AI IndustryVisaJul 28, 2026 23:27 UTC

Visa Detects Payment Network Vulnerabilities with AI, Releases Tool Publicly

On June 10, 2025, Visa conducted security verification of its payment network infrastructure using Anthropic's AI model "Claude Mythos" and publicly released the tool "Visa Vulnerability Agentic Harness" on GitHub as open source. The testing was conducted as part of Anthropic's "Project Glasswing," enabling the discovery of vulnerabilities embedded deep within the stack in a cascading manner. The company also published a technical white paper and 12 design principles for critical infrastructure, providing a foundation for other organizations to leverage similar methodologies.

Visa Detects Payment Network Vulnerabilities with AI, Releases Tool Publicly

Visa applied Anthropic's AI model "Claude Mythos" to its payment network infrastructure to conduct security vulnerability detection. The tool "Visa Vulnerability Agentic Harness (VVAH)" used in this process was released as open source on GitHub on June 10, 2025. Additionally, the company published a technical white paper outlining architectural details, lessons learned, and 12 design principles for critical infrastructure.

Visa's payment network covers more than 200 countries and regions and processes fund transfers in approximately 160 currencies. It also connects approximately 5 billion payment authentication records with more than 175 million merchants, serving as the foundation for massive transaction volumes on a daily basis. For infrastructure of this scale, the company has built zero-trust architecture (a security model designed on the premise of "not trusting" users and devices), multi-layered defense, and automated security operations over many years.

This testing was conducted as participation in "Project Glasswing," which Anthropic launched to call upon organizations operating critical software for practical evaluation of Mythos. According to Anthropic, across all participating organizations in this project, more than 10,000 critical and high-severity vulnerabilities were detected within one month from the start of testing. Visa participated in this project to verify its defense level at AI speed, as explained by Rajat Taneja, Visa's Chief Technology Officer, at VB Transform 2026.

One characteristic that Mythos demonstrated within Visa's environment was the ability to understand vulnerabilities embedded deep within the stack not in isolation but as chains. The discovery that seemingly minor individual issues can combine to create serious attack paths was something that traditional penetration testing had difficulty surfacing until late in the process. While some findings received critical (highest severity) ratings, Visa explained that through zero-trust controls, network segmentation, and multi-layered safeguards, it was able to block these chains before external attackers could take action.

The released VVAH is designed as a "reference implementation" that any security team can reference, modify, and extend. Taneja announced this release jointly with Subra Kumaraswamy, Chief Information Security Officer. Kumaraswamy joined Visa in 2013 and has overseen technology strategy, product engineering, and global infrastructure since 2019.

The use of AI agents for security verification of critical infrastructure is accelerating across the industry. Traditional human-led penetration testing is time-consuming and costly, making it difficult to continuously cover vast systems in their entirety. AI is positioned as offering the potential to analyze wider ranges in shorter timeframes. However, assuming that similar AI tools can also be utilized by attackers, the establishment of continuous verification systems for the defense side to take the initiative becomes a critical future challenge.

Visa's decision to release the tool as open source carries significance beyond simply disclosing the company's efforts. It facilitates adoption of similar methodologies by other financial institutions and critical infrastructure operators, while serving as a foundation for accumulating knowledge about AI-driven security techniques across the industry. Whether the 12 design principles presented in the technical white paper will function as a common guide in scaling these efforts is another important point to watch in the future.

#GenerativeAI#AIAgent#Cybersecurity#Anthropic#OpenSource#FinancialInfrastructure#VulnerabilityAssessment
AI issue Staff

This article is an original work independently written and edited by the AI issue editorial team based on factual reporting. © AI issue. Unauthorized reproduction, redistribution, or use for AI training is prohibited.

Comments

Log in to comment