{"id":77082,"date":"2026-06-17T15:22:31","date_gmt":"2026-06-17T15:22:31","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/77082\/"},"modified":"2026-06-17T15:22:31","modified_gmt":"2026-06-17T15:22:31","slug":"legit-security-brings-agentic-ai-to-appsec-remediation-and-risk-reduction","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/77082\/","title":{"rendered":"Legit Security brings agentic AI to AppSec remediation and risk reduction"},"content":{"rendered":"<p><a href=\"https:\/\/www.helpnetsecurity.com\/tag\/legit-security\/\" rel=\"nofollow noopener\" target=\"_blank\">Legit Security<\/a> has launched new remediation agents that independently prioritize issues, generate fixes, open pull requests, and confirm results using context learned from each organization\u2019s distinct codebase.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/06\/Legit-SAST_remediation_agent.webp\" class=\"aligncenter\" alt=\"Legit Security remediation agents\" title=\"SAST remediation agent\"\/><\/p>\n<p>As AI allows attackers to exploit vulnerabilities faster than ever, rapid remediation becomes critical. As part of Legit\u2019s agentic AppSec platform, these agents offer parallel remediation across code bases, critical when a common authentication bypass vulnerability is introduced through reused code and propagated across multiple services, along with using business context to prioritize the real threats, and create the right fix, regardless of which AppSec testing tools are deployed.<\/p>\n<p>AI-first development has fundamentally changed the math on application security, necessitating an entirely new approach to AppSec. Consider:<\/p>\n<p><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/03\/13\/claude-code-openai-codex-google-gemini-ai-coding-agent-security\/\" rel=\"nofollow noopener\" target=\"_blank\">AI coding agents<\/a> account for most of the committed code<br \/>\nAI generated code contains 2.74 times more vulnerabilities than human-written code<br \/>\nThe median time to remediate a vulnerability is 252 days, nearly six times longer than attackers need to move from disclosure to exploitation<br \/>\nAttackers equipped with new frontier models exploit new vulnerabilities within minutes of deployments<\/p>\n<p>The bottom line: the faster teams ship with AI, the faster risk compounds \u2013 and the faster attackers execute exploitation campaigns. These trends collide to create enormous risk that must be solved with automated, intelligent, agentic tools<\/p>\n<p>\u201cSecurity teams aren\u2019t losing the war because they lack talent. They\u2019re losing because the model has changed completely, but AppSec testing tools have stayed the same,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/ronifuchs\/\" target=\"_blank\" rel=\"nofollow noopener\">Roni Fuchs<\/a>, CEO at Legit. \u201cLegit\u2019s new remediation agents were built for this reality by offering AI-speed remediation centered on the context of your business and codebase, so you can trust them.\u201d<\/p>\n<p>Key features: Legit Remediation agents<\/p>\n<p>Unlike general-use AI coding tools like Cursor, Claude Code and GitHub Copilot, Legit\u2019s agents have the security knowledge and business context to generate production fixes, rather than patches. In addition, Legit\u2019s remediation agents:<\/p>\n<p>Unified risk posture: Legit\u2019s stores the full risk posture of your codebases and apps, created from continuous scanning across the SDLC and the ingestion of risk signal from 3rd party tools. LLMs and coding agents do not have native access to this data.<br \/>\nKnow what really matters: Legacy AppSec tools find volumes of issues without clear prioritization. Legit\u2019s agents are informed by each customer\u2019s distinct environment so only issues that really matter, prioritized by factors such as reachability, exploitability and production status, reach the remediation queue.<br \/>\nClose complete attack surface gaps: Vulnerabilities rarely live in a single repo; a critical CVE can exist across dozens of services simultaneously. Legit\u2019s agents open pull requests across every affected repo in parallel, to close every gap in the attack surface.<br \/>\nValidate before opening a PR: Legit\u2019s agents run tests, confirm the remediation held, and then create the PR with a plain-language explanation of what was fixed and why.<br \/>\nCreate auditable records of agent activity: Legit records every action its remediation agents take \u2013 from the original finding to the PR, the validated fix, and what engineering did with it, providing a complete, auditable record of activity.<\/p>\n<p>\u201cSecurity teams tell us they\u2019ve tried pointing AI coding tools at their vulnerability backlogs, but the results are thousands of patches that lack context and aren\u2019t validated, some even try to fix false positives, which wastes a lot of time,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/yoavstahl\/\" target=\"_blank\" rel=\"nofollow noopener\">Yoav Stahl<\/a>, vice president of product at Legit. \u201cLegit\u2019s agents know your codebase, your risk profile, and your organizational policies, so when we deliver a fix, we know it works for you.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Legit Security has launched new remediation agents that independently prioritize issues, generate fixes, open pull requests, and confirm&hellip;\n","protected":false},"author":2,"featured_media":20114,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[405,7537,42190],"class_list":["post-77082","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agents","tag-artificial-intelligence-agents","tag-legit-security"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/77082","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=77082"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/77082\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/20114"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=77082"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=77082"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=77082"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}