Full Tech Ahead
On this podcast, I sit down with business leaders, researchers and executives to explore innovative technology solutions and products, whether they’re transforming industries today or still in development. But we go far beyond the tech itself. From real-world use cases and business implementation journeys to cybersecurity challenges and future trends, we uncover what’s shaping the digital landscape.
We also dive into topics that matter to every tech professional: Work/life balance, business communication, education and training. Think of it as your one-stop shop for meaningful technology discussions that inspire and inform.
Full Tech Ahead
Manage Your AI Security Debt
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of "Full Tech Ahead," host Amanda Razani interviews Nidhi Aggarwal, Chief Product Officer (CPO) of HackerOne. They discuss the paradigm shift in cybersecurity risks caused by AI-accelerated software development. Aggarwal introduces HackerOne’s new continuous threat exposure management platform, H1, designed to bridge the "find-to-fix" lifecycle gap.
She reveals that following the release of advanced AI models, vulnerability report volumes surged by over 90% in April 2026 alone. This influx has dramatically shortened the "zero-day clock", the time between vulnerability discovery and adversary exploitation, from an average of one month down to mere hours or minutes.
To combat the resulting 25X spike in critical vulnerability backlogs and build up "exposure debt," Aggarwal emphasizes that organizations must abandon seasonal compliance checks in favor of continuous, AI-driven adversarial pen testing combined with human discernment.
Key Quotes
- "Remediation has not kept pace... most CISOs are not looking for more vulnerabilities. Everybody's inundated with vulnerabilities."
- "The zero day clock... has steadily gone down from it used to be about a month last year to a matter of a few hours now in this year with AI."
- "Defense has to operate at that AI offensive scale... We have a concept called exposure debt... you have to think of it like technical debt or something sitting on your balance sheet."
- "The big advice would be offense is defense. So you have to think offensively."
Takeaways
- Automate Defense at Machine Scale: Since generative AI has driven the marginal cost of cyberattacks close to zero, adversaries can now launch massive, automated exploits in under ten minutes. Security defense can no longer operate at human speed; prioritization and remediation must scale up to match offensive AI.
- Manage Your "Exposure Debt": Unremediated high-risk vulnerabilities function like technical debt on an enterprise balance sheet. Organizations must treat this exposure as a board-level risk conversation and design a continuous drawing-down plan rather than letting critical backlogs accumulate.
- Filter out "AI Slop" via Bifurcation: The explosion of automated AI scanning has altered risk distribution. Security teams are experiencing a bifurcation: they are flooded either with informational "AI slop" (false positives that existing controls block) or hyper-critical zero-days. Rapid automated validation is mandatory to isolate true exposure.
- Shift to Continuous Risk-Based Pen Testing: Move away from compliance-driven, checkbox security architectures. True defensive resilience requires automated, 24/7 white-box and black-box pen testing, paired with the creative adversarial judgment of ethical human researchers using AI.
Find Amanda Razani on LinkedIn. https://www.linkedin.com/in/amanda-razani-990a7233/
Follow the FTA LinkedIn Page: https://www.linkedin.com/company/full-tech-ahead/
Visit the FTA website: https://fulltechahead.com/
Check out the Substack Channel: https://fulltechahead.substack.com/
Hello and welcome to Full Tech Ahead. I'm your host, Amanda Razzani, and I'm so excited to be here today with Nitty Agerwal. She is the Chief Product Officer of Hacker One. How are you doing today? I'm doing very well, Amanda. Thank you so much. Thank you for having me. Yes, happy to have you on the show. Can you share first a little bit about Hacker One and the services that you provide?
SPEAKER_01Yeah, sure. Hacker One is a continuous threat exposure management platform, and uh we help uh the biggest companies to help find vulnerabilities and validate them and remediate them. So it's the find to fix uh life cycle. That's uh those are the services we provide. Wonderful.
SPEAKER_00Well, our topic for today is AI and software development and all the cybersecurity risks that are new and have been introduced because of it. But first, I want to give you a chance to share your news. You recently uh put out a new product, so I'd love for our audience to hear about that.
SPEAKER_01Sure, thank you. Yes, we launched our H1 platform. Uh, it is the continuous threat exposure management platform. And the problem, as you talked about, is AI is accelerating software development and vulnerability discovery, but remediation has not kept pace. So, like most CISOs are not looking for more vulnerabilities. Everybody's inundated with vulnerabilities. In fact, we saw that on our platform in April, the report volume surged more than 90% following the release of all of these advanced AI models, and that forced a deliberate conversation about what quality actually means on the platform. And not all AI assisted volume is equal. So we had to really validate what is true exposure, what out of these all of these reports are the kinds of vulnerabilities that uh represent true exposure for you, which means that they can be exploited, and which ones are already stopped by your security controls. And then how do you prioritize them? And the ones that are prioritized for you, how do you actually remediate or fix them? Because that's the real thing, right? If you are not going to fix something, knowing the problem doesn't solve the problem. So that's the H1 platform, bridges the gap between finding the risk and fixing the risk. That's the defining platform. And H1 platform is built for continuous discovery, validated exploitability, prioritized action, and remediation at AI scale. That's what we launched.
SPEAKER_00Wonderful. Well, that will certainly be helpful. And I feel that that is a good segue then into that topic. So, from your experience, what are some of the newer or more recent cybersecurity risks or challenges that business leaders are facing with the use of AI and software development?
SPEAKER_01So the whole cybersecurity paradigm itself was built on the premise that uh uh security vulnerabilities, once they were discovered, you had a little bit of time uh before they could be exploited, and you had time to remediate them. But that paradigm itself has changed with AI. We have something called the zero-day clock, which means that that is tracking how much time uh there is now between when a vulnerability is discovered before it is exploited. That time has steadily gone down from it used to be about a month last year to a matter of a few hours now in this year with AI. Because the moment it is discovered, it can be exploited. In some cases, there are adversaries who've exploited vulnerabilities in less than 10 minutes. So that's the scale. And now you can do it at scale. Everybody, every adversary who has an access to a model can try an attack. So now you have to try and do your security defense also at machine scale. You cannot operate at human uh speed. So now defense has to operate at that AI offensive scale. And with uh what we're seeing is the moment we are in is the cost of an attack is going down uh faster and faster. It's almost coming down to zero. Meanwhile, the attack surface is also growing uh really fast because uh recent surveys indicate that 73% of engineering teams now use AI coding tools daily, and AI-powered security tools are surfacing those vulnerabilities. So now that remediation gap is increasing. In fact, on our platform, we published this research that uh even as we are fixing vulnerability, the time to fix vulnerabilities is getting faster. We can fix vulnerabilities now 80% faster. The critical vulnerability backlog has grown 25x. That's the gap that uh CISOs and organizations are facing. So we need a complete redesign of our security architecture for this AI era.
SPEAKER_00Wow. So what you're saying essentially too is we've got to fight AI with AI. Yes. Yeah. So what is the the first place to start when it comes to better protection of companies and their software and and and their tools?
SPEAKER_01So the first place uh to start, I would say, uh, is do the basics right. Take stock of what assets do you have? Uh, do you know uh what assets are vulnerable in the sense of uh uh what is connected to the internet, what is your attack surface, what are the things that are uh most important uh to you? For example, what are the crown rules? And that is the first uh place to start. Uh do an after doing the inventory for your code, uh have a static analysis of your code. Uh do the analysis, what is my code vulnerability? It's a defense in-depth approach. Then move up the stack and say, how can I now see when this code is dynamically? How do I test for that? Then test it adversarially. Okay, I've tested it defensively, but an attacker is going to use uh is going to test it adversarially. How do I test it in that motion adversarially? And do that continuously with AI. Don't do periodic testing because the periodic testing was maybe quarterly or annually, that speed doesn't work anymore. And then at the end, you still have to have like you do all of this with AI. The ultimate test is how do you think like adversely, who is a human with powered with AI, right? There is a human with AI. That's where the ethical researchers, the security researchers come into play. The security researchers are also adopting AI. On our platform, we see that. Like a lot of our uh most of our researchers are now finding vulnerabilities using AI. That's the test. Like, how are they uh testing your environment so that defense-in-depth approach helps you protect at multiple layers? There is no silver bullet. You have to use AI to scale, and you have to use human creativity and discernment to find the novel and edge cases. And that those two loops have to work together.
SPEAKER_00Yeah, the human is still a very important part of the process.
SPEAKER_01Yeah. The human cannot be in the critical path, but the human is very important for that uh creativity and the adversarial judgment.
SPEAKER_00Absolutely. Well, so AI is advancing and it's evolving. And so, what is the next thing that business leaders need to be on the lookout for and prepared for?
SPEAKER_01So, business leaders need to be on the uh lookout for one, the it's not about a particular model, right? We hear a lot about this model or that model, this model has gotten this capability. From now on, the models are going to get better and better. We are in an era where most models, uh, right, and open source models or frontier models will have the capability to discover new vulnerabilities. So we have to prepare for that world. Um, it's uh uh so we have to prepare for a world where attacks will come faster, attacks will come at scale, and it's continuous. So defense has to be continuous. This is where to your point earlier: fight AI with AI. Prepare for that world where you are defending yourself continuously, you are testing continuously, you are validating what is actual risk continuously, and then you are prioritizing continuously and then remediating continuously. So you can't afford to have cycles where remediation takes longer and longer, and you are not uh making security a priority. So security becomes a board-level conversation. Uh, we have a concept called exposure debt. Uh, so the exposure debt is how many critical high vulnerabilities are sitting in your staff that you haven't yet remediated. You have to think of it like technical debt or something that is sitting on your balance sheet, and that is the risk you're taking in the business. And you have to have plans to draw it down. And that's the conversation, that's the world we have to prepare for.
SPEAKER_00Do you think that it's important to do regular, like deep dive pen testing to just test to test and make sure there's no vulnerabilities?
SPEAKER_01So when I talk about continuous testing, continuous testing is uh pen testing. Okay. Uh it is AI-driven pen testing, it is uh right, a combination of human and AI pen testing, and you have to do both what we call black box pen testing, which is outside in, thinking like an adversary, and then a combination of what we call white box pen testing, where you have access to the source code. So you do it deeper because you know the context of the code, and then you can have a much deeper analysis of what is the application trying to do. So, what are the kinds of vulnerabilities that you should remediate? Uh, so you have to do both of those continuously and not do the pen test as a mechanism for compliance checkbox, but for truly security-oriented outcomes. You're trying to draw down the, you're trying to manage your exposure. So you have to take a risk-based approach now versus a compliance-based approach.
SPEAKER_00And how has, I know in the past, you know, and probably still, companies look at risk and they determine, okay, can they let this risk slide? Okay, this risk is more important. But how has that changed where it's a little bit more difficult to say, oh, we're okay with this level of risk because, you know, AI introduces so many different challenges?
SPEAKER_01It has changed because now the number of critical vulnerabilities that you're going to get has risen up. What we saw early on with AI was there was a lot of what's called AI slot, which meant that AI was finding a lot of vulnerabilities. Uh, but when you actually looked through it, uh, most of those vulnerabilities you couldn't actually exploit them in the environment. Your security rules would have, right? Your security controls would have stopped them. Uh, or uh those vulnerabilities were low-level vulnerabilities, they didn't really matter. They were informational. But over time, uh, what we've seen on our platform is almost a bifurcation. Either we see vulnerabilities that are false positives. You can't truly uh exploit them. Or we've seen some really good quality vulnerabilities. Those are critical, they really are something you should pay attention to and remediate uh really quickly. So now you have to take that risk into account much faster and do the remediation. So that's where now you have to have the ability to identify that risk much faster, prioritize it, and remediate it much faster. So that's how it has changed. It is no longer that even distribution of you get a few vulnerabilities that are critical, once in a blue moon, and then the rest are sort of your medium grade risk and you can fix them over time. It used to be that finding a zero-day vulnerability required a lot of talent, expertise, and finding that used to be once you found them, it was like, wow, something big has happened. Now it's becoming way more common. Right.
SPEAKER_00Yeah. Well, if there was one key takeaway or piece of advice that you could give to business leaders in this day and age, what would it be?
SPEAKER_01The big advice would be offense is defense. So you have to think offensively. You have to get into the mindset of the adversary and think how they would be attacking you. So you have to do continuous discovery on your own perimeter. You have to have continuous validation that are you testing for the right things? Are you prioritizing the right things? And are you then remediating them at machine speed while at the same time keeping the human judgment and discernment in that process so that you are ahead of the adversaries?
SPEAKER_00All right. Well, thank you so much for sharing your insights with us today. Thank you so much for having me. And thank you to our audience. If you have questions about this or comments, please leave them and I will try to respond as soon as possible. And have a wonderful week.