Close Menu
    Trending
    • A new media ecosystem is taking root on the left, reshaping Democratic politics
    • SEC Enforcement Deputy Sam Waldon To Step Down As Agency Reshuffles Leadership
    • Run a Node Grants Round Grantee Announcement
    • SEC Chairman Wants To Advance Crypto Clarity Act
    • Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible
    • Inside the rogue ChatGPT hack of Hugging Face
    • League of Legends World Championship tickets are appearing for over $3,000, but Riot may not be the one to blame
    • “If I say this, people might laugh at me…”: Deep Dasgupta hails Team India despite their inconsistent T20I performances
    FreshUsNews
    • Home
    • World News
    • Latest News
      • World Economy
      • Opinions
    • Politics
    • Crypto
      • Blockchain
      • Ethereum
    • US News
    • Sports
      • Sports Trends
      • eSports
      • Cricket
      • Formula 1
      • NBA
      • Football
    • More
      • Finance
      • Health
      • Mindful Wellness
      • Weight Loss
      • Tech
      • Tech Analysis
      • Tech Updates
    FreshUsNews
    Home » Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible
    Tech Updates

    Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible

    FreshUsNewsBy FreshUsNewsJuly 29, 2026No Comments8 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Visa aimed Anthropic's Claude Mythos on the infrastructure behind billions of every day transactions, a community that spans greater than 200 international locations and territories, strikes cash in roughly 160 currencies, and connects almost 5 billion cost credentials to greater than 175 million service provider places.

    The mannequin stitched minor weaknesses deep within the stack into working exploit chains that will historically have surfaced solely late in penetration testing. Rajat Taneja, Visa's president of know-how, walked the VB Transform 2026 viewers by what got here subsequent, together with why Visa launched the harness that ruled your entire hunt as open supply and why the corporate deserted conventional remediation metrics for a measurement its workforce invented.

    Taneja has run know-how technique, product engineering, and international infrastructure at Visa since 2019, after becoming a member of the corporate in 2013 from Digital Arts, the place he served as CTO following 15 years at Microsoft. He co-authored, with Visa chief data safety officer Subra Kumaraswamy, the June 10 blog post saying the discharge of the Visa Vulnerability Agentic Harness on GitHub as a reference implementation that any safety workforce can examine, adapt, and prolong. Visa additionally revealed a technical white paper detailing the structure, classes realized, and 12 non-negotiable architectural practices for crucial infrastructure.

    Belief constructed on pessimism and paranoia

    Taneja led with the arithmetic that makes Visa a goal price defending obsessively. Belief on the scale of world funds will get engineered by what he known as pessimism and paranoia, by assuming failure and designing round it earlier than failure arrives. The community has been hardened over a few years by zero-trust structure, layered defenses, and extremely automated safety operations constructed for the dimensions and reliability international funds demand.

    So when Anthropic invited the organizations behind crucial software program to check Mythos beneath Challenge Glasswing, Visa stated sure. Glasswing contributors collectively recognized greater than 10,000 high- or critical-severity vulnerabilities within the first month of testing throughout software program underpinning crucial programs industry-wide, in accordance with Anthropic. Anthropic's personal conclusion positioned the bottleneck after discovery, in verification, disclosure, and patching velocity. Visa joined to check many years of hardening at AI velocity and study the place superior fashions might push its defenses additional.

    What Mythos confirmed at Visa

    Inside Visa's surroundings, Mythos demonstrated system-wide, context-aware evaluation, surfacing vulnerabilities buried deep within the stack and flagging points that develop extra severe when chained collectively, with findings clear sufficient that engineering groups might act on them with out wading by noise. Some findings carried crucial severity scores, and Visa credit its zero-trust controls, community segmentation, and layered safeguards with breaking the chain earlier than any exterior actor might have acted.

    That affirmation mattered, Taneja stated, however the epiphany that adopted mattered extra. "In a world of agentic assaults, protection additionally needs to be agentic," he stated. Even at an organization that has invested many years in defense-in-depth, the mannequin revealed assumptions the workforce had been working beneath that wanted rethinking. Conventional SAST instruments preserve their place as a primary go towards recognized vulnerability patterns, Visa's white paper notes, however sample matching alone can not comply with an adversary who causes by logic, knowledge movement, and the exploit chains that dwell between the signatures.

    A harness, not a scanner

    Visa's response was not one other monolithic scanner. The workforce constructed the Visa Vulnerability Agentic Harness, now in its fifth era, as a ruled pipeline that directs frontier AI fashions by structured safety duties whereas imposing deterministic controls, coverage gates, and human oversight at each stage. Taneja walked by the design philosophy. The harness operates throughout 4 phases and eleven phases, from code ingestion and menace modeling by deep-dive verification, exploit chain synthesis, and eventually remediation and repair validation.

    Three design decisions drive discovering high quality, per the mission's personal documentation. Menace modeling runs earlier than evaluation to concentrate on the assault floor somewhat than scanning all the pieces blindly, multi-agent deterministic voting requires convergence throughout unbiased reasoning chains earlier than a discovering advances, and structured triage artifacts compress the lifecycle from discovery to a consequence builders can really ship. The payoff is a pipeline that runs scorching by default. A plain scan within the shipped profile runs all eleven phases and edits supply information within the goal repository in repair mode, making use of candidate patches until the operator stops it at detection.

    The harness is multi-model by design. An LLM abstraction layer lets Visa swap or mix suppliers with out altering the management airplane, and the open-source model works with Anthropic Claude, OpenAI-compatible fashions, or a combination. The repo's documentation is candid concerning the exception. Making use of a repair requires the file-editing instruments that solely the Anthropic backends expose, so the remediation and validation phases at the moment require Anthropic fashions for full performance, and an OpenAI-compatible mannequin in these roles is restricted to report-only output. VentureBeat's Q2 2026 Pulse analysis, offered earlier on the convention, reinforces why that supplier flexibility issues. Among the many enterprises surveyed, 82% rely on provider-native controls as their primary security layer, and 59% plan to undertake or change agent safety tooling throughout the yr. The controls enterprises adopted final yr are already changing into the controls they plan to interchange.

    Imply Time to Adapt replaces legacy metrics

    Discovering vulnerabilities is not the exhausting half, Taneja argued. The true problem is how shortly a workforce can affirm a problem is really exploitable, repair it, and show the assault path is closed somewhat than simply displaying a patch was utilized. Visa calls this Imply Time to Adapt, and the white paper tracks it alongside three dimensions. Stock freshness measures how present and full the group's view is of code, configuration, and runtime deployment. Exploitable paths per launch counts what number of end-to-end assault chains stay potential after every launch, not simply what number of findings had been closed. Validation cycle time tracks how lengthy it takes to provide repeatable, evidence-backed proof {that a} repair works and stays working in manufacturing.

    That distinction issues as a result of legacy measures similar to imply time to detect and uncooked CVE closure counts can look higher on paper whereas precise publicity retains rising beneath them. A corporation can shut lots of of findings a month and nonetheless depart viable exploit chains open if no one examined whether or not the patches really break the assault. MTTA forces groups to measure the result that issues, and the white paper leans on CISA Identified Exploited Vulnerabilities knowledge to make the prioritization case, noting that fewer than 1% of CVEs are ever actively exploited. Visa's SSDLC coverage now assumes each exploitable path can be exercised in manufacturing and requires it to be remediated earlier than code is promoted.

    Provide chain danger accelerates beneath AI

    The dialog moved previous Visa's personal perimeter when Taneja turned to suppliers. A well-defended enterprise stays uncovered by weak distributors and weak open-source elements, the white paper warns, so Visa is making AI-specific safety posture a non-negotiable dimension of provider due diligence, with expectations for steady vulnerability validation, dwelling software program payments of supplies, and MTTA baselines throughout its know-how stack.

    Visa has additionally joined Challenge Lightwell, the $5 billion IBM and Red Hat initiative to harden broadly used open-source elements by AI-driven validation and coordinated patching, alongside monetary establishments together with Financial institution of America, JPMorganChase, Goldman Sachs, and Mastercard. The dedication extends the identical logic upstream, as a result of the MTTA clock doesn’t pause at any single firm's perimeter.

    When brokers begin shopping for issues

    Securing agentic commerce is Visa's subsequent drawback. Taneja described a future the place AI brokers transact on behalf of shoppers and enterprises, and stated Visa is constructing the belief framework, id layer, and agent readiness scoring that retailers will want earlier than brokers can safely full transactions. Behind that work sits the Visa Fee Threats Lab, a simulation surroundings the place actual fraud eventualities get replayed towards the authorization guidelines, thresholds, and configurations Visa really runs, to floor AI-enabled failure modes as focused hardening suggestions.

    The id problem shouldn’t be theoretical. VentureBeat's Pulse analysis discovered that 69% of enterprises already run credential sharing someplace of their agent deployments, and corporations with shared credentials report safety incidents or near-misses at a 63.5% charge, towards 40.9% the place each agent has its personal scoped id. Visa's white paper addresses that hole straight, itemizing "AI brokers are identities" amongst its 12 non-negotiable practices and requiring scoped permissions, least privilege enforcement, full audit trails, and inclusion in IAM governance for each agent that calls an API, reads knowledge, or modifies a system.

    Three priorities for defenders

    Visa is organizing its defensive technique round three priorities, Taneja stated. Shift safety left till exploitable flaws are designed out earlier than they attain manufacturing, and exchange high-risk, under-supported elements earlier than they flip into materials publicity. The third is the heaviest raise at Visa's scale, refactoring defenses to run autonomously beneath human governance so detection, validation, and response preserve tempo as menace quantity grows and the fashions behind assaults enhance.

    None of it requires a cost community's finances to begin. The harness sits on GitHub with 595 stars and 97 forks as of July 20, MTTA wants a dashboard somewhat than a procurement cycle, and the white paper's 12 non-negotiable practices map onto structure opinions safety groups already run. Visa's personal conclusion reads like a deadline. The opening to get forward of machine-speed attackers remains to be there, the paper argues, and it’ll not keep open.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleInside the rogue ChatGPT hack of Hugging Face
    Next Article SEC Chairman Wants To Advance Crypto Clarity Act
    FreshUsNews
    • Website

    Related Posts

    Tech Updates

    Snowflake launches Cortex AI Gateway to control AI agents and prevent runaway enterprise costs

    July 28, 2026
    Tech Updates

    Kimi K3's full weights are here, but they're 'open' with a caveat: What enterprises should know

    July 28, 2026
    Tech Updates

    Uh-oh: Some Claude shared conversations and Artifacts appear to be indexed and publicly accessible on Google Search

    July 27, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Larry Nance Jr heads back to Cleveland

    July 2, 2025

    Russia & Impossibility Of Peace

    January 11, 2026

    Trump shares Melania Trump’s letter to Putin

    August 18, 2025

    Justin Rose makes turn with two-shot lead

    April 12, 2026

    Acting ICE director, CBP commissioner to testify for first time since fatal shootings

    February 10, 2026
    Categories
    • Bitcoin News
    • Blockchain
    • Cricket
    • eSports
    • Ethereum
    • Finance
    • Football
    • Formula 1
    • Healthy Habits
    • Latest News
    • Mindful Wellness
    • NBA
    • Opinions
    • Politics
    • Sports
    • Sports Trends
    • Tech Analysis
    • Tech News
    • Tech Updates
    • US News
    • Weight Loss
    • World Economy
    • World News
    Most Popular

    A new media ecosystem is taking root on the left, reshaping Democratic politics

    July 29, 2026

    SEC Enforcement Deputy Sam Waldon To Step Down As Agency Reshuffles Leadership

    July 29, 2026

    Run a Node Grants Round Grantee Announcement

    July 29, 2026

    SEC Chairman Wants To Advance Crypto Clarity Act

    July 29, 2026

    Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible

    July 29, 2026

    Inside the rogue ChatGPT hack of Hugging Face

    July 29, 2026

    League of Legends World Championship tickets are appearing for over $3,000, but Riot may not be the one to blame

    July 29, 2026
    Our Picks

    Wormhole Foundation challenges LayerZero’s $110M Stargate acquisition proposal

    August 20, 2025

    LLM Benchmarking: Surprising Task Complexity Gains

    July 14, 2025

    Ethereum Staking Deposits Just Surpassed Withdrawals, Why This Could Send ETH Price Above $4,000

    January 4, 2026

    Soap, deodorant and sanitiser recalls over sepsis concerns – full list revealed

    September 10, 2025

    Vacations Just Aren’t As Great Anymore Once You Retire Early

    October 15, 2025

    TSMC raises sales outlook on ‘very strong’ AI demand

    October 16, 2025

    Bitcoin Sees Renewed Demand From US Institutional Players — What’s Changing?

    April 27, 2026
    Categories
    • Bitcoin News
    • Blockchain
    • Cricket
    • eSports
    • Ethereum
    • Finance
    • Football
    • Formula 1
    • Healthy Habits
    • Latest News
    • Mindful Wellness
    • NBA
    • Opinions
    • Politics
    • Sports
    • Sports Trends
    • Tech Analysis
    • Tech News
    • Tech Updates
    • US News
    • Weight Loss
    • World Economy
    • World News
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    Copyright © 2025 Freshusnews.com All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.