CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3841

As cited

Copy frozen at (site build).

research

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

Elastic implemented an AI-powered triage system for bug bounty reports on HackerOne that costs approximately $2 per report and agrees with human security engineers 85% of the time. The system uses an eight-stage analysis pipeline with adversarial review on one VM and a separate reproduction VM for validation, orchestrated through Elastic Workflows with automatic 30-minute shutdowns. The approach addresses the scaling challenge created by LLMs making report generation nearly free, which increased Elastic's submissions from 600-850 annually to over 1,390 in the first half of 2026.

Why it matters: Security teams managing high-volume bug bounty programs need cost-effective triage methods as AI-generated submissions overwhelm manual review capacity. Practitioners can adopt this two-phase architecture and adversarial review pattern to reduce triage costs while maintaining human final decision authority.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

research

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

research

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

Elastic built an artificial intelligence (AI) agent system to triage HackerOne bug bounty reports at approximately $2 each, achieving 85% agreement with human security engineers on a validation set of 764 reports. The two-phase pipeline uses separate compute-isolated virtual machines for analysis (which applies an eight-stage assessment with adversarial review) and reproduction (which runs submissions in sandboxed Elastic Stack environments), with humans making final decisions on all reports. The system was created to address a scaling challenge where large language models dramatically increased submission volume in the first half of 2026 to over 1,390 reports, while the cost of human triage remained constant.

Why it matters: Security teams operating bug bounty programs should evaluate AI-assisted triage to manage the operational burden of high-volume, low-signal submissions without sacrificing decision quality or security.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

research

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

Elastic built an artificial intelligence (AI) agent system to triage HackerOne bug bounty reports at approximately $2 each, achieving 85% agreement with human security engineers on a validation set of 764 reports. The two-phase pipeline uses separate compute-isolated virtual machines for analysis (which applies an eight-stage assessment with adversarial review) and reproduction (which runs submissions in sandboxed Elastic Stack environments), with humans making final decisions on all reports. The system was created to address a scaling challenge where large language models dramatically increased submission volume in the first half of 2026 to over 1,390 reports, while the cost of human triage remained constant.

Why it matters: Security teams operating bug bounty programs should evaluate AI-assisted triage to manage the operational burden of high-volume, low-signal submissions without sacrificing decision quality or security.

VendorsGoogleDockerElastic
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary