Software delivery firm Harness wants to fix vulnerabilities before attackers can weaponize them.
Harness announced Aug. 19 a set of AI-powered security capabilities designed to move vulnerabilities from detection through remediation and deployment with fewer manual handoffs, potentially helping MSPs and MSSPs manage customer vulnerability backlogs.
The launch includes AI SAST, LLM scan orchestration, a Triage Agent, a Remediation Agent, a Zero-Day Agent and virtual patching. Harness says the tools are designed to work within the software delivery pipeline rather than operate as disconnected security products.
The push comes as attackers increasingly use AI to find and exploit vulnerabilities. Harness said attackers have moved from disclosure to exploitation in as little as six hours, while vulnerabilities take more than 50 days to remediate on average.
“We’re at a point where the same AI models helping our customers ship software faster are also what attackers are using to find and exploit vulnerabilities faster,” Rahul Sood, general manager of application security at Harness, said in the company’s announcement.
What the AI agents do
According to Harness, its Triage Agent uses CVSS, EPSS and reachability analysis to prioritize vulnerabilities that are more likely to pose real risk. Its Remediation Agent writes and validates a proposed fix before opening a pull request for developer review and approval.
The Zero-Day Agent is aimed at newly disclosed threats. It continuously monitors for zero-days, identifies affected artifacts and pipelines, and prepares a validated fix for review.
Virtual patching provides another layer of protection while a permanent code fix is being completed. When testing identifies a vulnerability, Harness says it can deploy a protective patch without requiring a code change, shielding production while developers work on the underlying fix.
The company is also taking a hybrid approach to vulnerability scanning. Its AI SAST combines deterministic analysis with an AI confidence layer, while LLM Scan Orchestration allows teams to run large language model scanners inside their pipelines.
More scanning can also mean more noise
The challenge Harness is addressing is not simply finding vulnerabilities. AI-based scanners can uncover substantially more potential problems, but that can leave security teams with a much larger queue to investigate.
Harness cites Project Glasswing testing in which partners found roughly 10 times more vulnerabilities using LLM-based scanning. Comcast reported that 44% of the critical- and high-severity findings produced during its testing were false positives.
Harness says its own OWASP Java testing reduced false positives by 79%, from 454 to 95, while increasing precision from 74% to 93% and retaining 91% recall. Those results are based on Harness’s internal benchmarking and have not been independently verified.
Harness’ approach could help enterprises reduce repetitive security work, but faster remediation does not eliminate the risks of automated code changes. A bad fix can introduce a new vulnerability or disrupt production. The company keeps developers in control by requiring human review before remediation pull requests are merged. Its use of existing policy gates, approvals and chain-of-custody controls also gives organizations a way to put limits around the agents.
Read more: As agentic tools spread across security operations, Black Hat USA 2026’s major cybersecurity announcements show how vendors are combining automation with governance and new partner service opportunities.





