Product2 distinct publishers3 min readUpdated
New agents scan, triage and open the pull request, leaving a developer to approve. The virtual patching alongside them is the tell: fixes average 50 days, exploits can land in six hours.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
Harness has launched a set of AI agents that find software vulnerabilities, judge which ones are exploitable and write the patch, with the developer's remaining job being to approve the fix before it ships [1]. Shipping alongside them is virtual patching, which blocks exploitation in production without any code change until the real fix lands [6], and that feature is the more honest part of the announcement.
The pipeline is straightforward to describe. A deterministic static scanner runs first, then an AI layer strips out noise; Harness says that layer cuts false positives and catches logic flaws such as missing authorization checks that conventional tools tend to miss [2]. What survives goes to a Triage Agent that narrows the pile to findings the software judges exploitable [3]. A Remediation Agent then drafts a fix, validates it, and opens a pull request against the vulnerable function [4]. A separate Zero-Day Agent monitors newly disclosed flaws around the clock and flags affected systems, according to the company often with a validated fix ready within minutes [5]. Customers already running their own large language model scanners can pipe those results into the same triage workflow [7].
The arithmetic behind the product is the part worth keeping. Harness says attackers using frontier models can move from a public disclosure to a working exploit in as little as six hours, while the average vulnerability takes more than 50 days to fix [8][9]. That is roughly a 200-fold gap between how fast the attack arrives and how fast the patch does [19]. No amount of agentic pull request authoring closes that on its own, which is why virtual patching exists: it buys time rather than fixing anything. Harness also says its own testing found frontier models surfacing about 10 times more vulnerabilities than conventional scanners, and argues most security teams have no realistic way to work through that much output [10]. Both halves of the pitch point the same way. The new bottleneck is not detection, and it is not even authoring. It is human approval and deployment.
The company frames the models involved as "Mythos-class," a reference to Claude Mythos Preview, which Anthropic has kept out of general release because of how well it finds and chains software vulnerabilities; defenders have had access since April through Project Glasswing [11]. Chief Executive Jyoti Bansal said attackers are using the same models that help Harness customers ship software, and that security has to become "a first-class part of the delivery pipeline itself," with work currently stalling in handoffs between disconnected scanning, ticketing and deployment systems [12][13]. Rahul Sood, general manager of application security, said the agents all draw on one set of reachability data, keeping teams off findings that were never exploitable, and that the discovery-to-deployment window should shrink "from weeks to hours" [14].
Sood arrived with Harness's September acquisition of Qwiet AI, whose Code Property Graph technology underpins the scanning [15]. That deal sits inside an 18-month security buildout that also included a merger with API security firm Traceable announced in February 2025 and Agent DLC, shipped July 21 to audit and govern AI coding agents [16]. Harness last raised $240 million at a $5.5 billion valuation in December [18].
Watch whether virtual patches become permanent in practice, because a control that blocks exploitation without a code change removes the urgency that used to force the merge. Watch approval throughput too: if the scanners really return 10 times more findings [10], the queue of agent-authored pull requests will test whether one reviewer per fix is a workable model. The agents and virtual patching are available to Harness customers now [17].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Harness Inc. launched a set of AI agents that find software vulnerabilities and write the patches, with developers approving the fixes before anything ships.
Harness AI SAST runs a deterministic static scanner, then applies an AI layer to strip out noise; Harness said that layer cuts false positives and catches logic flaws such as missing authorization checks, which conventional tools tend to miss entirely.
Findings that survive the AI layer go to a Triage Agent, which narrows the pile to findings the software judges exploitable.
A Remediation Agent drafts a fix, validates it and opens a pull request against the vulnerable function.
A Zero-Day Agent watches newly disclosed flaws around the clock and flags affected systems across a customer environment, often with a validated fix ready within minutes.
Virtual patching blocks exploitation in production until the code fix ships, and requires no code changes.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Vendor-sourced, no independent testing
Two trade outlets describe the same product mechanics consistently, which firms up what shipped. But every load-bearing number - six hours to exploit, 50-plus days to fix, 10x more findings, fixes within minutes - originates with Harness, with no methodology, dataset or third-party benchmark, and the two sources even give different exploit-window figures. The Anthropic Mythos Preview and Project Glasswing assertions rest on a single publisher with no cited primary source.
Announced availability only
The only adoption signal is that the agents and virtual patching are stated to be available to Harness customers on launch day, reported by both outlets. There are no named customers, deployment counts, pipeline volumes, remediation outcomes or pricing disclosures, and one publisher explicitly says it is unclear how far DevSecOps teams are revisiting tooling.
Claims run ahead of evidence
The gap is between agentic promises - exploitable-only triage, validated fixes in minutes, remediation windows shrinking from weeks to hours - and a body of evidence that consists of a launch announcement plus unverified vendor statistics. Notably, the virtual patching capability implicitly concedes that code fixes will not arrive inside the stated exposure window, which pulls the score back from the extreme: the vendor is not claiming the code-fix problem is solved.
Vendor launch with capital and M&A stakes
Both articles derive from a coordinated vendor announcement published minutes apart, with quotes almost entirely from Harness executives. Harness has direct commercial incentive to amplify AI-enabled attack speed, since the threat framing sells the pipeline it is monetizing, and it is validating an acquisition-led buildout (Traceable, Qwiet AI) against a $5.5 billion valuation. The only non-vendor voice is an analyst from a research firm whose commentary supports the vendor's thesis.
Confident on what shipped, not on effect
Two independent publishers agree on the product surface, dates and availability, so confidence in the launch facts is high. Confidence in the operational significance is low: no adoption metrics, no independent measurement of triage precision or remediation latency, and single-sourced external claims about frontier models pull the overall figure toward the middle.
build
Harness bundles six security agents into its pipelines, betting deployment control beats scanner quality1 distinct publisher
product
Claude Code's 50% boost expires tonight, and your sprint capacity was a promotion1 distinct publisher
product
Adronite's Codistry makes token count, not context window, the axis of competition2 distinct publishers
build
Claude's system prompt grew ninefold in two years. Version yours like code.1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026
1 article · August 19, 2026