{"id":4956,"date":"2026-08-27T20:15:14","date_gmt":"2026-08-27T20:15:14","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/08\/27\/sonar-ai-agent-discovers-vulnerabilities-hidden-in-business-logic-workflows\/"},"modified":"2026-08-27T20:15:14","modified_gmt":"2026-08-27T20:15:14","slug":"sonar-ai-agent-discovers-vulnerabilities-hidden-in-business-logic-workflows","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/08\/27\/sonar-ai-agent-discovers-vulnerabilities-hidden-in-business-logic-workflows\/","title":{"rendered":"Sonar AI Agent Discovers Vulnerabilities Hidden in Business Logic Workflows"},"content":{"rendered":"<div><img data-opt-id=368520493  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/08\/Sonar1-770x330-1.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=339441229  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/08\/Sonar1-770x330-1-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p>Sonar today made available an artificial intelligence (AI) agent designed to discover vulnerabilities and business logic flaws that pose the greatest risk to an organization should they be exploited.<\/p>\n<p>The <a href=\"https:\/\/www.sonarsource.com\/company\/press-releases\/sonar-launches-sonarqube-hunter-agent\/\">SonarQube Hunter Agent<\/a> first analyzes an entire codebase to find three categories of flaws: broken access control, business-logic vulnerabilities, and authentication or session-management issues.<\/p>\n<p>Satinder Khasriya, a technical product marketing manager for Sonar, said that, historically, discovering these issues would have required manual testing or a penetration test. The AI agent developed by Sonar automates those investigations by tracing how code and data move through a system in a way that can now run on demand, he added.<\/p>\n<p>Additionally, SonarQube Hunter Agent is able to identify the developer who created any piece of code, with verified issues that are surfaced within a DevSecOps workflow via integrations with continuous integration\/continuous delivery (CI\/CD) platforms.<\/p>\n<p>That\u2019s critical because as advances in AI now make it possible for cybercriminals to discover and exploit vulnerabilities in a matter of hours, DevSecOps teams need to be able to identify issues at machine speed versus waiting until they might be discovered using legacy scanning tools, noted Khasriya. The time to exploitation after a vulnerability has dramatically shrunk, he added.<\/p>\n<p>Deterministic scanning tools are good for catching flaws that look wrong in the code, such as injection vulnerabilities, unsafe data flows, and insecure patterns, but some vulnerabilities aren\u2019t detectable in code, he added. A privilege escalation issue, for example, only becomes visible when there is an understanding of how the code is supposed to function, said Khasriya.<\/p>\n<p>As the threat landscape continues to evolve, it is becoming more critical than ever to discover and verify issues as early as possible in the software development lifecycle, noted Khasriya. Every line of code is now part of the attack surface that DevSecOps teams need to defend, he added. The challenge is that the rate at which that code is being created is overwhelming existing DevSecOps workflows, he added.<\/p>\n<p>It\u2019s already apparent each software engineering team will now need to revisit those workflows sooner than later. Historically, many application development teams might have allocated a few hours a month to creating a patch that might not be deployed for months. In some cases, the exploit of a vulnerability is now being developed faster than the patch needed to remediate it. DevSecOps teams are simultaneously trying to eliminate vulnerabilities in new code while also having to pay down massive amounts of technical debt that has been allowed to accrue for decades. Software engineering teams will need to be able to continuously deploy patches in near real time as quickly as possible, assuming, of course, the patch itself has been verified to be free of malware.<\/p>\n<p>Hopefully, there won\u2019t require multiple application security incidents before organizations allocate the resources needed to safely deploy applications in the AI era. In the meantime, however, DevSecOps teams might be well-advised to, while continuing to hope for the best, prepare now for the worst.<\/p>\n<p><a href=\"https:\/\/devops.com\/sonar-ai-agent-discovers-vulnerabilities-hidden-in-business-logic-workflows\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>Sonar today made available an artificial intelligence (AI) agent designed to discover vulnerabilities and business logic flaws that pose the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4957,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-4956","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4956","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=4956"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4956\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/4957"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=4956"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=4956"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=4956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}