HackerOne Extends Platform Reach to Remediate Source Code Vulnerabilities
HackerOne has added a remediation capability to its H1 Platform that reduces the amount of time required to remediate validated vulnerabilities and other weaknesses affecting specific lines of source code. Nidhi Aggarwal, chief product officer for HackerOne, said H1 Remediation combines artificial intelligence (AI) and crowdsourced research to identify the root cause of issues that […]
HackerOne has expanded its platform to tackle source code vulnerabilities, introducing a remediation feature that leverages artificial intelligence (AI) and crowdsourced research. This new capability, known as H1 Remediation, aims to pinpoint the root cause of issues traced back to specific lines of code, integrating seamlessly with existing issue tracking tools and AI coding agents via a Model Context Protocol (MCP) server.
The primary objective is to optimize remediation efforts, mitigating the growing exposure debt posed by advanced AI models uncovering more vulnerabilities in code, as stated by Nidhi Aggarwal, HackerOne's chief product officer.
Reports generated by H1 Remediation include root cause analysis, pinpointing the location of risky inputs and the resulting damage, language-specific code changes, business context, and implementation guidance. The platform also offers integrations with DevOps tools like Jira, Linear, and Confluence to provide incident histories and asset information, enhancing the overall visibility into remediation progress.
Additionally, a dashboard enables tracking of resolution rates, mean time to remediate by severity, findings flow, and trends in exposure backlog, including peer benchmarking and year-over-year comparisons.
Traditionally, application development teams spend considerable time validating vulnerabilities reported by cybersecurity teams, often leading to frustration and wasted efforts when the affected code is not externally accessible or not loaded into memory. AI tools have expedited vulnerability discovery, but this advance has coincided with a surge in false positives in code, according to Aggarwal.
H1 Remediation addresses this challenge by providing video examples of how specific lines of source code can be exploited, with plans to also offer examples of exploitation within a Docker container, enabling application developers to observe and understand potential threats.
With these insights, teams can more easily either patch the code or develop a kill chain to mitigate the threat using HackerOne's continuous threat exposure management (CTEM) platform. While it's unclear how rapidly cybercriminals are now exploiting vulnerabilities in production environments, it is confirmed that AI-assisted exploitation can occur within a day.
In many cases, the creation of an exploit now outpaces the patching process needed to fix the vulnerability, placing DevSecOps teams in a race against time to become more proactive in discovering and remediating vulnerabilities. As application security evolves, the traditional approach of waiting for vulnerabilities to be discovered by cybersecurity teams is being replaced by a more proactive stance.
The ultimate question remains: how long can organizations persist in this new reality before facing a wave of increasingly lethal cyberattacks?
Written by urgent.news from DevOps.com's reporting — not their text. Machine-written; read the original for the full account.




