SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
HackerOne launches H1 Remediation for faster fixes

HackerOne launches H1 Remediation for faster fixes

Wed, 29th Jul 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

HackerOne has launched H1 Remediation, a new feature in its H1 Platform designed to help organisations fix validated software vulnerabilities.

The launch comes as critical flaws are being closed at a much lower rate. Data from the platform shows the resolution rate for critical vulnerabilities has fallen from more than 83% to under 40% over the past year, while the backlog of unresolved critical issues has increased 29-fold.

H1 Remediation produces fix plans for findings already validated as exploitable. It traces a vulnerability's root cause to specific lines of source code and sends the guidance into software engineering tools including Jira, Linear and ServiceNow, as well as AI coding tools such as Claude Code and Cursor.

HackerOne is positioning the product as a response to a long-standing problem between security and engineering teams. Security teams often identify weaknesses faster than developers can fix them, while engineers may hesitate to act on severity rankings if they cannot see how a flaw affects their own code.

The feature works only on findings already established as real and exploitable on HackerOne's platform. Those findings can come from bug bounty researchers, pentesting work and continuous testing activity.

Kara Sprague, Chief Executive Officer at HackerOne, said the product is also intended to give senior management a clearer record of unresolved risk and the time taken to remove it.

"Boards no longer want to hear how many vulnerabilities were found. They need to know the magnitude of the exposure debt you're carrying and what you are doing about it," said Sprague. "H1 Remediation gives security leaders a defensible answer to both. Every finding carries a documented trail from validated exploitable vulnerability to verified fix, with exposure duration as a measurable, reportable metric. Closing that gap faster is both an operational improvement and a governance imperative."

Growing backlog

HackerOne said the backlog has worsened even though the average time to remediate critical findings has improved by more than 50%. In its view, the problem is less about coding speed and more about the friction involved in turning a security finding into a fix that developers trust and can implement quickly.

That reflects a broader shift in cybersecurity operations as companies adopt more automated discovery tools. Faster identification of weaknesses can increase the volume of findings presented to internal teams, but it does not necessarily lead to faster closure if engineers still need to reproduce the issue, trace its source and decide on a remediation path.

H1 Remediation aims to address that by connecting to code repositories including GitHub, GitLab, Azure DevOps and Bitbucket. It can also pull context from connected systems such as Confluence and issue-tracking tools to add business and operational detail to the remediation plan.

Tickets can be created directly in issue-tracking systems, with status updates synchronised back into the H1 Platform. HackerOne has also added a remediation dashboard intended to show resolution rates, mean time to remediate by severity, findings flow and backlog trends.

Customer view

Veterans United Home Loans is among the early users cited by HackerOne. The lender's application security team said the main benefit was being able to give developers guidance tied directly to their own code rather than broad advice.

"The value for us is in speed to resolution. H1 Remediation hands our engineers clear technical steps already grounded in our own code, so they can move straight to a fix," said Connor Knabe, Application Security Architect at Veterans United Home Loans. "This results in time saved for the security and product teams. It's clear this isn't generic guidance. It's based on our actual code and fits right into how our team already works, so there's no new process, just better information showing up exactly where we need it."

For HackerOne, the release extends its push beyond vulnerability discovery and validation into remediation, where many security programmes struggle to show progress. The company argues that creating a clear path from confirmed exploitability to verified fix is becoming more important as boards ask for evidence not just of how much risk has been found, but how much has actually been reduced.

Nidhi Aggarwal, Chief Product Officer at HackerOne, said the company has repeatedly heard that confirmed findings remain unresolved because engineering teams do not get enough specific context to act quickly.

"Every customer conversation comes back to the same problem: validated findings sitting unresolved because engineering lacks the context to act on them quickly," said Aggarwal. "H1 Remediation extends the workflow from discovery to verified fix. When a fix plan starts from a validated, exploitable finding traced to the actual source code, is informed by the customer's context, and is delivered into the engineering workflows teams already use, the friction that stalls remediation disappears. Combining agentic capabilities with human ingenuity from the security research community is what gives teams the confidence that what they are fixing is real. That is what turns remediation from a backlog problem into a continuous improvement process that drives measurable risk reduction."