Visa has released its AI-driven Vulnerability Agentic Harness as open source after using Anthropic’s Claude Mythos to uncover complex exploit chains across its global payment network, giving enterprises a reusable framework for AI-powered security testing.
Visa has open-sourced its AI-powered Visa Vulnerability Agentic Harness after using Anthropic’s Claude Mythos to analyse the infrastructure behind its global payment network. The AI uncovered vulnerabilities and exploit chains that would typically emerge much later during conventional penetration testing, prompting Visa to release the framework as a reference implementation for other organisations.
Now in its fifth generation, the harness provides a governed AI pipeline spanning four phases and eleven stages, from code ingestion and threat modelling to exploit chain synthesis, remediation and fix validation. It combines deterministic controls, policy gates, human oversight and frontier AI reasoning to improve vulnerability discovery while maintaining governance.
The framework prioritises threat modelling before analysis, multi-agent deterministic voting and structured triage artefacts to improve the quality of findings. It also supports Anthropic Claude, OpenAI-compatible models and mixed-model deployments, although automated code fixing currently requires Anthropic models because of their file-editing capabilities.
Alongside the release, Visa introduced Mean Time to Adapt (MTTA), a new metric that measures inventory freshness, exploitable paths per release and validation cycle time. The company argues MTTA provides a more meaningful measure of security readiness than traditional metrics such as Mean Time to Detect or CVE closure counts.
Visa has updated its secure software development practices to require remediation of exploitable attack paths before production, strengthened supplier security requirements with continuous vulnerability validation, SBOMs and MTTA baselines, and joined Project Lightwell, an IBM and Red Hat initiative to improve the security of widely used open-source software through AI-driven validation and coordinated patching.













































































