HackerOne has announced the integration of Anthropic's Claude Mythos into its H1 Platform for selected products, aiming to enhance security through the use of cutting-edge cyber artificial intelligence (AI). This integration will be featured in H1 Code Security Audit and H1 Code, enabling advanced vulnerability management processes that connect the discovery, validation, prioritisation, and remediation phases.
The cybersecurity landscape is seeing a rapid increase in the speed of identifying potential threats, though there remains a significant delay in validation and remediation actions. According to HackerOne, the average time to remediate critical vulnerabilities on their H1 Platform has improved by over 50% in the past year. Despite this progress, unresolved critical vulnerabilities have grown 29-fold during the same timeframe, illustrating the widening gap that frontier AI can both help and exacerbate.
Enhancing existing processes
Through this integration, the H1 Platform aims to provide an efficient way to validate and prioritise discovered vulnerabilities within existing engineering workflows.
The use of Mythos will facilitate improved coverage and validation of model outputs, with an emphasis on integrating actionable insights directly into the workflows. Nidhi Aggarwal, Chief Product Officer at HackerOne, highlighted the importance of the platform's harness, stating, "Frontier cyber AI models can do one of two things to a security team. It can hand them a longer list, or it can hand them a list they can act on."
Advanced vulnerability discovery
H1 Code Security Audit will leverage Claude Mythos to thoroughly scan code repositories
H1 Code Security Audit will leverage Claude Mythos to thoroughly scan code repositories, bringing to light complex vulnerabilities that may include extended compositional vulnerabilities across years of code commits.
Furthermore, H1 Code will enhance the review of pull requests, ensuring comprehensive threat detection. Kara Sprague, Chief Executive Officer at HackerOne, emphasised the importance of advanced models in defending against AI-driven attacks, stating, "Finding vulnerabilities faster matters only if organisations can validate, prioritise, and act on them."
Complementary approach to security
HackerOne stresses the importance of having multiple layers of security, combining the capabilities of frontier cyber AI with the skills and experience of human security researchers. This collaboration is intended to cover complex attack chains and provide real-world contextual insights. Additionally, HackerOne has made it clear that it does not use confidential researcher submissions or customer vulnerability data to develop or enhance its AI models.
The selected H1 Platform offerings will soon be available with the Mythos integration. Users interested in HackerOne's experiences with Mythos as part of Project Glasswing or in learning more about the H1 Platform can find further information on their official website.
HackerOne, a global pioneer in Continuous Threat Exposure Management (CTEM), announces the upcoming integration of Anthropic’s Claude Mythos across select H1 Platform products: H1 Code Security Audit and H1 Code. The integration will make frontier cyber AI available in existing security workflows, connecting agentic vulnerability discovery with validation, prioritisation, and remediation.
Enterprises are identifying possible exposures faster than ever, yet falling further behind on validating true exposure and making fixes. Frontier AI is widening that gap in both directions. According to H1 Platform data, critical vulnerability mean time to remediate (MTTR) improved by more than 50% over the past 12 months.
Existing engineering workflows
Over the same period, the unresolved critical backlog grew 29x. As frontier cyber AI increases the speed and depth of discovery, organisations need a scalable way to validate and prioritise what it finds. The H1 Platform harness will be available with Mythos through discovery of source code vulnerabilities with controls designed to improve coverage, validate model outputs, and bring validated exposures into existing engineering workflows.
"Frontier cyber AI models can do one of two things to a security team," said Nidhi Aggarwal, Chief Product Officer at HackerOne. "It can hand them a longer list, or it can hand them a list they can act on. Which one depends entirely on what sits between the model and the security team. A harness helps turn model output into a validated exposure a security team can act on. We ran and validated the H1 Platform harness for ourselves before any customer saw it."
Surface complex vulnerabilities
On the discovery side, H1 Code Security Audit scans full repositories to surface complex vulnerabilities, including compositional vulnerabilities that can span years of commits and multiple authors, and H1 Code reviews pull requests.
“Attackers are already using frontier AI to find and exploit vulnerabilities faster than humans alone can respond,” said Kara Sprague, Chief Executive Officer at HackerOne. “Defenders need access to advanced cyber-capable models, with people accountable for the decisions those models inform and the actions those models take. Finding vulnerabilities faster matters only if organisations can validate, prioritise, and act on them.”
Complementary layers of continuous security
Frontier cyber AI is one layer of coverage. An elite community of security researchers provides another, bringing creativity, contextual understanding, and real-world adversarial expertise to complex attack chains, business logic flaws, and novel exploitation paths. Together, frontier cyber AI and human expertise provide complementary layers of continuous security.
HackerOne does not use or permit use of confidential researcher submissions or customer vulnerability data to train, fine-tune, or otherwise improve generative AI models. The select H1 Platform offerings will soon be available with Mythos. Users can also read more about what HackerOne found running Mythos on its systems as part of Project Glasswing and learn more about the H1 Platform.