Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

AI

Harness Adds AI Agents to Automate DevSecOps Workflows at Machine Speed

Harness today added multiple artificial intelligence (AI) agents and a virtual patching capability to its portfolio to automate DevSecOps workflows at a time when the number of vulnerabilities being discovered in code continues to exponentially increase. The AI agents include one that has been added to the static application security testing (SAST) tool that Harness […]

Harness Adds AI Agents to Automate DevSecOps Workflows at Machine Speed

Harness has incorporated artificial intelligence (AI) agents and a virtual patching capability into its suite of tools to streamline DevSecOps workflows, addressing the rapidly escalating number of vulnerabilities discovered in code. The AI agents include a SAST tool enhancement and triage agents that prioritize remediation efforts based on exploitability, generate a fix, and open a pull request for developer approval.

DevSecOps teams may also integrate additional AI scanners into their pipelines. Additionally, a Zero-Day Agent continuously monitors threat intelligence feeds for zero-day vulnerabilities, swiftly identifying affected pipelines and artifacts and generating a validated fix within minutes. Harness general manager Rahul Sood emphasized that these enhancements enable DevSecOps teams to respond "at machine speed," a critical aspect given the potential for advanced AI models to quickly uncover thousands of vulnerabilities in applications, thereby allowing cybercriminals to exploit them in a short span of hours.

Many DevSecOps teams are also underestimating the extent to which their applications could become collateral damage in AI-driven cyberattacks against other organizations, noted Sood. Sood explained that the challenge lies in the high number of false positives generated by AI tools, which Soot's team addressed by combining AI's probabilistic capabilities with a deterministic platform to validate vulnerability exploitability.

This approach reduces AI tokens consumption during code scanning. Futurum Group's Mitch Ashley highlighted that DevSecOps teams are overwhelmed by the pace of vulnerability findings and cannot act fast enough. Harness integrates triage and remediation directly into the pipeline, ensuring fixes travel with the release. Ashley pointed out that the machine-speed generation model necessitates control over the code creation process.

While the immediate challenge for DevSecOps teams may be prioritizing which applications to fix first amidst the looming AI-enabled cyberattacks, the long-term solution could be an improvement in overall application security as DevSecOps teams address long-standing technical debt issues.

Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at devops.com →

More in AI

Beyond the Chat Box: OpenAI's OS-level Agent and Its Plaintext Problem

The agent is leaving the chat window and moving into the operating system. OpenAI's new "Computer History" feature for the ChatGPT macOS app creates a searchable timeline of your actions by tracking…

  • OpenAI introduces Computer History feature in ChatGPT macOS app
  • Plaintext database of user activity poses security risks
  • Feature enables prompt injection through access to user's digital life

More from Wednesday 19 August →