Visa updates AI cybersecurity tools to patch vulnerabilities

Visa has expanded its cybersecurity offering with new AI-powered tools and advisory services designed to help organisations identify, prioritise and fix security vulnerabilities more quickly.

The payments company has updated its open-source Visa Vulnerability Agentic Harness (VVAH), adding new capabilities that support the full vulnerability management process, from identifying security issues through to validating fixes.

Visa said the latest version aims to reduce the "Mean Time to Adapt" (MTTA), the time between discovering a vulnerability and resolving it, from weeks to hours.

The updated framework introduces a closed-loop remediation process, which Visa said allows security teams to refine fixes that fail validation without restarting the workflow. It also supports multiple AI models, including Anthropic and OpenAI, and provides optional real-time monitoring of scans and remediation progress.

Alongside the technology update, Visa has expanded its Visa Consulting & Analytics (VCA) Cybersecurity Advisory Practice with three new services.

The first offers AI cybersecurity training and workshops for executives and security leaders. The second provides organisations with a cybersecurity maturity assessment using the VVAH framework, while the third helps firms prioritise cyber risks and develop long-term remediation roadmaps.

"Across Asia Pacific, AI is accelerating both the scale of cyber threats and the speed at which vulnerabilities can be exploited," said Prateek Sanghi, head of Visa Consulting & Analytics for Asia Pacific. "In this environment, identifying vulnerabilities is no longer the differentiator.

"The real challenge is determining which risks matter most and remediating them before they can be leveraged by attackers."

Visa said it has already used its cybersecurity advisory practice to help financial institutions assess their cybersecurity maturity and strengthen operational resilience.

The company highlighted work with Brazilian card issuer CAIXA Cartões, which used Visa's assessment framework to support risk management planning.

Visa also said interest in its AI-powered cybersecurity framework has grown since it released VVAH as open-source software in June 2026. It reported that developers have downloaded the framework tens of thousands of times.

The company has also joined NVIDIA's Open Secure AI Alliance and IBM and Red Hat's Project Lightwell initiative, where it plans to contribute VVAH and collaborate on securing open-source software and AI systems.



Share Story:

Recent Stories


Creating value together: Strategic partnerships in the age of GCCs
As Global Capability Centres reshape the financial services landscape, one question stands out: how do leading banks balance in-house innovation with strategic partnerships to drive real transformation?

Data trust in the AI era: Building customer confidence through responsible banking
In the second episode of FStech’s three-part video podcast series sponsored by HCLTech, Sudip Lahiri, Executive Vice President & Head of Financial Services for Europe & UKI at HCLTech examines the critical relationship between data trust, transparency, and responsible AI implementation in financial services.

Banking's GenAI evolution: Beyond the hype, building the future
In the first episode of a three-part video podcast series sponsored by HCLTech, Sudip Lahiri, Executive Vice President & Head of Financial Services for Europe & UKI at HCLTech explores how financial institutions can navigate the transformative potential of Generative AI while building lasting foundations for innovation.

Beyond compliance: Building unshakeable operational resilience in financial services
In today's rapidly evolving financial landscape, operational resilience has become a critical focus for institutions worldwide. As regulatory requirements grow more complex and cyber threats, particularly ransomware, become increasingly sophisticated, financial services providers must adapt and strengthen their defences. The intersection of compliance, technology, and security presents both challenges and opportunities.