{"id":146588,"date":"2026-08-20T20:37:15","date_gmt":"2026-08-20T20:37:15","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/146588\/"},"modified":"2026-08-20T20:37:15","modified_gmt":"2026-08-20T20:37:15","slug":"harness-ai-agents-speed-vulnerability-remediation","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/146588\/","title":{"rendered":"Harness AI Agents Speed Vulnerability Remediation"},"content":{"rendered":"\n<p>Software delivery firm Harness wants to fix vulnerabilities before attackers can weaponize them.<\/p>\n<p>Harness announced Aug. 19 a set of AI-powered security capabilities designed to move vulnerabilities from detection through remediation and deployment with fewer manual handoffs, potentially helping MSPs and MSSPs manage customer vulnerability backlogs.<\/p>\n<p>The launch includes AI SAST, LLM scan orchestration, a Triage Agent, a Remediation Agent, a Zero-Day Agent and virtual patching. Harness says the tools are designed to work within the software delivery pipeline rather than operate as disconnected security products.<\/p>\n<p>The push comes as<a href=\"https:\/\/www.channelinsider.com\/security\/connectwise-report-trusted-identities-exploited\/\" rel=\"nofollow noopener\" target=\"_blank\"> attackers increasingly use AI to find and exploit vulnerabilities<\/a>. Harness said attackers have moved from disclosure to exploitation in as little as six hours, while vulnerabilities take more than 50 days to remediate on average.<\/p>\n<p>\u201cWe\u2019re at a point where the same AI models helping our customers ship software faster are also what attackers are using to find and exploit vulnerabilities faster,\u201d <a href=\"https:\/\/www.prnewswire.com\/news-releases\/harness-launches-ai-agents-for-machine-speed-vulnerability-response-302855262.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Rahul Sood<\/a>, general manager of application security at Harness, said in the company\u2019s announcement.<\/p>\n<p>  What the AI agents do<\/p>\n<p>According to Harness, its Triage Agent uses CVSS, EPSS and reachability analysis to prioritize vulnerabilities that are more likely to pose real risk. Its Remediation Agent writes and validates a proposed fix before opening a pull request for developer review and approval.<\/p>\n<p>The Zero-Day Agent is aimed at newly disclosed threats. It continuously monitors for zero-days, identifies affected artifacts and pipelines, and prepares a validated fix for review.<\/p>\n<p>Virtual patching provides another layer of protection while a permanent code fix is being completed. When testing identifies a vulnerability, Harness says it can deploy a protective patch without requiring a code change, shielding production while developers work on the underlying fix.<\/p>\n<p>The company is also taking a hybrid approach to vulnerability scanning. Its AI SAST combines deterministic analysis with an AI confidence layer, while LLM Scan Orchestration allows teams to run large language model scanners inside their pipelines.<\/p>\n<p>More scanning can also mean more noise<\/p>\n<p>The challenge Harness is addressing is not simply finding vulnerabilities. AI-based scanners can uncover substantially more potential problems, but that can leave security teams with a much larger queue to investigate.<\/p>\n<p>Harness cites <a href=\"https:\/\/www.channelinsider.com\/news-and-trends\/anthropic-ai-compute-security-glasswing\/\" rel=\"nofollow noopener\" target=\"_blank\">Project Glasswing<\/a> testing in which partners found roughly 10 times more vulnerabilities using LLM-based scanning. Comcast <a href=\"https:\/\/corporate.comcast.com\/stories\/how-frontier-ai-is-changing-the-economics-of-cybersecurity\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported<\/a> that 44% of the critical- and high-severity findings produced during its testing were false positives.<\/p>\n<p>Harness <a href=\"https:\/\/www.harness.io\/blog\/harness-announces-capabilities-that-enable-security-at-machine-speed\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">says<\/a> its own OWASP Java testing reduced false positives by 79%, from 454 to 95, while increasing precision from 74% to 93% and retaining 91% recall. Those results are based on Harness\u2019s internal benchmarking and have not been independently verified.<\/p>\n<p>Harness\u2019 approach could help enterprises <a href=\"https:\/\/www.channelinsider.com\/security\/swimlane-ai-soc-intelligent-routing-costs\/\" rel=\"nofollow noopener\" target=\"_blank\">reduce repetitive security work<\/a>, but faster remediation does not eliminate the risks of automated code changes. A bad fix can introduce a new vulnerability or disrupt production. The company keeps developers in control by requiring human review before remediation pull requests are merged. Its use of existing policy gates, approvals and chain-of-custody controls also gives organizations a way to put limits around the agents.<\/p>\n<p>Read more: As agentic tools spread across security operations,<a href=\"https:\/\/www.channelinsider.com\/security\/black-hat-usa-2026-ai-cybersecurity-announcements\/\" rel=\"nofollow noopener\" target=\"_blank\"> Black Hat USA 2026\u2019s major cybersecurity announcements<\/a> show how vendors are combining automation with governance and new partner service opportunities.<\/p>\n","protected":false},"excerpt":{"rendered":"Software delivery firm Harness wants to fix vulnerabilities before attackers can weaponize them. Harness announced Aug. 19 a&hellip;\n","protected":false},"author":2,"featured_media":146589,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[405,8918,25,7537,313,1627,36211,68662,13709],"class_list":["post-146588","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agents","tag-application-security","tag-artificial-intelligence","tag-artificial-intelligence-agents","tag-cybersecurity","tag-harness","tag-software-delivery","tag-virtual-patching","tag-vulnerability-management"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/146588","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=146588"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/146588\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/146589"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=146588"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=146588"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=146588"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}