NewsStocksVisa Open-Sources AI-Powered Cyber Defense System VVAH After 10,000+ Vulnerabilities Uncovered

Visa Open-Sources AI-Powered Cyber Defense System VVAH After 10,000+ Vulnerabilities Uncovered

Author: CryptoBriefing·

Key Takeaways

  • •Visa open-sourced its VVAH cybersecurity framework in June 2026 under the permissive Apache 2.0 license, which permits commercial use, modification, and redistribution.
  • •The framework originated from Visa's collaboration with Anthropic's Project Glasswing, an initiative whose testing uncovered more than 10,000 high and critical vulnerabilities across industry systems in its first month.
  • •VVAH operates a four-phase pipeline covering discovery, triage, remediation, and validation, built on a zero-trust architecture with controls and human oversight at each stage.
  • •An August 27, 2026, update introduced automated remediation and validation, enabling the system to implement and verify fixes and significantly shortening vulnerability response times.
  • •The project has seen rapid adoption, with GitHub stars rising from about 595 in mid-July to over 2,300 by late August, tens of thousands of downloads globally, and Visa monetizing deployment through paid consulting services.
Visa Open-Sources AI-Powered Cyber Defense System VVAH After 10,000+ Vulnerabilities Uncovered

Payments giant Visa has open-sourced an AI-powered cyber defense system, releasing its Visa Vulnerability Agentic Harness (VVAH) in June 2026 under the Apache 2.0 license, a permissive open-source license that permits commercial use, modification, and redistribution. The decision followed a collaboration with Anthropic's Project Glasswing, an initiative that uncovered more than 10,000 high and critical vulnerabilities—the two most severe categories in standard vulnerability ratings—across industry systems in the first month of testing alone.

VVAH is designed to find, prioritize, fix, and verify security flaws through an AI-driven pipeline—the 'agentic' in its name points to AI systems that carry out multi-step work with a degree of autonomy.

From Stress Test to Open-Source Release

The project traces back to April 2026, when Visa joined Anthropic's Project Glasswing. The initiative involved deploying Anthropic's Claude Mythos AI model against Visa's sprawling global payment infrastructure—a network spanning more than 200 countries, roughly 160 currencies, and nearly 5 billion payment credentials. The exercise effectively served as a large-scale stress test of Visa's network defenses.

Rather than quietly patching the flaws and moving on, Visa built VVAH as a structured response framework. The system operates a four-phase pipeline covering discovery, triage, remediation, and validation. It runs on a zero-trust architecture, a security model in which every component assumes it has already been compromised and verifies accordingly, and it incorporates deterministic controls and human oversight at each stage. Under the license's permissive terms, other organizations can now adapt a pipeline built and exercised at the scale of one of the world's largest payment networks to environments of their own.

VVAH was open-sourced around June 10, 2026. Adoption grew quickly: the project's GitHub repository had accumulated roughly 595 stars by mid-July, and the count had cleared 2,300 by late August—stars being a commonly cited proxy for community interest in open-source projects. Visa has recorded tens of thousands of downloads globally since launch.

August Update Adds Automated Fixes

On August 27, 2026, Visa pushed a significant update to the framework. The new version added automated remediation and validation features, meaning VVAH can now do more than find and categorize vulnerabilities—it can also propose and implement fixes, then verify that those fixes actually work. The change turns the framework from a system that identified and prioritized flaws into one that can carry fixes through to verified completion, and the automated remediation capabilities have significantly compressed response times for vulnerability fixing.

Free Tool, Paid Expertise

a has also expanded its consulting services around the framework, building out cybersecurity advisory offerings that help enterprises implement VVAH and integrate it with existing security infrastructure—a familiar playbook in enterprise open source, where the code is given away and the services around it are sold. The open-source tool is free; the expertise to deploy it correctly at scale is not.