TL;DR — Key Takeaways
- Harness is adding AI agents to automate vulnerability triage, remediation and pull request creation across DevSecOps workflows.
- A new Zero-Day Agent continuously monitors threat intelligence and identifies affected pipelines and artifacts when new vulnerabilities emerge.
- Harness is also introducing virtual patching, allowing teams to mitigate vulnerabilities without immediately changing application code.
Harness today added multiple artificial intelligence (AI) agents and a virtual patching capability to its portfolio to automate DevSecOps workflows at a time when the number of vulnerabilities being discovered in code continues to exponentially increase.
The AI agents include one that has been added to the static application security testing (SAST) tool that Harness already provides. In addition, there is now a set of AI agents that automatically triage scanner findings to prioritize remediation efforts based on exploitability, create and validate a fix, and open a pull request for a developer to review and approve. DevSecOps teams can also opt to add their own AI scanners within their pipelines.
There is also now a Zero-Day Agent that monitors threat intelligence feeds for newly disclosed zero-days on a 24/7 basis. Once a zero-day vulnerability is discovered, the AI agent instantly identifies every affected pipeline and artifact and generates a validated fix ready for review within minutes.
Finally, Harness has added a capability that enables DevSecOps teams to apply a virtual patch the moment a vulnerability is discovered during testing that requires no code changes.
Rahul Sood, general manager of application security at Harness, said collectively these additions make it possible for DevSecOps teams to respond to issues at machine speed. That’s crucial at a time when advanced AI models are now capable of discovering thousands of vulnerabilities in applications that cybercriminals can now create exploits for them in a couple of hours, he added.
Many DevSecOps teams are also underestimating to what degree their applications may now become collateral damage when cyberattacks enabled by AI impact organizations that might not have been the initial target, noted Sood.
The challenge that DevSecOps teams are encountering as they attempt to use AI to discover many of those vulnerabilities themselves is the number of false positives those tools generate. By incorporating AI agents into a SAST tool it becomes possible to combine the probabilistic capabilities of an AI agent with a deterministic platform that validates whether a vulnerability is actually exploitable, said Sood. That approach also provides the added benefit of reducing the number of tokens that would otherwise be consumed by an AI agent as code is scanned, he added.
Mitch Ashley, vice president and practice lead for software lifecycle engineering at the Futurum Group, said DevSecOps teams in the AI era are now drowning in vulnerability findings they can’t act on fast enough. Harness, in effect, is moving triage and remediation into the pipeline that already ships the code so the fix now travels with the release, he added.
Periodic scanning was built for code humans wrote at human speed, noted Ashley. Machine-speed generation breaks that model, which means DevSecOps teams now need to have control the moment code is created, not at the next scan window, he added.
It’s not clear to what degree DevSecOps teams are revisiting existing workflows, tools and platforms to address what has become a vulnerability management crisis, but for most it’s now more a question of when and to what degree rather than if. In fact, the issue in the short term at least may be prioritizing which applications to fix first on the assumption that DevSecOps teams will not be able to remediate every issue before a wave of AI-enabled cyberattacks are launched.
On the plus side, however, it may also turn out that in the longer term the overall state of application security may finally improve as DevSecOps teams finally address technical debt issues that have been kicked down the proverbial road for far too long.
Frequently Asked Questions
What new AI capabilities has Harness introduced?
Harness added AI agents for SAST, vulnerability triage, remediation, fix validation and pull request creation, along with a Zero-Day Agent for monitoring newly disclosed vulnerabilities.
What does the Harness Zero-Day Agent do?
It monitors threat intelligence feeds around the clock, identifies pipelines and artifacts affected by newly disclosed zero-day vulnerabilities and generates validated fixes for review.

