Visa Open-Sources Tool for Internal Payment Network Vulnerability Hunts
Visa utilized an AI model to identify vulnerabilities within its payment network and has now released the developed harness as open-source software.

Financial services giant Visa has released an open-source tool that it used to find vulnerabilities within its extensive payment network. The tool, named Visa Vulnerability Agentic Harness, is built upon Anthropic's Claude Mythos AI model.
Visa employed the AI to test its infrastructure, which processes billions of daily transactions across more than 200 countries and 160 currencies. The objective was to uncover weaknesses buried deep within the system that traditional penetration testing might not reveal.
Rajat Taneja, Visa's technology president, explained that the Mythos model successfully identified exploitable chains of vulnerabilities that developers could directly address. "In a world of agentic attacks, defense also has to be agentic," Taneja stated.
Beyond vulnerability discovery, Visa developed a new metric, Mean Time to Adapt, to replace traditional security metrics. This new measure focuses on the speed at which a team can verify and remediate an identified issue.
The company has published the tool on GitHub, along with accompanying technical documentation. The aim is to assist other organizations in enhancing their security and to share best practices for protecting critical infrastructure.