicates. Where Hai delivers speed and scale, the global community pushes beyond what any model can reach, surfacing business logic flaws, novel attack chains, and adversarial techniques no training set contains. The result is evidence-based exploitability confirmation, not theoretical risk scores. As enterprises move from securing code to securing AI itself, the researcher community's contribution to the platform will continue to expand beyond finding individual vulnerabilities to shaping the intelligence that protects enterprises at AI scale. Continuous exposure management With agentic capabilities built into the H1 Platform, it unifies discovery, validation, prioritisation, and remediation into a single operational system for continuous exposure management. Key platform capabilities include: Continuous agentic testing across the attack surface, with exploitability validation informed by program history and attack-path analysis Agentic prioritisation that ranks vulnerabilities based on exploitability and business impact Integrated remediation workflows across Jira, GitHub, ServiceNow, Azure DevOps, Linear, and dozens of other enterprise integrations Agentic exploitation workflows that generate validated, evidence-backed findings routed directly to developers for immediate remediation Board and CISO-level executive analytics, including Return on Mitigation (RoM) metrics, designed to help organizations quantify exposure reduction, prioritise remediation investments, and concretely measure security outcomes Prioritising remediation investments The H1 Platform supports 1,300 organizations worldwide, including 20% of the Fortune 500 and AI innovators, helping security teams continuously validate and remediate exploitable risk at scale. Across its customer base, HackerOne has helped organizations mitigate more than $32 billion in exposure risk and reduce mean time to remediate (MTTR) by approximately 80%. "We went from a set-and-forget security program to one that actually keeps pace with how fast threats move,” said Scott Brown, Security Lead, KOHO Financial. “Reducing median triage time by roughly 80% has changed everything. Our team focuses on what's confirmed and exploitable, and vulnerabilities get addressed before they become real risk."