2 min read

Visa Open-Sources AI Framework to Speed Software Vulnerability Fixes

The Visa Vulnerability Agentic Harness covers discovery, triage, remediation and validation, with remediation and validation disabled by default.

A security badge rests beside a quiet code review terminal / TokenPost.ai
A security badge rests beside a quiet code review terminal / TokenPost.ai

Visa has open-sourced an artificial intelligence framework designed to help organizations manage software vulnerabilities faster, addressing the work required after security flaws are discovered.

The Visa Vulnerability Agentic Harness (VVAH) covers vulnerability discovery, triage, remediation and validation. Its GitHub implementation uses four phases: discovery and modeling, deep-dive verification, synthesis and reporting, and optional remediation and validation. The default profile disables remediation and validation unless those stages are enabled.

VVAH supports Anthropic Claude, OpenAI-compatible endpoints and open-weight models. Its latest release added closed-loop remediation, flexible model selection and optional real-time progress views.

Some remediation timelines fell from weeks to hours, although no sample size or precise average was provided. The framework had been downloaded by “tens of thousands” of developers worldwide since its June 10 release.

The project followed Visa’s participation in Anthropic’s Project Glasswing. Roughly 50 initial participants collectively identified more than 10,000 high- or critical-severity vulnerabilities after one month of testing. The figure covered Project Glasswing participants collectively and vulnerabilities in systemically important software, not Visa’s network specifically.

The project used Claude Mythos Preview, a restricted artificial-intelligence model for defensive cybersecurity work. The results shifted pressure from finding vulnerabilities toward verifying, disclosing and patching the large number of flaws identified by AI.

“AI is compressing the time between vulnerability discovery and exploitation, which means defenders need a faster, more reliable path to action,” said Rajat Taneja, Visa’s president of technology.

“Finding vulnerabilities is no longer the hardest part. Speed to remediation is the new battleground,” said Carl Rutstein, global head of Visa Consulting & Analytics.

VVAH is available under the Apache 2.0 license. Its documentation calls for human oversight of AI-generated findings and fixes and limits testing to software the user owns or has permission to examine.

Visa’s network processes hundreds of billions of transactions annually across more than 200 countries and territories. Human reviewers remain responsible for confirming severity, choosing remediation paths and approving changes.

Loading…