The AI Bug Bounty Reality: Why Discovery Is No Longer Enough
The arithmetic of application security has fundamentally changed—we’re no longer living in a world where finding a vulnerability is the hard part. HackerOne CEO Kara Sprague joins Techstrong TV to explain why the explosion of AI-generated code, combined with the plummeting cost of adversarial tools, means organizations are drowning in a sea of theoretical exposures. As the industry races to embrace agentic workflows, Sprague details how HackerOne’s community of independent researchers and AI-driven platforms are cutting through the noise, shifting the focus from simple discovery to proving exploitability and driving actual remediation at scale.
Transcript
Hi, everyone. Welcome back here to Techstrong TV. I am really happy to have this next guest on.
I don't think she's been on Techstrong TV before, unless I'm mistaken, but look, I've been doing, Techstrong TV for a long time. Let me introduce you to Cara Sprague. Cara is the CEO of HackerOne.
Cara, welcome to Techstrong TV. Thanks for having me, Alan. Great to be here.
You've not been on before, correct? I don't believe so. Or with me anyway.
At least not in this role. Me either. Nope.
Okay. Well, that's important. Well, and that's a great segue.
I wanted to ask you, you know, you weren't born the CEO at HackerOne. Give, give our audience a sense of your journey, Cara. It's a, you know, it's a great story, and I'm sure people wanna hear it.
Sure. Um, well, I am an engineer, by heart and by training. Um, and, you know, this was back in the early 2000s.
And at that point, when I started taking on engineering roles and, and realizing that a lot of the work, was very individual, it felt like I worked on the same thing for a very long time, and wasn't... I was missing the big picture. I decided to go back to school and broaden my horizons a bit, and that ended up taking me into management consulting for 13 years, where I worked in, the tech practice.
So I got exposure to a whole bunch of technology companies, B2B, B2C, up and down the stack. Uh, it was a great overall view on the industry, and ultimately, I made the decision to move into a company, F5, i- as a- Sure ... executive there in the product organization.
And I, I, spent seven years there learning how to take, you know, translate what happens in consulting, which oftentimes, you know, goes only so far into the strategy and, and really, learn how to drive it and operationalize those strategies. And then last, November of 2024 is when I made the move over to HackerOne as CEO. Love it.
So look, F5 is a company we've covered. My, my good friend Lori McVey, I'm sure you probably know Lori if you were there- Yes, yes ... seven years.
Um, Lori's still there writing up a storm. I just saw something she wrote on LinkedIn this week, and I was gonna reach out to her and ask her if she wants to come on here and talk about it. You know, I've been reading Lori McVey, and Don, her husband, used to write for us here at Techstrong.
But I've been reading the McVeys, I'm ashamed to tell you, like since the '90s- ... early '90s, something like that. A long time.
Um, what... So I, I get the whole engineer to, to business, you know, m- moving to the business side of the house, then doing the kind of the business consulting thing and, and all of that, the F5 piece. And of course, everyone wants to be a CEO.
Or, I don't know. I don't know if everyone wants to be a CEO, actually. I, I think that's my generation's bias, right?
Mm-hmm. That's a, a dream job. Maybe today, people, not everyone wants to be the CEO.
But w- Cara, what, what got your juices going, so to speak, about coming in as the CEO of HackerOne? Well, HackerOne, you know, it's an organization that's been around for over a decade, and it is the pioneer in a space called, bug bounty. And, and that's where organizations, and I'm talking about, like, companies, they set up programs so that the independent security researcher ecosystem can then submit vulnerabilities in a safe way.
Mm-hmm. And in some cases, as in the case of bug bounty, get paid for that. Um, and that model was in- incredibly intriguing to me when I, when I first learned about the company, because w- if you've been in cybersecurity for a while, and you know, I started getting into cybersecurity when I was a consultant, and then did more of it, even more at F5 as the company was enhancing its portfolio in, in security, what you find is that the c- the industry has been plagued by some very long-term, challenges.
So number one is, we keep creating a lot of insecure stuff. Uh, you know, every time we, we, we make new applications and put them out there, those applications often have a lot of vulnerabilities that are being shipped with them. And we know, especially in this age of AI, with more AI generating more code, that the code that's getting released is even more insecure.
And so that backlog of vulnerabilities only continues to grow. Um, we know that there's a talent shortage, and there's just not enough people, with the skill set and the desire to be in cybersecurity. I think, you know, some estimates are that that talent shortage is in the millions of people.
And so when you look at an organization like HackerOne, the whole premise is, how do you scale out, through a platform and through the ecosystem of independent security researchers to really bring companies the kind of talent and expertise they need to identify those vulnerabilities and make their applications and their technology safer before it can be exploited by a criminal? That just really spoke to me. And I would say in the time since, when I, since I joined the company, I'm even more excited, because now we're seeing all of these new developments out there.
Um, you know, there's still, AI is en- enabling us to write, applications and develop technologies faster than ever. Um, we've got these new developments like, Claude Code Security, and, I think OpenAI has one of their own, which are, are promising to say we, we can stop shipping insecure code. And so there's even this l- this, this vision that maybe someday the code that we write and, and produce will no longer have vulnerabilities in it.
And we still have- One can hope. That's at least, that's at least, you know, the, the very rosy view of it. Uh-huh.
And, and there's still this mountain of technology that's already out there and deployed that people are using. It's, it's running our critical infrastructure. It's running, you know, our, our core citizen, services.
It's running the business cores. Uh, but there's still fundamental, vulnerabilities and exposures within that code base, that we still need to address. Agreed.
Agreed. You know, look, as I said, I've been in the, in the security industry twenty-five plus years. Mm.
Technology almost thirty-five. " And I was here when the whole bug bounty concept, you know, Katie Moussouris and- Mm-hmm ... and some of the other folks came about, and what a great thing that was, right?
Because now you had this army crowd- literally crowdsourced of vulnerability researchers who can , you know, whether they were fuzzing or whatever, they, they would help you find your vulnerabilities. And it was... You know what?
Yeah, there were these, you know, there were a few big million-dollar vulnerabilities, if you wanna call them, but the average vulnerability we were finding was a couple of hundred bucks, and it was well worth a couple of hundred bucks to find that vulnerability and, and, and close that one off, right? Of course, you mentioned the AI word, and it's had a- it's already had a profound impact, especially on the bug, bug bounty program, right? Because I- I wrote an article about this just last week.
Actually, it might have just come out today actually, now that I think about it. But th- th- the, the arithmetic has changed, where we used to pay the money to find maybe bugs. Mm-hmm.
What we're finding now is with AI, AI finds a l- Forget whether AI creates bugs when it's coding. I, I agree with you, it'll get better, but it's finding so many bugs in our existing code and in our new AI code that the, the value is no longer in finding potential bugs. The value is in evaluating those potential bugs, finding out if they are in fact real bugs and then-- or vulnerability- vulnerabilities, let's, you know, use the right term.
And then finding out are they exploitable, are they reachable, are they, you know, how, what, you know, how critical severity-wise are we doing these things? And that focus change, that arithmetic change is something that I'm sure, like at HackerOne, Kari, you guys gotta be seeing firsthand already, right? I- it's not- Yes ...
just enough to find a potential bug. We gotta take it all the way through. I'm wondering how that...
You know, what you guys... 'Cause you're, you're in the front lines on this. I, I just report on it.
Well, we're seeing, we're seeing very much the same thing that you are describing. Um, so, you know, average bounties today are a couple of thousand and, you know, HackerOne in the last year paid out over eighty million dollars in bounties. So the amount of bugs that this, this approach is, is- and vulnerabilities that this approach is uncovering continues to grow.
Uh, but to your point, right, we're at an inflection point in the cybersecurity industry, where we now have attack surfaces growing very, very fast as companies rush to, implement new AI-driven capabilities, and, and deploy technology faster than ever before. But at the same time, the cost to run an attack or the cost to find a vulnerability has come way, way down because of the capabilities that AI enables for, for cyber criminals as well as for, for ethical hackers. Um, and that means to exactly what you're saying, the focus can no longer just be on discovery.
Um, we need to look for solutions that enable co- companies to move from discovery all the way through the cycle to remediation, and actually prove that there's actually a fix that has been implemented and that it sticks. Um, and that's one of the th- really exciting things I think there is about, you know, these, these offerings that, that provide adversarial thinking, which is, which is what a lot of what HackerOne brings to, to companies, is we offer them a view of the vulnerabilities that are truly exploitable, because these are things that have been identified on an external, attack surface and, things that have actually been validated, to be of a certain severity level and truly, a risk to the company. And what we find, in those programs is that those are oftentimes the things that companies wanna prioritize for their development teams to focus on first.
Because rather than focus on, you know, the laundry list of, theoretical, exposures or vulnerabilities that might come out of a more deterministic scanner, what you want to do is, is find those things that an external adversary is actually able to detect and exploit, in your technology and make sure that you close that gap first, and that's exactly what we offer. Absolutely. Absolutely.
And, and I think that's an important piece of it, right? Too many... You can't blame them.
I'm not blaming anyone. But too many f- people, like you mentioned eighty million dollars. Mm-hmm.
A lot of people, they just get fixated on the number, right? And, and they don't understand the real, the, the full mission. Yes, the mission is to facilitate- Mm ...
researchers getting compensated for, for bugs and vulnerabilities they find. But, you know, and, and if that's all you're interested in, great. Eight- eighty million's the number you should know.
But there's more to that mission, right- Yes ... that goes beyond paying out the bounty. Precisely.
I want to- Yep. Yep. A- and I think that's an important...
You know, people out there need, need to pick that out. Um-But Kara, I, I, I, we were talking off camera. I told you I spent all weekend automating stuff with agentic AI.
Now, was it-- You know, I've been using, generative AI for, since it burst on the scene, right? But- Mm-hmm. I-I can't help but think over the last three weeks, four weeks, this, this thing with Clawbot, right?
Mm-hmm. OpenClaw, whatever you wanna call it. OpenClaw.
The-- It's like an-another era has kicked, right? We're seeing a whole different kind of wave, if you will. Um, I wonder, are, are you feeling and seeing that too?
Like, so we're moving from purely generative to agentic AI. So, you know, you didn't need an agent in Claude Code to write code. But now not only is Claude Code writing that code, it's deploying that code for you.
It's hosting, it's setting up the hosting of it and everything else, right? And, and then as you said, the, the latest, ChatGPT is Codex or whatever it's called. It, it's not terrible either, though developers seem to be forming around Claude for, for various reasons.
But, do you see this-- Have you seen the switch flip as well? Are you, you know... Absolutely.
Um, yeah. So absolutely. I see this, and I, I, I have been also using this in my, both my, my personal and my, my own specific professional, workflows.
Um, the agentic AI has been a game changer. Uh, we see this with our customers. Um, so, you know, we, we were very proud to evolve our, GenAI offering high, into a team of agents, last year.
And what we're seeing from our customers in terms of what they're reporting is that some of the agentic workflows are saving our customers up to seventy-five percent of the time that they used to spend on, incoming reports. Um, and again, for, for overworked security teams, that is a massive, massive time, saver for them and a huge amount of- It's a miracle. I mean, it's, it's, it's game-changing.
Um, and then equally, you know, for, for those CISOs that, have been struggling to get coverage across their attack surface area because, you know, it's, it's, it's time intensive and expensive to be doing pen testing, for example, or periodic pen testing, which many, many organizations in the past have, have applied to only to a fraction of their overall, attack surface on a, on a very irregular basis. What we're now seeing, with agents is that agents can now test continuously across those entire attack surfaces. And so you get the proposition of a lot more continuous testing and a lot more breadth of coverage.
Um, so it's, it's actually really exciting in terms of the ability now that we have to do, much more, robust, cybersecurity and, find more of those issues. But to your point, finding the issues is not the only problem, right? Um, you need to complement the discovery with a platform that can actually facilitate getting those issues remediated, which is where all of the validation and the prioritization has to come in and the integration into developer workflows.
Um, and so that's, that's actually, you know, the, the vision that I'm, I'm very excited about that, that we are working on, is how do you bring an entire, end-to-end view, together so that regardless of the different discovery mechanisms that might be out there in the market finding vulnerabilities, and there's gonna be a lot of vulnerabilities discovered over the next twelve to eighteen months, how do we make sure that you put those into something that makes sure that you're optimizing the, the risk that you're reducing, by, by prioritizing appropriately what your developers are focused on? And, and this is something HackerOne is bringing to market. Yes.
Yes. Available now, available soon, coming soon. What's, what's the status?
Uh, it-- we have it available. It's available now, and it's continuing to get better every, every month, every quarter. So- As everything is, it seems, right?
Yeah. Yeah. It's, it's crazy.
Um, how do people sign up for that, Kara? They can, well, they can reach out to HackerOne. You can contact us through our website.
You can reach out to me directly, kara@hackerone. Um, but, you know, this is, this is exciting, and, and what I'm, I'm looking forward to, I, I really see a huge amount of potential, as we move into this agentic era, uh- Mm-hmm ... to truly take the burden off of cybersecurity teams and to really...
Actually, I think there is a path for us to finally start, having technology that is more inherently secure, which should be exciting for everybody. From your mouth to God's ears, right, as they say. Um, Kara, you know, but there are people out here who worry about their jobs.
Yeah. I don't know a nicer way of saying it, so I'm just gonna be blunt, which is my style. They're worried, is this AI gonna take their job?
Yeah. Is this AI gonna just automate finding vulnerabilities, remediating vulnerabilities, documenting vulnerability? You know, where do I fit in?
Where's the human-- I'm a human. Where would-- You know, what do I do? Am I, am I gonna be as valuable?
Am I gonna, you know... Is the security industry gonna have a place for me? Do I have a place in it?
And, you know, as you said right in the beginning, it's still an industry where we have, at the very least, tens of thousands of openings probably, right? If not hundreds or millions. Um, and, and if history is any guide, as these new waves of innovation and technology come out, it doesn't make security smaller, right?
I-- None of these things always. So I'm wondering, what, what do you say to those people out there, Kara, who are worried? I would say, first I, I think that, that concern, is, is a familiar feeling for, for anybody who's lived through, you know, these massive generational shifts in technology.
Um, you know, we saw this, when the industrial era, era came. We saw this through the various evolutions of computers from mainframes into personal computers and then into the internet era. And AI is bringing a, a fresh wave of, of disruption to the way that that work gets done.
And yes, there are some new things about AI, that are different from, from previous generations. Um, but if history is our guide, to what-- to the point you made exactly, Alan, this sh- this will expand the opportunity set. This expands tremendously what, an individual is capable of doing.
Um, and this should create more, opportunity for us to, to bring real outcomes to life at an individual level. And so the, the amount of empowerment that an individual has at this point with these tools is astounding. Um, and that's very, very exciting.
And, and yes, there is change in, in what we do on a day-to-day basis and how we get our work done and how we drive impact. Um, but that change buys us the opportunity to have much, much more impact than ever before. Agreed.
You know, we mentioned the website, we mentioned the website, but I don't think we ever did the URL, Kara. Oh. com?
com. Then that's one spelled out, O-N-E. So it's H-A-C-K-E-R-O-N-E dot one...
dot com Dot com. Got it. Kara, we're about out of time.
I wanna thank you. I wanna invite you back because this, as we're talking about, this changes almost day to day right now, if not week to week, certainly month to month. Yeah.
I'd love to hear what... for the HackerOne services, but from the research community that you're so intertwined with as well. And because it, it, you know, I, I think they, they're mirror images of each other in some ways, but there's gonna be some-- they'll each be figuring out their place in this new reality that we're finding ourselves in.
Happy to. Happy to. as you, as you're, as you said, it's a very fast-moving space and, a lot of, a lot of very fascinating things are happening every day.
Absolutely. You know, I was here for the whole internet thing and then of course the cloud, and, you know, I rode the dot com up, the dot com down. I did the cloud.
I did, you know, venture backed startups, then here in media for ten, twelve years. I don't think anything has moved this fast, right? This gives internet time a whole new, whole new meaning.
Um, Kara, thanks for coming on here. Continued success at HackerOne. Do come back and keep us posted, okay?
Thank you. Thank you. Kara Sprague, CEO, HackerOne, here on Techstrong TV.
We're gonna take a break. We'll be back in just a bit.