HackerOne has introduced h1 Validation, a tool aimed at enhancing Continuous Threat Exposure Management (CTEM) by managing the increasing complexity of vulnerabilities identified by advanced AI models.
With systems such as Claude Mythos and OpenAI’s GPT-5.4-Cyber rapidly advancing the speed and scope of vulnerability discovery, the disparity between identifying and addressing these vulnerabilities is expanding, while cyber adversaries are quick to exploit them.
High-severity vulnerabilities
Recent data from HackerOne reveal a significant increase in vulnerability submissions, which have surged by 76% year over year, peaking in March 2026. Despite the influx, around 25% of these submissions are confirmed exploitable, maintaining its rate.
The overall number of verifiable vulnerabilities is on the rise as a result. Notably, critical and high-severity vulnerabilities now constitute 32% of the total, up from the previous average of 26-28%. The timeframe between disclosure and exploitation is narrowing to just hours, yet the pace of remediation has only improved by 19% annually, leading to unprecedented vulnerability backlogs.
Measurable risk reduction
In an era where AI is enhancing both the discovery process and adversarial strategies
Nidhi Aggarwal, Chief Product Officer at HackerOne, remarked, “AI is accelerating both the volume and the sophistication of vulnerabilities. AI is increasingly exploiting complex attack paths and multi-step chains, and the time to exploit them is shrinking. h1 Validation helps organisations keep up by combining agentic AI and human expertise to quickly determine what is actually exploitable, deliver clear remediation steps, and reduce the time from find to fix.”
The h1 Validation system is tailored to manage this evolving landscape. It processes large numbers of vulnerabilities and complex attack pathways efficiently. By swiftly validating the exploitability of threats and prioritising genuine risks, it assists security and engineering teams in responding more swiftly to vulnerabilities that could be targeted by attackers.
In an era where AI is enhancing both the discovery process and adversarial strategies, it’s crucial for organisations to progress from merely discovering vulnerabilities to embracing continuous validation and remediation. h1 Validation bridges this gap by expediting the ongoing cycle from discovery through validation to remediation, turning an increasing number of vulnerabilities into prompt, quantifiable risk mitigation.
