SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Harness launches AI security agents to speed fixes

Harness launches AI security agents to speed fixes

Thu, 20th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Harness has launched a set of AI-based security tools for vulnerability detection, triage and remediation, adding new functions across the software delivery process.

The new products include AI SAST, LLM Scan Orchestration, a Triage Agent, a Remediation Agent, a Zero-Day Agent and virtual patching. Available now within the Harness platform, the tools are designed to help security teams move more quickly from identifying a flaw to deploying a fix.

The release targets a problem that is becoming more urgent as AI models are used by both attackers and defenders. Attackers can move from public disclosure of a vulnerability to an initial exploit in as little as six hours, while the average vulnerability still takes more than 50 days to fix, according to Harness.

Harness also pointed to a growing volume of findings from AI-assisted scanning. Project Glasswing partners have uncovered about 10 times more vulnerabilities with large language model-based scanning, the company said, increasing the backlog for security teams unless triage and remediation also speed up.

What is included

AI SAST combines a deterministic scanning engine with an AI layer intended to reduce false positives and identify issues that conventional tools may miss, according to Harness. LLM Scan Orchestration lets teams using their own large language model scanners run them inside the delivery pipeline and feed results into the same workflow as other findings.

The Triage Agent is designed to sort scanner results and rank findings by likely exploitability. The Remediation Agent generates and validates a fix for a prioritised issue, then opens a pull request for a developer to review and approve.

The Zero-Day Agent monitors for newly disclosed zero-day vulnerabilities, identifies affected pipelines and artifacts in a customer environment, and prepares a validated fix for review, Harness said. Virtual patching is designed to apply a protective patch when a vulnerability is discovered in testing, shielding production systems while a permanent code fix is completed.

The launch builds on Harness's broader effort to bring security functions closer to software delivery workflows. Vulnerability management is often slowed by handoffs between separate tools and teams, the company argued, making it harder to respond quickly as threat volume rises.

Rahul Sood, General Manager of Application Security at Harness, described the shift as a response to changes in how software is attacked and defended. "We're at a point where the same AI models helping our customers ship software faster are also what attackers are using to find and exploit vulnerabilities faster," Sood said. "The only way to close that gap is to make security a first-class part of the delivery pipeline itself, so scanning, prioritization, remediation, and deployment all move together instead of getting stuck in handoffs between disconnected systems. That's the shift we built these agents around, and it's the same shift every enterprise is going to have to make to stay ahead."

Security push

Harness has been expanding its security portfolio since its merger with Traceable in early 2025. More recently, it introduced Agent DLC, which provides governance and chain of custody for AI coding agents across the software delivery lifecycle, according to the company.

It has also added integrations with Kong and Google as part of a broader effort to extend security and governance features across infrastructure and platform environments. Those moves suggest Harness is positioning application security as an embedded part of software delivery rather than a standalone function.

All of the newly launched agents are built on the same reachability data, Harness said. In practice, that means the tools share a common view of whether a vulnerability can be reached or exploited within an application or environment, which should help teams focus on the issues that pose the greatest risk.

That shared workflow is central to the pitch. Rather than requiring separate products for scanning, prioritisation, code fixing and production protection, Harness is offering a chain of tools that can handle each step within the same platform, according to the company.

For software teams, the commercial argument is less about adding another security dashboard and more about reducing the delay between discovery and response. Harness said that could narrow the time between identifying a vulnerability and shipping a fix from weeks to hours.

Sood made that case in a second statement. "For customers, this means the distance between 'we found something' and 'it's fixed and deployed' shrinks from weeks to hours, without adding headcount or a new tool to manage," Sood said. "Every agent in this launch is built on the same reachability data, so teams aren't just moving faster, they're spending that speed on the vulnerabilities that actually matter instead of chasing noise."