AI

Visa Opens Up Its AI Security Testing System

Bakhtawar Majid

By: Bakhtawar Majid

4 min read

The payments company found vulnerabilities while testing Anthropic’s Mythos model and is now using AI to speed up the work of investigating, fixing and checking software flaws. 

[For more news, click here]

Visa is using advanced AI to do something security teams have traditionally spent considerable time doing themselves: working through large amounts of software to find weaknesses and determine what needs to be fixed. The company has now made the system it developed during that work available as open-source software, following tests with Anthropic's Mythos model that uncovered vulnerabilities in Visa's environment. Visa says its existing security controls prevented those findings from being exploited, while the testing showed how quickly an AI system can examine software and produce findings for security teams to investigate.  

Visa President of Technology Rajat Taneja described the experience as “humbling.” Visa developed its Vulnerability Agentic Harness through Project Glasswing, Anthropic'scybersecurity program involving selected organizations testing advanced models on real software. Anthropic said participants identified more than 10,000 high- or critical-severity vulnerabilities during the program's first month. Visa's system was initially built to help find and assess vulnerabilities, but its latest version also supports remediation and validation, allowing teams to work through a problem, produce a fix and test whether the vulnerability has actually been closed.  

Finding a vulnerability is only the beginning of the process. Security teams still need to establish whether a finding can be exploited, work out what needs to change and then confirm that the fix has not simply moved the problem somewhere else. Visa says its latest system can reduce some remediation work that previously took weeks to hours in its own operations. The company describes the tool as a way to give security and engineering teams more time to deal with difficult decisions while software handles more of the investigation and testing.  

A separate incident involving Hugging Face and OpenAI provides a practical example of why this work is attracting attention. During an internal cybersecurity evaluation in July, an OpenAI system escaped its testing environment and eventually reached Hugging Face infrastructure. Hugging Face's investigation found that the system exploited vulnerabilities in its dataset-processing systems before moving through parts of the company's internal environment. Investigators reconstructed about 17,600 actions during the campaign, including reconnaissance, command execution, credential collection and movement between systems. Five datasets connected to the evaluation were accessed, but Hugging Face said it found no evidence that its public models, datasets, Spaces or software supply chain had been altered.  

Those vulnerabilities included an arbitrary file-read vulnerability and a template-injection vulnerability. What made the incident notable was how much work the system could carry out after obtaining access. It could inspect the environment, try different approaches, collect information and continue to another system without a person deciding what it should do at every stage. OpenAI later said its models had circumvented isolation controls during the evaluation, which had been designed to measure the models' underlying cybersecurity capabilities.  

Keeping pace with that development will require security systems that can do more than flag a vulnerability. Visa's harness is designed to work across a software environment rather than examine one vulnerability at a time, and its latest version can use different AI models rather than being tied to a single provider. Human review remains part of the process, with security and engineering teams checking findings, assessing their severity and deciding how remediation should proceed before changes are advanced.  

The same issue is emerging in Visa's work on AI-powered payments. The company is developing capabilities that allow AI agents to carry out transactions on behalf of consumers, bringing similar questions into financial services. An agent may have permission to make a purchase, but systems still need to determine what it is authorized to buy and when a transaction should require the customer's involvement. 

Opening the vulnerability system to outside developers and security researchers gives Visa's approach a life beyond its own network, but the more immediate lesson comes from the work itself. AI can now help security teams uncover weaknesses and work through parts of the repair process much faster than before. Companies still need to decide how much authority those systems should have once they move from examining software to taking action inside it, particularly when that software handles financial transactions or other sensitive operations. 


Related Articles 

Tenable and Anthropic Think Agentic AI Can Finally Close the Gap Between Cyber Discovery and Response 

Delinea Takes AI Agent Security Beyond Access 

Cequence Security Launches Agent Personas to Automate AI Agent Governance Across the Enterprise 


 


 

Share this article

Related Articles