Tag: DevSecOps

  • Harness Debuts AI Agents to Fix Vulnerabilities at Machine Speed

    Harness Debuts AI Agents to Fix Vulnerabilities at Machine Speed

    On August 19, 2026, San Francisco-based Harness announced six new security capabilities — AI SAST, LLM Scan Orchestration, a Triage Agent, a Remediation Agent, a Zero-Day Agent, and virtual patching — all available now on its AI Software Delivery Platform. The agents are designed to compress the gap between the roughly six hours attackers now need to weaponize a disclosed vulnerability and the 50-plus days enterprises take on average to fix one.

    The launch landed the same day Palo Alto Networks unveiled its multi-vendor Frontier AI Critical Defense Program to protect critical infrastructure from AI-discovered vulnerabilities, and MarketsandMarkets projected the critical infrastructure protection market will grow from $160.28 billion in 2026 to $206.31 billion by 2031.

    Executive Summary

    Harness is betting that the vulnerability-response problem is no longer a detection problem but a speed problem. Frontier AI models — the most capable large language models — are being used by attackers to find and chain vulnerabilities faster than ever, with first exploits appearing as little as six hours after disclosure. Defenders are gaining the same scanning power: Harness cites Project Glasswing partners surfacing roughly 10 times more vulnerabilities with LLM-based scanning. But more findings without faster remediation just means a bigger backlog.

    The new agents cover the full vulnerability lifecycle inside the delivery pipeline itself: AI SAST pairs deterministic scanning with an AI layer that filters false positives and catches complex flaws like IDOR (insecure direct object references, where an attacker manipulates identifiers to access data they shouldn’t); the Triage Agent prioritizes what is actually exploitable; the Remediation Agent writes, validates, and opens a pull request with a fix; the Zero-Day Agent monitors disclosures around the clock and generates validated fixes often within minutes; and virtual patching shields production immediately with no code changes while the real fix is finished.

    Why it matters: as Harness application-security GM Rahul Sood put it, the same AI models helping customers ship software faster are what attackers use to exploit it faster — and the only way to close that gap is to make security a first-class part of the delivery pipeline rather than a disconnected process. The simultaneous Palo Alto Networks program launch suggests the whole industry has reached the same conclusion on the same day.

    The Six-Hour Exploit Window Breaks the Old Security Model

    The economics of vulnerability management were built on a comfortable assumption: defenders had weeks between a disclosure and real-world exploitation. Harness’s numbers — six hours to first exploit versus more than 50 days to an average fix — show that assumption is dead. When AI can read a vulnerability disclosure and generate a working exploit before most security teams have finished their morning stand-up, any process with human handoffs between scanning, ticketing, triage, and deployment is structurally too slow, regardless of how well each step is staffed.

    This reframes what security products have to sell. For two decades, the pitch was visibility: find more vulnerabilities. Harness’s own framing concedes that visibility now makes things worse — Project Glasswing partners finding 10x more vulnerabilities via LLM scanning simply produces a 10x bigger backlog if remediation speed stays flat. The scarce resource is no longer detection; it is validated, deployable fixes. Products will increasingly be judged on time-from-disclosure-to-deployed-patch, a metric most enterprises today cannot even measure.

    Security Is Collapsing Into the Delivery Pipeline

    Strategically, this launch is a land grab by a DevOps platform into application security territory. Harness’s argument is architectural: standalone scanners produce findings that must cross organizational and tooling boundaries to become fixes, and every boundary adds days. By putting scanning, triage, remediation, and deployment on one platform — with every agent working from the same reachability data, meaning analysis of whether vulnerable code is actually invoked in a given application — Harness claims fixes ship in hours without added headcount. The 2025 Traceable merger, July 2026’s Agent DLC governance launch, and the Kong and Google integrations show this has been a multi-year build, not a feature bolted on for a press cycle.

    The winners and losers logic is straightforward. Platform vendors that own the pipeline (Harness, and by extension GitHub, GitLab, and the cloud providers) gain a structural advantage over point-solution SAST and vulnerability-management vendors, whose findings now have to flow into someone else’s remediation loop. For buyers, the trade-off is the classic platform bargain: faster outcomes and fewer tools to manage, in exchange for deeper dependence on a single vendor.

    A Coordinated Industry Response — and a $206 Billion Market

    Harness did not announce alone. The same morning, Palo Alto Networks introduced the Frontier AI Critical Defense Program, described as a collaboration of leading technology providers to protect critical infrastructure against the rapid rise of AI-discovered vulnerabilities. When the largest pure-play security vendor organizes a multi-vendor defense program on the same day a DevOps platform ships machine-speed remediation agents, the signal is clear: AI-discovered vulnerabilities have moved from a research concern to the organizing threat model of the industry.

    The money follows. MarketsandMarkets projects the critical infrastructure protection market growing from $160.28 billion in 2026 to $206.31 billion by 2031, a 5.2% compound annual growth rate. That is steady rather than explosive growth — but the composition of that spend is what matters. Budgets built around perimeter appliances and manual patch cycles will be re-allocated toward automated response, and vendors positioned on the remediation side of the ledger stand to capture a disproportionate share of it.

    The Trust Problem: Machines Propose, Humans Still Approve

    Harness has kept a human in the loop at the critical moment — the Remediation Agent opens a pull request for a developer to review and approve rather than pushing fixes straight to production. That is the right call for adoption, but it also means the last mile of the process still runs at human speed. If AI agents generate 10x more validated fixes, code review becomes the new bottleneck, and enterprises will face pressure to auto-merge low-risk patches — a governance question this launch raises but does not resolve.

    Virtual patching, which shields production immediately without code changes, is the pragmatic hedge: it buys time at machine speed while humans finish the real fix. The risk to watch is complacency — virtual patches that quietly become permanent, accumulating an invisible layer of compensating controls. The enterprises that win with these tools will be the ones that treat machine-speed response as a bridge to actual remediation, not a substitute for it.

    Background

    Harness began as a continuous-delivery company and has grown into what it brands the AI Software Delivery Platform™ — automating the software lifecycle after code is written, from builds and testing through deployment and cost management. Customers such as United Airlines, Morningstar, and Choice Hotels use it to accelerate releases by up to 75% and cut cloud costs by 60%, and the company is backed by Goldman Sachs, Menlo Ventures, IVP, Unusual Ventures, and Citi Ventures. Its security push dates to the early-2025 merger with API-security firm Traceable and continued through 2026 with Agent DLC governance for AI coding agents and integrations with Kong and Google.

    The market backdrop is an arms race: the same frontier AI models that help developers ship faster let attackers find and chain vulnerabilities in hours, and let defenders surface an order of magnitude more findings than their patching processes were built to absorb. That dynamic — visibility outrunning remediation — is driving both vendor consolidation around delivery pipelines and industry-wide efforts like Palo Alto Networks’ new Frontier AI Critical Defense Program.

    Source: Harness Launches AI Agents for Machine-Speed Vulnerability Response — Harness press release via PR Newswire, August 19, 2026, with same-day context from Palo Alto Networks’ Frontier AI Critical Defense Program announcement and MarketsandMarkets’ critical infrastructure protection market forecast.

  • Grafana’s GitHub Breach Shows How One npm Compromise Cascades Downstream

    Grafana’s GitHub Breach Shows How One npm Compromise Cascades Downstream

    Grafana Labs, the observability software company behind the widely deployed Grafana dashboard platform, has linked a breach of its GitHub environment to the supply chain attack on TanStack npm packages, according to a May 22, 2026 report by Cybersecurity Dive. The disclosure connects a named, major infrastructure vendor to a compromise that began upstream, in an open-source library ecosystem it depends on.

    Executive Summary

    According to the report, Grafana Labs determined that unauthorized access to its GitHub environment — the collection of code repositories, automation, and credentials an engineering organization maintains on GitHub — traced back to the attack on TanStack, a popular family of open-source JavaScript libraries distributed through npm, the default package registry for the JavaScript world.

    The significance is less about Grafana specifically and more about the mechanism. Supply chain attacks work by compromising something many organizations automatically trust — here, a package that developers install by the thousands — and riding that trust into otherwise well-defended companies. When the downstream victim is itself a vendor whose software sits inside thousands of enterprise monitoring stacks, the incident illustrates how a single upstream compromise can put pressure on the entire chain of trust below it.

    As of the publication date, the public reporting establishes the link between the two incidents but not the full scope of what was accessed. That distinction matters, and we treat it carefully below.

    One Package, Many Victims: The Cascade Mechanic

    Modern software is assembled more than it is written. A typical JavaScript application pulls in hundreds of open-source packages from npm, and those packages update automatically in many build pipelines. When attackers compromise a widely used package — by hijacking a maintainer account or its publishing credentials — every downstream developer machine and continuous-integration system that installs the poisoned version becomes a potential foothold.

    The classic goal of such malware is credential harvesting: stealing the API tokens, cloud keys, and GitHub credentials present in developer and build environments. Those stolen credentials then unlock second-stage intrusions that have nothing to do with npm at all. A breach of a company’s GitHub environment traced to a package compromise fits that well-documented pattern, and it is why a single registry incident can produce disclosures from unrelated companies weeks or months later.

    This is the economics that makes supply chain attacks attractive: one successful upstream compromise is a force multiplier, converting a single point of failure into access across an entire user base. Defenders must be right everywhere; the attacker needs one popular package.

    When the Downstream Victim Is Also an Upstream Vendor

    Grafana Labs is not an ordinary downstream victim. Its open-source and commercial products — dashboards, metrics, logs, and alerting — run inside enterprise and infrastructure environments worldwide, often with privileged visibility into those systems. That makes any intrusion into its engineering environment a legitimate concern for its customers, because the nightmare scenario in this class of incident is a SolarWinds-style pivot from a vendor’s development systems into the software it ships.

    It is important to be precise about what the reporting does and does not say. The available source establishes that Grafana linked a GitHub environment breach to the TanStack attack; it does not establish that product code, release artifacts, or customer data were tampered with or taken. Companies in this position typically publish detailed advisories covering scope, affected systems, and required customer actions, and those advisories — not headlines — are what customers should act on.

    Even so, the structural lesson stands: vendors that sit deep in other companies’ infrastructure inherit their dependencies’ risk and re-export their own. Every organization in that chain is simultaneously downstream of someone and upstream of someone else.

    The Open-Source Trust Problem Has No Cheap Fix

    The npm ecosystem has seen this movie before — incidents such as the event-stream backdoor in 2018 and the ua-parser-js hijacking in 2021 followed the same script of compromised publishing and downstream credential theft, and the 2024 xz Utils backdoor showed the same dynamic outside JavaScript entirely. The recurring element is that critical open-source infrastructure is often maintained by small teams whose personal accounts become single points of failure for a global user base.

    The defensive playbook is known, if unevenly adopted: lockfiles and version pinning so new package releases do not flow into builds automatically; short-lived, narrowly scoped tokens in developer and CI environments so stolen credentials expire quickly; package provenance and signing so registries can prove who published what; and secret scanning to catch exposed credentials before attackers do. None of these are exotic — the gap is operational discipline at scale, and incidents like this one are what move them from best practice to procurement requirement.

    Background

    Grafana Labs commercializes Grafana, an open-source observability platform that became a de facto standard for infrastructure dashboards over the past decade; its tools for metrics, logs, and traces are embedded in enterprise, cloud, and data center operations globally. TanStack, meanwhile, is one of the most widely adopted independent open-source library collections in the JavaScript ecosystem, which makes its packages a high-value target for anyone seeking downstream reach.

    Both sit atop npm, a registry serving billions of package downloads weekly, where a long line of incidents — from event-stream in 2018 to ua-parser-js in 2021 — has demonstrated that compromising a single popular package can propagate malicious code into companies that never installed it knowingly. This breach is best read as the latest chapter in that ongoing story rather than an isolated event.

    Source: Grafana Labs links GitHub environment breach to TanStack npm supply chain attack — Cybersecurity Dive’s May 22, 2026 report connecting Grafana’s GitHub intrusion to the upstream TanStack npm package compromise.