HackerOne has added a remediation capability to its H1 Platform that reduces the amount of time required to remediate validated vulnerabilities and other weaknesses affecting specific lines of source code.
Nidhi Aggarwal, chief product officer for HackerOne, said H1 Remediation combines artificial intelligence (AI) and crowdsourced research to identify the root cause of issues that are traced back to specific lines of code. Designed to integrate with existing issue tracking tools and AI coding agents via a Model Context Protocol (MCP) server, the goal is to better prioritize remediation efforts in a way that reduces the amount of exposure debt that continues to increase as advanced AI models discover many more vulnerabilities in code, said Aggarwal.
Reports generated, in addition to root cause analysis, also detail exactly where a risky input enters the code and the resulting damage caused, language-specific code change suggestions, business context, and implementation guidance. Additional context is provided via integrations with DevOps tools and platforms such as Jira, Linear, and Confluence to provide incident histories and asset information.
The H1 platform also provides access to a dashboard for tracking resolution rate, mean time to remediate by severity, findings flow, and exposure backlog trends such as peer benchmarking and year-over-year comparisons.
Historically, application development teams have allocated a significant amount of time validating any vulnerabilities reported by cybersecurity teams. That often led to a lot of frustration and wasted effort when application developers discovered the code in question was either not externally accessible or was never loaded into memory. AI tools have now made it much easier to discover vulnerabilities but along with that advance has come a sharp rise in the number of false positives discovered in code, noted Aggarwal.
H1 Remediation addresses that issue by surfacing video examples of how a specific line of source code can be exploited, with plans to also provide examples of how source code can be exploited running in a Docker container that application developers can run and observe, said Aggarwal.
Armed with those insights, it then becomes simpler to either fix that code or develop a kill chain that mitigates the threat using the company’s continuous threat exposure management (CTEM) platform, she added.
It’s not clear at what rate cybercriminals are now moving to exploit vulnerabilities in production environments but it has been confirmed that with help from AI they are able to create an exploit in less than a day. In many instances, the exploit is now being created faster than the patch needed to fix the vulnerability. In effect, DevSecOps teams are now locked in a race against time that requires them to be much more proactive about discovering and remediating vulnerabilities versus waiting for them to be discovered by their cybersecurity teams, said Aggarwal.
Regardless of approach, the way application security is achieved and maintained has fundamentally changed. The only thing that remains to be seen now is how long it will be before organizations that fail to adapt to that new reality start to experience a wave of cyberattacks that will, more than likely, become increasingly lethal with each passing day.

