Visa expands its open VVAH AI cyberdefense system and beefs up its cybersecurity advisory arm

🕒 Published on Zendoric: September 1, 2026 · 00:48
✨ AI-generated · how it's made
Visa has announced an expansion of its cybersecurity portfolio focused on two fronts: the evolution of its open-source Visa Vulnerability Agentic Harness (VVAH) tool and the expansion of Visa Consulting & Analytics (VCA) advisory services in cybersecurity.
Visa has announced an expansion of its cybersecurity portfolio focused on two fronts: the evolution of its open-source Visa Vulnerability Agentic Harness (VVAH) tool and the expansion of Visa Consulting & Analytics (VCA) advisory services in cybersecurity. The stated goal is to help organizations identify and fix vulnerabilities faster and more effectively at a time when, according to the company, artificial intelligence is shortening the time between the discovery of a vulnerability and its exploitation by attackers.
VVAH is a framework that is agnostic as to the AI model it uses, meaning it does not depend on any specific vendor, and which Visa released as open source. According to the company, this new version significantly reduces the 'Mean Time to Adapt' (MTTA), that is, the time between detecting an attack path and resolving it, with cases in which that process has gone from weeks to hours. Rajat Taneja, Visa's president of Technology, summed up the project's motivation by noting that AI is compressing the time between vulnerability discovery and exploitation, so defense teams need a faster and more reliable path to action, and added that expanding VVAH and its advisory capabilities seeks to help organizations move from detection to validated remediation, strengthening resilience against an increasingly AI-driven threat landscape.
VVAH's origins trace back to Visa's participation in Project Glasswing, a frontier AI cybersecurity initiative led by Anthropic. In its first version, the tool already demonstrated how AI can help security teams discover vulnerabilities, assess their level of exploitability and generate structured findings. The new version extends that workflow beyond initial discovery, incorporating remediation and validation phases within a single structured process of discovery, triage, remediation and verification.
Among the specific improvements introduced by this update are three elements. First, closed-loop remediation, whereby a structured feedback system helps teams refine fixes that fail validation without having to restart the entire process from scratch. Second, greater flexibility in the choice of AI models: organizations can deploy approved models from both Anthropic and OpenAI, as well as any other model, simply through configuration and without modifying code. Third, greater operational visibility, thanks to optional real-time progress views that provide additional transparency over long-running scans and remediation flows.
Alongside these technical improvements, Visa Consulting & Analytics has introduced three new cybersecurity advisory services, designed to help organizations put these advances into practice. The first is 'AI Cyber Leadership Education', consisting of executive workshops, training and Visa University certification courses taught by Visa specialists in AI and cybersecurity, with the aim of sharing lessons drawn from the company's experience with frontier AI applied to cybersecurity. The second is the 'VVAH-Informed Cybersecurity Maturity Assessment', a service that helps organizations apply the VVAH framework to identify and assess potential vulnerabilities, understand their risk areas and prioritize remediation efforts. The third is 'VVAH Cyber Risk Prioritization and Roadmap', which offers strategic guidance to evaluate findings, prioritize remediation and develop a long-term cyber risk management roadmap.
Carl Rutstein, global head of Visa Consulting & Analytics, stressed that finding vulnerabilities is no longer the hardest part of the problem, and that remediation speed has become the new battleground: when AI-powered attackers move faster and probe at scale, companies need defenses that are equally AI-powered. Rutstein added that these advisory services combine Visa's experience deploying frontier AI models for cybersecurity, the VVAH tool itself and decades of payments-industry expertise, in order to help clients prioritize risk areas, act quickly and build sustainable cyber resilience.
According to the article, over the past year VCA's Cybersecurity Advisory Practice has supported clients on various projects aimed at assessing cybersecurity maturity, identifying risk areas and setting priorities to strengthen risk management and operational resilience. As an example, it cites the case of CAIXA Cartões, which worked with Visa on a cybersecurity maturity assessment and on prioritizing its risk management and operational resilience initiatives. Lessandro Thomaz, chief executive of CAIXA Cartões, noted that cybersecurity is a fundamental pillar for customer trust and business sustainability in an increasingly complex digital environment, and that the collaboration with Visa has helped broaden the institution's strategic perspective on cybersecurity, providing a structured assessment of the maturity of its processes and supporting the prioritization of initiatives focused on risk management and operational resilience.
As for adoption of the tool, the article indicates that since its launch as an open-source project in June 2026, VVAH has been downloaded by tens of thousands of developers around the world, reflecting growing interest in practical AI-assisted vulnerability management. In addition, Visa has recently joined industry initiatives aimed at promoting secure, open and responsible practices in frontier AI development: on the one hand, it is part of NVIDIA's Open Secure AI Alliance, to which it contributes VVAH as an AI-model-agnostic framework; on the other, it is working with IBM and Red Hat through Project Lightwell, an initiative focused on helping secure open-source software alongside other organizations.
Taken together, Visa's move fits into a broader trend in the financial and technology sectors toward the use of agentic AI both to attack and to defend critical infrastructure, and reflects the interest of a central player in the payments industry in positioning itself as a benchmark in the practical application of frontier AI to cybersecurity, combining open technical tools with commercial consulting services aimed at its institutional clients.
🔗 Related on Zendoric
- GLM-5.2 matches Mythos in cybersecurity: China closes the gap on AI's most sensitive front · 2026-06-29
- The U.S. expands its ban on importing Chinese technology: the FCC extends the veto to older models from Huawei, ZTE, Hikvision and more · 2026-06-30
- China issues a security alert over an alleged 'backdoor' in Anthropic's Claude Code · 2026-07-09


