NNewsGPT ← Home
US

Visa uses AI to find payment network flaws, open-sources security tool

US2 hr ago

Visa has employed Anthropic's Claude Mythos AI model to identify vulnerabilities within its extensive global payment network, which processes transactions across over 200 countries and territories, handles approximately 160 currencies, and connects nearly 5 billion payment credentials to over 175 million merchant locations. The AI model successfully stitched together minor weaknesses into exploit chains, a task traditionally reserved for late-stage penetration testing. Rajat Taneja, Visa's president of technology, explained that the company has now open-sourced the "Visa Vulnerability Agentic Harness," the tool that managed this AI-driven security hunt, allowing other security teams to inspect, adapt, and extend it. This initiative is detailed in a technical white paper that also outlines 12 essential architectural practices for critical infrastructure. Visa's approach to security is built on "pessimism and paranoia," assuming failure and designing defenses accordingly, employing zero-trust architecture, layered defenses, and automated security operations. When invited to test Mythos through Anthropic's Project Glasswing, Visa participated to assess its decades of hardening against AI-speed analysis. Mythos demonstrated an ability to perform system-wide, context-aware analysis, uncovering vulnerabilities deep within the system and identifying issues that become more severe when chained together, with findings clear enough for immediate action. The experience highlighted the need for "agentic defense" in an era of agentic attacks, prompting a reevaluation of existing assumptions beyond traditional static analysis tools. The open-sourced harness is designed as a governed pipeline that directs AI models through structured security tasks with deterministic controls and human oversight, operating across four phases and eleven stages. Key design choices include pre-analysis threat modeling, multi-agent voting for finding convergence, and structured triage artifacts to accelerate the discovery-to-remediation lifecycle. While the harness supports multiple AI models, full remediation and validation currently require Anthropic models due to their file-editing capabilities. Visa is also shifting its security metrics from traditional detection and closure rates to "Mean Time to Adapt" (MTTA), which measures the speed of confirming exploitability, fixing issues, and validating that attack paths are closed. This new metric focuses on actual exposure reduction, acknowledging that many reported vulnerabilities are not actively exploited. Furthermore, Visa is extending its security scrutiny to its supply chain, making AI-specific security posture a requirement for vendors and joining initiatives like IBM and Red Hat's Project Lightwell to harden open-source components.

AI Analysis

Visa's proactive use of advanced AI for internal security testing and subsequent open-sourcing of its "harness" tool represents a significant shift in how critical infrastructure might be secured. By leveraging AI to discover complex exploit chains, Visa is acknowledging that traditional vulnerability scanning methods may be insufficient against sophisticated, AI-driven threats. The decision to open-source the harness, while potentially increasing the attack surface for malicious actors, also fosters a collaborative defense ecosystem, enabling broader industry adoption of advanced security practices. This move highlights a growing recognition that security is not solely about defense-in-depth but also about rapid adaptation and shared intelligence in the face of evolving threats. The emphasis on "Mean Time to Adapt" over traditional metrics suggests a move towards measuring actual resilience and the speed of response to emerging threats, a crucial evolution in the AI era where the pace of both attack and defense is accelerating. This approach could set a precedent for how other large organizations manage supply chain risks and ensure the security posture of their technology partners.

AI-generated to prompt reflection — not editorial opinion, not advice, not a statement of fact. How this works.

Compiled by NewsGPT from VentureBeat. Read the original for full details.