{
  "id": 12630953,
  "title": "HackerOne Report Surfaces Massive Increase in Vulnerability Backlogs",
  "url": "https://urgent.news/2026/10/07/hackerone-report-surfaces-massive-increase-in-vulnerability-backlogs",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T13:00:18.000Z",
  "source": {
    "name": "DevOps.com",
    "slug": "devops-com",
    "url": "https://devops.com/hackerone-report-surfaces-massive-increase-in-vulnerability-backlogs/"
  },
  "original_language": "en",
  "account": "A recent HackerOne report reveals a staggering surge in the backlog of unresolved vulnerabilities, with the total number of known issues increasing by 131% over the past two years. While the rate of vulnerability resolution has risen by 54% in the last year, the pace of vulnerability discovery has accelerated due to the AI era. Thirty-eight percent of security leaders surveyed report that validated findings are being added to their backlogs faster than they can be remediated.\n\nKara Sprague, CEO of HackerOne, warns that DevSecOps teams are being overwhelmed by this trend. The report suggests that many teams need to adopt AI to better manage vulnerability remediation. As cybercriminals increasingly leverage AI to discover and exploit vulnerabilities, the race against time has become more urgent. In some cases, cybercriminals can create an exploit from a vulnerability in just hours.\n\nThe report highlights the growing challenges posed by AI in application development. System prompt leakage reports have surged by 557%, and output handling issues have risen by 264%. Despite security leaders' efforts to track exposure debt, 85% of security researchers are upskilling using AI, with nearly three-quarters reporting an increase in valid findings. More than two-thirds of researchers are focusing on higher-complexity, higher-bounty bugs, aided by AI.\n\nHackerOne data shows that researchers earned a record $89 million from July 2025 to June 2026 through the platform. In 2025, organizations running bug bounty programs on the H1 Platform awarded $89 million in total, an 18% increase from the previous year. However, a significant challenge remains: many organizations continue to prioritize building new applications and features over reducing application security debt. HackerOne's data indicates that exposure debt has never been higher in the 10 years of their reports.\n\nSprague emphasizes that organizations must devote more resources to remediation, as the trend of accelerating vulnerability discovery is likely to continue, even with AI's assistance. However, she notes that many organizations only revisit their DevSecOps strategies after experiencing a crisis. While the number of discovered vulnerabilities and breaches may not be directly correlated, the report underscores the importance of proactive DevSecOps measures to prevent cybersecurity incidents.",
  "summary": "HackerOne research shows vulnerability remediation is getting faster, but AI-driven discovery is expanding exposure debt even more quickly, putting DevSecOps teams under growing pressure.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}