

An analysis of the backlog of vulnerabilities published today by HackerOne finds that while the rate at which issues are being resolved has increased 54% in the past year there has also been a 131% over the last two years in the total number of known validated issues that have not been resolved.
On average, organizations have cut average resolution time from 135 days to 62 days, but the pace at which vulnerabilities are being discovered in the artificial intelligence (AI) era continues to increase. In fact, a separate survey of 111 security leaders finds 70% are seeing validated findings being added to their backlogs faster than they are being remediated.
HackerOne CEO Kara Sprague said that as researchers make use of AI to discover vulnerabilities, it’s apparent that DevSecOps teams are starting to be overwhelmed. As a result, it’s clear that many of those teams now need to start applying AI to remediate vulnerabilities faster by, for example, formally addressing best vulnerability operations (VulnOps) practices, she added.
It’s not clear at what rate DevSecOps teams are embracing AI to reduce exposure debt, but as cybercriminals become more adept at using AI to discover and exploit vulnerabilities, it is now a race against time. In many instances, it is now possible for cybercriminals to create an exploit by reverse engineering a vulnerability in a matter of hours. Historically, DevSecOps teams have counted on the fact that they typically had a few months between when a vulnerability was first disclosed and an exploit might actually manifest.
More challenging still, as application developers embrace AI to write code, DevSecOps teams are also contending with emerging issues such as a 557% increase in system prompt leakage reports and a 264% increase in output handling, according to the HackerOne analysis.
On the plus side, three-quarters (75%) of security leaders report their organization now formally tracks exposure debt. The challenge is that security researchers are using AI to discover even more issues. Another survey of 408 security researchers conducted by HackerOne finds 85% are actively upskilling using AI, with nearly three-quarters reporting they have seen a meaningful increase in valid findings. More than two-thirds (68%) have shifted toward higher-complexity, higher-bounty bugs with the help of AI.
In fact, HackerOne reports that researchers using its platform to find and report vulnerabilities earned a record $89 million from July 2025 to June 2026. Organizations running bug bounty programs on the H1 Platform awarded $89 million to security researchers, an 18% increase over the prior year and the highest annual total in the platform’s history.
No one knows for certain how long the accelerated rate at which vulnerabilities are being discovered will continue, but even with the help of AI, it’s apparent more resources need to be devoted to remediation. The challenge is that far too many organizations are still devoting a much higher percentage of their application development effort toward building new applications and adding features to existing ones versus reducing their application security debt, noted Sprague. In fact, in the 10 years that HackerOne has been sharing its application security reports, the overall level of exposure debt has never been higher, she added.
Unfortunately, it usually requires some actual crisis before an organization revisits its DevSecOps strategy. While the number of vulnerabilities being discovered has clearly increased, it’s not quite clear there has been a corresponding increase in the number of breaches. As always, however, an ounce of DevSecOps prevention is worth a pound of any cybersecurity incident management that will have to be applied long after the damage has already been done.
from DevOps.com https://ift.tt/9cxXf7r
Comments
Post a Comment