Urgent.News

What's breaking now, across thousands of outlets.

AI

Visa ships a security AI that patches production code before any human reviews it

Visa's open-source security harness now finds the vulnerability, writes the fix, and turns an adversarial panel on its own patch before any human reviews it. The whole loop ships on by default. A plain scan of the Visa Vulnerability Agentic Harness runs all 11 stages and edits source files in the target repo unless the operator caps it at detection. The announcement Thursday pairs the release…

Visa ships a security AI that patches production code before any human reviews it

Visa has released a security AI tool that automatically detects vulnerabilities in production code, writes fixes, and implements them before any human review. The Visa Vulnerability Agentic Harness (VVAH) runs through all 11 stages of scanning and editing source files in the target repository, unless manually stopped at the detection stage.

This default release comes 18 days after Tenet Security's GhostJacking attack and two days after Steve Wilson, an AI and product officer, advocated for a safety gate outside the AI model. Visa's AI outruns human vulnerability discovery, making the bottleneck fixing and proving the fix effective. The harness, originally developed through Visa's participation in Anthropic's Project Glasswing, has gained popularity, with over 2,300 stars and 300 forks on GitHub.

The new VVAH release extends the pipeline to include remediation, validation, and iteration, reducing Mean Time to Adapt (MTTA) from weeks to hours. Wilson's concerns about the AI's ability to make high-impact changes have been addressed by Visa's implementation of scoped permissions, least privilege, audit trails, and IAM governance for agents.

Written by urgent.news from VentureBeat's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at venturebeat.com →

More in AI

More from Thursday 27 August →