How Our AI Reached the HackerOne Top 3 and What We Learned
90 days on live bug bounty programs. 204 valid reports. Top 3 across multiple HackerOne leaderboards, using AI agents. Bikash Barai shares what the experiment revealed about the current capabilities and limitations of AI pentesting agents.
- ✓ Where can AI agents already outperform experienced human researchers?
- ✓ Where do humans still win, and why?
- ✓ What matters more in AI pentesting: the model, the agent, or the harness around it?
Register for the session
Thursday, October 1, 2026. 9:00 PM IST / 11:30 AM ET / 7:30 PM GST. The joining link is sent to your email once you register.
Who you will be hearing from
Bikash Barai
Serial security entrepreneur with multiple USPTO patents in network security. Recognised in Fortune's 40-under-40 and a speaker at RSA Conference and TEDx. Earlier founded iViZ, the first company to take penetration testing to the cloud, later acquired by Synopsys.
Other Turbo Talks sessions
Register for any session in the series. Each one is a standalone 20-minute live talk.

Model alignment is only one part of the problem. A technical look at where agent safety diverges from model safety.
Register
AI is collapsing the attacker timeline, exposing "depth debt" in current ASM and CTEM tools.
Register
Black Hat shows where the industry is going. DEF CON shows how attackers plan to break it.
Register
Two decades of secure coding, SAST, DAST, and Shift Left, and the same vulnerability classes keep reaching production.
Register
As offensive AI agents get more capable, control becomes the harder problem.
Register

Every vendor claims AI now. The questions that separate AI-native platforms from scanners with an AI wrapper.
Register