Visa has updated its open-source vulnerability tool, VVAH, to add remediation, validation, and model choice for security teams.

The company has also expanded its Visa Consulting & Analytics (VCA) Cybersecurity Advisory Practice with new services intended to help clients assess risk, prioritise remediation efforts, and build resilience as threats evolve.

According to Visa, the changes are designed to help organisations identify and fix vulnerabilities faster by cutting what it calls “Mean Time to Adapt”(the time between discovery and resolution of attack paths. Some fixes shrank from weeks to hours.)

Rajat Taneja, President of Technology at Visa, said: “AI is compressing the time between vulnerability discovery and exploitation, which means defenders need a faster, more reliable path to action.

“By advancing VVAH and expanding our cybersecurity advisory capabilities, we’re helping organisations move from insight to validated remediation while strengthening resilience in an increasingly AI-driven threat landscape.”

From Project Glasswing to a full remediation workflow

VVAH began life through Visa’s work on Project Glasswing, Anthropic’s frontier AI cybersecurity initiative. That early version showed how AI could help security teams find vulnerabilities, assess whether they could be exploited, and produce structured findings. The new release pushes the same workflow past discovery, into remediation and validation.

Three changes anchor the update. Closed-loop remediation uses structured feedback so teams can refine fixes that fail validation without restarting the entire process.

Swapping or adding an AI model inside a VVAH workflow no longer requires touching code, only configuration. That determines how easily a VVAH user can test new models from Anthropic, OpenAI, or elsewhere as they arrive, without rebuilding the pipeline connecting vulnerability discovery to remediation and validation.

A third addition, optional real-time progress views, gives teams visibility into long-running scans and remediation jobs while they run. Visa built the framework around one structured workflow. It starts with discovery and triage, then ends with remediation and validation.

New advisory services aim to turn findings into action

VCA is introducing three cybersecurity advisory services. Each draws on Visa’s own use of AI in security work. 

AI Cyber Leadership Education covers executive workshops, training, and Visa University certification courses, run by Visa’s AI and cybersecurity specialists and built around lessons from its frontier AI work.

The VVAH-Informed Cybersecurity Maturity Assessment applies the VVAH framework to help organisations identify vulnerabilities, understand risk areas, and set remediation priorities.

A third service, the VVAH Cyber Risk Prioritization and Roadmap, offers guidance to evaluate findings and build a long-term cyber risk management plan.

Carl Rutstein, Global Head of Visa Consulting & Analytics, commented: “Finding vulnerabilities is no longer the hardest part. Speed to remediation is the new battleground. When AI-enabled attackers move faster and probe at scale, companies need AI-powered defenses.

“Our enhanced cybersecurity advisory services combine insights from implementing frontier AI models for cybersecurity, VVAH, and decades of payments expertise to help clients prioritise risk areas, act quickly, and build sustainable cyber resilience.”

Adoption and industry alliances

Over the past year, VCA’s Cybersecurity Advisory Practice has worked with clients on cybersecurity advisory engagements covering maturity evaluation, risk assessment, and priorities for risk management and operational resilience. Visa names one client publicly: CAIXA Cartões, which used the advisory practice to run a cybersecurity maturity assessment and set priorities for its risk management and operational resilience work.

Lessandro Thomaz, Executive Director at CAIXA Cartões, said: “At CAIXA, we understand that cybersecurity is a fundamental pillar for customer trust and business sustainability in an increasingly complex digital environment.

“Our partnership with Visa has helped broaden our strategic perspective on cybersecurity by providing a structured assessment of the maturity of our processes and supporting the prioritisation of initiatives focused on risk management and operational resilience.

Visa says VVAH has been downloaded by tens of thousands of developers worldwide since its open-source release in June 2026, which it points to as evidence of growing interest in practical AI-powered vulnerability management.

The company has also joined two industry initiatives, both of which are tied to frontier AI security work. It is contributing VVAH as a model-agnostic framework to NVIDIA’s Open Secure AI Alliance. Separately, Visa is working with other organisations through IBM and Red Hat’s Project Lightwell initiative to help secure open-source software.

“Projects like this reinforce the importance of collaboration between financial institutions and strategic partners to anticipate challenges, strengthen capabilities, and deliver increasingly secure and reliable solutions to our customers,” concludes Thomaz.

See also: AWS adds OpenAI’s GPT-5.6 to Kiro’s agentic coding workflow

Banner for Cyber Security Expo by TechEx events.

Want to learn more about cybersecurity from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the AI & Big Data Expo. Click here for more information.

Developer is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

Share.
Leave A Reply

Exit mobile version