Visa open-sources AI-powered cyber defense system after vulnerabilities exposed

visa building

Visa open-sources AI-powered cyber defense system after vulnerabilities exposed

The payments giant released its Vulnerability Agentic Harness after AI stress-testing uncovered more than 10,000 critical flaws across its global network in a single month

Visa just handed the entire enterprise world a free cybersecurity toolkit, and the reason it exists is slightly terrifying.

The payments giant open-sourced its Visa Vulnerability Agentic Harness, or VVAH, in June 2026 after a collaboration with Anthropic’s Project Glasswing revealed more than 10,000 high and critical vulnerabilities across industry systems in the first month of testing alone. The tool, released under an Apache 2.0 license, is designed to find, prioritize, fix, and verify security flaws using an AI-driven pipeline.

Advertisement

How a stress test became a product launch

The backstory starts in April 2026, when Visa joined Anthropic’s Project Glasswing. The initiative involved deploying Anthropic’s Claude Mythos AI model against Visa’s sprawling global payment infrastructure, a network spanning over 200 countries, roughly 160 currencies, and nearly 5 billion payment credentials.

Rather than quietly patch things and move on, Visa built VVAH as a structured response framework. The system operates as a four-phase pipeline covering discovery, triage, remediation, and validation. It uses a zero-trust architecture, meaning every component assumes it’s already been compromised and verifies accordingly. The framework also bakes in deterministic controls and human oversight at each stage.

VVAH was open-sourced around June 10, 2026. By mid-July, the GitHub repository had accumulated roughly 595 stars. By late August, that number had cleared 2,300. Visa has recorded tens of thousands of downloads globally since launch.

The August upgrade changed the game

On August 27, 2026, Visa pushed a significant update to the framework. The new version added automated remediation and validation features, meaning VVAH can now not only find and categorize vulnerabilities but also propose and implement fixes, then verify those fixes actually work. The automated remediation capabilities have significantly compressed response times for vulnerability fixing.

Why open-source, and why now

Visa has also expanded its consulting services around the framework, building out cybersecurity advisory offerings that help enterprises implement VVAH and integrate it with existing security infrastructure. The open-source tool is free. The expertise to deploy it correctly at scale, less so.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.
Visa open-sources AI-powered cyber defense system after vulnerabilities exposed
Visa open-sources AI-powered cyber defense system after vulnerabilities exposed

The payments giant released its Vulnerability Agentic Harness after AI stress-testing uncovered more than 10,000 critical flaws across its global network in a single month

visa building

Visa just handed the entire enterprise world a free cybersecurity toolkit, and the reason it exists is slightly terrifying.

The payments giant open-sourced its Visa Vulnerability Agentic Harness, or VVAH, in June 2026 after a collaboration with Anthropic’s Project Glasswing revealed more than 10,000 high and critical vulnerabilities across industry systems in the first month of testing alone. The tool, released under an Apache 2.0 license, is designed to find, prioritize, fix, and verify security flaws using an AI-driven pipeline.

Advertisement

How a stress test became a product launch

The backstory starts in April 2026, when Visa joined Anthropic’s Project Glasswing. The initiative involved deploying Anthropic’s Claude Mythos AI model against Visa’s sprawling global payment infrastructure, a network spanning over 200 countries, roughly 160 currencies, and nearly 5 billion payment credentials.

Rather than quietly patch things and move on, Visa built VVAH as a structured response framework. The system operates as a four-phase pipeline covering discovery, triage, remediation, and validation. It uses a zero-trust architecture, meaning every component assumes it’s already been compromised and verifies accordingly. The framework also bakes in deterministic controls and human oversight at each stage.

VVAH was open-sourced around June 10, 2026. By mid-July, the GitHub repository had accumulated roughly 595 stars. By late August, that number had cleared 2,300. Visa has recorded tens of thousands of downloads globally since launch.

The August upgrade changed the game

On August 27, 2026, Visa pushed a significant update to the framework. The new version added automated remediation and validation features, meaning VVAH can now not only find and categorize vulnerabilities but also propose and implement fixes, then verify those fixes actually work. The automated remediation capabilities have significantly compressed response times for vulnerability fixing.

Why open-source, and why now

Visa has also expanded its consulting services around the framework, building out cybersecurity advisory offerings that help enterprises implement VVAH and integrate it with existing security infrastructure. The open-source tool is free. The expertise to deploy it correctly at scale, less so.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.