HackerOne has documented a 210% increase in valid AI-related vulnerability reports over the past year, signaling a fundamental shift in the threat landscape that space companies must address with urgency.
AI-Driven Vulnerabilities and the Rise of Autonomous Agents
Laurie Mercer, security architect at HackerOne, reports that the platform is seeing a surge in vulnerabilities either generated by or targeting AI tools, a trend he expects to accelerate through 2026. Common findings include sensitive information exposure in chatbots and image generation systems, often due to misconfigured permissions.
The emergence of 16 AI collectives operating on HackerOne’s platform represents a new paradigm. These autonomous agents are discovering vulnerabilities at a scale impossible for individual researchers, fundamentally changing how offensive security operates.
Crowdsourced Security Challenges for Satellite Operators
For space companies, the core challenge remains access. Unlike web applications, satellites and IoT systems present physical and logistical barriers that prevent traditional crowdsourced testing. Mercer notes that operators must decide whether to test production or pre-production environments, with the latter often preferred to avoid disruption.
Public bug bounty programs for satellite systems risk overwhelming operational networks. “If you have one thousand extra users trying to break into your systems, this can cause disruption,” Mercer warns, advising private, controlled engagements over public programs.
Supply Chain Weaknesses and the Promise of AI Remediation
Supply chain security remains a critical blind spot. Mercer observes that in 2025, companies realized their internal security controls far exceed what they require of suppliers, leading to breaches through third parties. This asymmetry is now a primary attack vector.
HackerOne is exploring whether AI agents can automate vulnerability prioritization, confirmation, and patching. “Can we have AI agents talking to each other—one finding an issue, another confirming it, a third locating the source code?” Mercer asks, describing a future of “digital coworkers” handling what human analysts do today.
A Worrying Rise in Business Logic Flaws
Despite increased investment in cybersecurity, HackerOne’s annual report reveals a nearly 20% year-over-year increase in business logic flaws and improper access control vulnerabilities. Mercer finds this trend concerning, as mature security programs should see decreases in known vulnerability categories.
Geographically, the hacker community is diversifying. The U.K. is now neck-and-neck with China in researcher activity, while Egypt emerged as a top competitor in HackerOne’s World Cup. “This is the Middle Eastern hacker community awakening,” Mercer notes, signaling a more global and unpredictable threat environment.
As AI-driven attacks and autonomous vulnerability discovery become the norm, space companies must move beyond traditional security postures. The next frontier is not just defending systems, but leveraging AI itself—and a globally distributed researcher community—to stay ahead of adversaries who are already using these tools at scale.
— Originally reported by SatelliteToday Cyber. Adapted and republished with editorial context for SpaceSecurityNews.