Visa Released Open-Source AI Security Tool

The Vulnerability Agentic Harness aims to automatically identify and repair security flaws across digital infrastructures.

Updated on Sept. 29, 2026 in Cybersecurity

Isometric editorial illustration of a secure core structure composed of interlocking crystalline cubes and modular protective layers representing cybersecurity.
Visa has open-sourced its new Vulnerability Agentic Harness, an AI-powered framework designed to identify and remediate security flaws in complex digital infrastructures. AI Illustration. Upload story photo >

Live Poll

Do you trust open-source software to improve overall digital security for the public?

Visa released its Vulnerability Agentic Harness as an open-source tool on June 10, 2026. The framework leverages artificial intelligence to discover, triage, remediate, and validate security vulnerabilities.

Why it matters

The software was developed following Project Glasswing stress-testing, which identified over 10,000 critical vulnerabilities in industry systems. By utilizing a zero-trust architecture, the framework seeks to provide a scalable solution for securing complex digital networks.

The system features an AI-driven pipeline that integrates deterministic controls alongside human oversight. It is designed to secure vast infrastructures, which globally support 5 billion payment credentials and 160 currencies.

The players

Visa

Visa is a global financial services corporation that facilitates electronic funds transfers throughout the world.

Project Glasswing

Project Glasswing is a cybersecurity initiative focused on stress-testing and identifying critical vulnerabilities in industry systems.

The details

Released under an Apache 2.0 license, the platform operates through a four-phase cycle of discovery, triage, remediation, and validation. Visa enhanced the framework on August 27, 2026, by adding automated remediation and validation capabilities to the pipeline.

Timeline

  1. April 2026: Visa joined the Project Glasswing initiative.

  2. June 10, 2026: The Vulnerability Agentic Harness was released as open-source.

  3. mid-July 2026: The GitHub repository reached 595 stars.

  4. August 27, 2026: Visa pushed a major update to the framework.

  5. late August 2026: The GitHub repository reached 2,300 stars.

The Tech Race

The adoption of the Apache 2.0 license reflects a broader industry trend toward transparency in AI-driven cybersecurity tools. Visa utilized this specific licensing structure to facilitate community-driven improvements to its security framework.

Developers and security teams can now implement this framework to automate their own vulnerability management workflows. By using this tool, organizations may improve the efficiency of identifying and patching software weaknesses.

The takeaway

Open-source collaboration enables organizations to share critical security fixes across global payment networks. Implementing automated validation protocols helps teams maintain oversight while accelerating the repair of software vulnerabilities.

Further reading

For more information on the evolving threat landscape, visit the Cybersecurity section.

Live Poll

Do you trust open-source software to improve overall digital security for the public?