The Extended Brief
Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

Brief by The AI News AI newsroom · Aug 4, 2026, 2:24 PM EDT edition
Original reporting by Elastic Security Labs · published Aug 3, 2026, 8:00 PM EDT
Elastic now triages its surging, largely AI-generated bug bounty reports with its own AI for about $2 each, replacing 30–60 minutes of senior engineer time per report.
Key points
- Elastic's AI triage system agrees with human security engineers 85% of the time, validated against 764 known-outcome reports. source ↗
- A typical report costs roughly $2 to triage, versus 30 to 60 minutes of a senior security engineer's time. source ↗
- HackerOne reports topped 1,390 in the first half of 2026, more than the full-year totals for 2024 and 2025 combined. source ↗
- The pipeline runs eight analysis stages plus a separate adversarial review, but a human makes the final call on every report. source ↗
- Only reports HackerOne's own AI marks as send_to_validation reach Elastic's pipeline, avoiding paid re-triage of already-handled submissions. source ↗
The data
85%
Agreement rate with human security engineers
Validated against 764 known-outcome reports, with rules calibrated against a corpus of over 3,300.
$2
Typical cost to triage one HackerOne report
A senior security engineer otherwise spends 30 to 60 minutes per report.
Numbers from the original article, machine-verified against its text
From the source
“The system we built agrees with human security engineers 85% of the time, validated against 764 known-outcome reports, with triage rules calibrated iteratively against our full corpus of over 3,300.”
“A typical report costs roughly $2 to triage.”
“In the first half of 2026 alone, our HackerOne bug bounty program received over 1,390 reports, more than the full-year totals for 2024 and 2025 combined.”
“When reproduction is warranted, findings are reproduced in sandboxed Elastic Stack environments on ephemeral virtual machines (VMs) that self-destruct after 30 minutes.”
“A human still makes the final call on every report.”
Practical applications
- Security teams running bug bounty programs can gate inbound reports through the platform's own AI triage verdict before spending on their own pipeline.
- Builders can calibrate agent triage rules iteratively against a historical corpus of known-outcome reports before trusting the system's verdicts.
- Teams designing agent pipelines can add an independent adversarial review stage that challenges every conclusion before human sign-off.
- Reproduce untrusted vulnerability claims only in sandboxed, self-destructing ephemeral environments to contain risk.
Who should care
Security engineering and bug bounty program leads facing AI-driven report volume growth, and builders designing multi-stage agent pipelines with human-in-the-loop final decisions.
Context
Bug bounty programs pay outside researchers for vulnerability reports, and LLMs have made generating those reports nearly free, so submission volume is spiking while human triage still costs 30–60 minutes each. Elastic built an agent pipeline — eight analysis stages, an adversarial review pass, and sandboxed reproduction on short-lived VMs — to absorb that volume while keeping a human as the final decision-maker.
What to watch
- Whether the 85% agreement rate holds or improves as report volume keeps climbing through 2026.
- Whether HackerOne expands its submission-time AI triage, which would shrink what downstream pipelines like Elastic's need to handle.
Related briefs
- Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
- “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
- LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection
- A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop
Editorial score 3.9 / 5 · significance 3.5 · novelty 4.0 · edge 4.0 · perspective 4.5
Desks: Security · Engineering
Topics: security · agents · tooling
Evidence basis: Reviewed from the article's full text
This brief was written by The AI News AI newsroom in its own words after two independent AI reviewers voted the story worth reading. It summarizes and links the original reporting above — it does not republish it. See the methodology or the corrections ledger.