Close Menu
    Trending
    • Run a Node Grants Round Grantee Announcement
    • SEC Chairman Wants To Advance Crypto Clarity Act
    • Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible
    • Inside the rogue ChatGPT hack of Hugging Face
    • League of Legends World Championship tickets are appearing for over $3,000, but Riot may not be the one to blame
    • “If I say this, people might laugh at me…”: Deep Dasgupta hails Team India despite their inconsistent T20I performances
    • Micah Parsons Injury Updates: Latest News Surrounding Packers Edge Rusher
    • Everton and Villa suffer disappointing losses
    FreshUsNews
    • Home
    • World News
    • Latest News
      • World Economy
      • Opinions
    • Politics
    • Crypto
      • Blockchain
      • Ethereum
    • US News
    • Sports
      • Sports Trends
      • eSports
      • Cricket
      • Formula 1
      • NBA
      • Football
    • More
      • Finance
      • Health
      • Mindful Wellness
      • Weight Loss
      • Tech
      • Tech Analysis
      • Tech Updates
    FreshUsNews
    Home » Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible
    Tech Updates

    Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible

    FreshUsNewsBy FreshUsNewsJuly 29, 2026No Comments8 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Visa aimed Anthropic's Claude Mythos on the infrastructure behind billions of every day transactions, a community that spans greater than 200 international locations and territories, strikes cash in roughly 160 currencies, and connects almost 5 billion cost credentials to greater than 175 million service provider places.

    The mannequin stitched minor weaknesses deep within the stack into working exploit chains that will historically have surfaced solely late in penetration testing. Rajat Taneja, Visa's president of know-how, walked the VB Transform 2026 viewers by what got here subsequent, together with why Visa launched the harness that ruled your entire hunt as open supply and why the corporate deserted conventional remediation metrics for a measurement its workforce invented.

    Taneja has run know-how technique, product engineering, and international infrastructure at Visa since 2019, after becoming a member of the corporate in 2013 from Digital Arts, the place he served as CTO following 15 years at Microsoft. He co-authored, with Visa chief data safety officer Subra Kumaraswamy, the June 10 blog post saying the discharge of the Visa Vulnerability Agentic Harness on GitHub as a reference implementation that any safety workforce can examine, adapt, and prolong. Visa additionally revealed a technical white paper detailing the structure, classes realized, and 12 non-negotiable architectural practices for crucial infrastructure.

    Belief constructed on pessimism and paranoia

    Taneja led with the arithmetic that makes Visa a goal price defending obsessively. Belief on the scale of world funds will get engineered by what he known as pessimism and paranoia, by assuming failure and designing round it earlier than failure arrives. The community has been hardened over a few years by zero-trust structure, layered defenses, and extremely automated safety operations constructed for the dimensions and reliability international funds demand.

    So when Anthropic invited the organizations behind crucial software program to check Mythos beneath Challenge Glasswing, Visa stated sure. Glasswing contributors collectively recognized greater than 10,000 high- or critical-severity vulnerabilities within the first month of testing throughout software program underpinning crucial programs industry-wide, in accordance with Anthropic. Anthropic's personal conclusion positioned the bottleneck after discovery, in verification, disclosure, and patching velocity. Visa joined to check many years of hardening at AI velocity and study the place superior fashions might push its defenses additional.

    What Mythos confirmed at Visa

    Inside Visa's surroundings, Mythos demonstrated system-wide, context-aware evaluation, surfacing vulnerabilities buried deep within the stack and flagging points that develop extra severe when chained collectively, with findings clear sufficient that engineering groups might act on them with out wading by noise. Some findings carried crucial severity scores, and Visa credit its zero-trust controls, community segmentation, and layered safeguards with breaking the chain earlier than any exterior actor might have acted.

    That affirmation mattered, Taneja stated, however the epiphany that adopted mattered extra. "In a world of agentic assaults, protection additionally needs to be agentic," he stated. Even at an organization that has invested many years in defense-in-depth, the mannequin revealed assumptions the workforce had been working beneath that wanted rethinking. Conventional SAST instruments preserve their place as a primary go towards recognized vulnerability patterns, Visa's white paper notes, however sample matching alone can not comply with an adversary who causes by logic, knowledge movement, and the exploit chains that dwell between the signatures.

    A harness, not a scanner

    Visa's response was not one other monolithic scanner. The workforce constructed the Visa Vulnerability Agentic Harness, now in its fifth era, as a ruled pipeline that directs frontier AI fashions by structured safety duties whereas imposing deterministic controls, coverage gates, and human oversight at each stage. Taneja walked by the design philosophy. The harness operates throughout 4 phases and eleven phases, from code ingestion and menace modeling by deep-dive verification, exploit chain synthesis, and eventually remediation and repair validation.

    Three design decisions drive discovering high quality, per the mission's personal documentation. Menace modeling runs earlier than evaluation to concentrate on the assault floor somewhat than scanning all the pieces blindly, multi-agent deterministic voting requires convergence throughout unbiased reasoning chains earlier than a discovering advances, and structured triage artifacts compress the lifecycle from discovery to a consequence builders can really ship. The payoff is a pipeline that runs scorching by default. A plain scan within the shipped profile runs all eleven phases and edits supply information within the goal repository in repair mode, making use of candidate patches until the operator stops it at detection.

    The harness is multi-model by design. An LLM abstraction layer lets Visa swap or mix suppliers with out altering the management airplane, and the open-source model works with Anthropic Claude, OpenAI-compatible fashions, or a combination. The repo's documentation is candid concerning the exception. Making use of a repair requires the file-editing instruments that solely the Anthropic backends expose, so the remediation and validation phases at the moment require Anthropic fashions for full performance, and an OpenAI-compatible mannequin in these roles is restricted to report-only output. VentureBeat's Q2 2026 Pulse analysis, offered earlier on the convention, reinforces why that supplier flexibility issues. Among the many enterprises surveyed, 82% rely on provider-native controls as their primary security layer, and 59% plan to undertake or change agent safety tooling throughout the yr. The controls enterprises adopted final yr are already changing into the controls they plan to interchange.

    Imply Time to Adapt replaces legacy metrics

    Discovering vulnerabilities is not the exhausting half, Taneja argued. The true problem is how shortly a workforce can affirm a problem is really exploitable, repair it, and show the assault path is closed somewhat than simply displaying a patch was utilized. Visa calls this Imply Time to Adapt, and the white paper tracks it alongside three dimensions. Stock freshness measures how present and full the group's view is of code, configuration, and runtime deployment. Exploitable paths per launch counts what number of end-to-end assault chains stay potential after every launch, not simply what number of findings had been closed. Validation cycle time tracks how lengthy it takes to provide repeatable, evidence-backed proof {that a} repair works and stays working in manufacturing.

    That distinction issues as a result of legacy measures similar to imply time to detect and uncooked CVE closure counts can look higher on paper whereas precise publicity retains rising beneath them. A corporation can shut lots of of findings a month and nonetheless depart viable exploit chains open if no one examined whether or not the patches really break the assault. MTTA forces groups to measure the result that issues, and the white paper leans on CISA Identified Exploited Vulnerabilities knowledge to make the prioritization case, noting that fewer than 1% of CVEs are ever actively exploited. Visa's SSDLC coverage now assumes each exploitable path can be exercised in manufacturing and requires it to be remediated earlier than code is promoted.

    Provide chain danger accelerates beneath AI

    The dialog moved previous Visa's personal perimeter when Taneja turned to suppliers. A well-defended enterprise stays uncovered by weak distributors and weak open-source elements, the white paper warns, so Visa is making AI-specific safety posture a non-negotiable dimension of provider due diligence, with expectations for steady vulnerability validation, dwelling software program payments of supplies, and MTTA baselines throughout its know-how stack.

    Visa has additionally joined Challenge Lightwell, the $5 billion IBM and Red Hat initiative to harden broadly used open-source elements by AI-driven validation and coordinated patching, alongside monetary establishments together with Financial institution of America, JPMorganChase, Goldman Sachs, and Mastercard. The dedication extends the identical logic upstream, as a result of the MTTA clock doesn’t pause at any single firm's perimeter.

    When brokers begin shopping for issues

    Securing agentic commerce is Visa's subsequent drawback. Taneja described a future the place AI brokers transact on behalf of shoppers and enterprises, and stated Visa is constructing the belief framework, id layer, and agent readiness scoring that retailers will want earlier than brokers can safely full transactions. Behind that work sits the Visa Fee Threats Lab, a simulation surroundings the place actual fraud eventualities get replayed towards the authorization guidelines, thresholds, and configurations Visa really runs, to floor AI-enabled failure modes as focused hardening suggestions.

    The id problem shouldn’t be theoretical. VentureBeat's Pulse analysis discovered that 69% of enterprises already run credential sharing someplace of their agent deployments, and corporations with shared credentials report safety incidents or near-misses at a 63.5% charge, towards 40.9% the place each agent has its personal scoped id. Visa's white paper addresses that hole straight, itemizing "AI brokers are identities" amongst its 12 non-negotiable practices and requiring scoped permissions, least privilege enforcement, full audit trails, and inclusion in IAM governance for each agent that calls an API, reads knowledge, or modifies a system.

    Three priorities for defenders

    Visa is organizing its defensive technique round three priorities, Taneja stated. Shift safety left till exploitable flaws are designed out earlier than they attain manufacturing, and exchange high-risk, under-supported elements earlier than they flip into materials publicity. The third is the heaviest raise at Visa's scale, refactoring defenses to run autonomously beneath human governance so detection, validation, and response preserve tempo as menace quantity grows and the fashions behind assaults enhance.

    None of it requires a cost community's finances to begin. The harness sits on GitHub with 595 stars and 97 forks as of July 20, MTTA wants a dashboard somewhat than a procurement cycle, and the white paper's 12 non-negotiable practices map onto structure opinions safety groups already run. Visa's personal conclusion reads like a deadline. The opening to get forward of machine-speed attackers remains to be there, the paper argues, and it’ll not keep open.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleInside the rogue ChatGPT hack of Hugging Face
    Next Article SEC Chairman Wants To Advance Crypto Clarity Act
    FreshUsNews
    • Website

    Related Posts

    Tech Updates

    Snowflake launches Cortex AI Gateway to control AI agents and prevent runaway enterprise costs

    July 28, 2026
    Tech Updates

    Kimi K3's full weights are here, but they're 'open' with a caveat: What enterprises should know

    July 28, 2026
    Tech Updates

    Uh-oh: Some Claude shared conversations and Artifacts appear to be indexed and publicly accessible on Google Search

    July 27, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Last Night in Baseball: The Astros Swept the Dodgers

    July 7, 2025

    Men like Trump represent what the founders were fighting against

    December 1, 2025

    Opinion | Iraq War Veterans, 20 Years Later

    November 11, 2025

    Mathematically Predicting Bitcoin Price Floor

    November 8, 2025

    CME Capitalizes On ADA, XLM, LINK In Crypto Strategy: Key Figures Exposed

    March 2, 2026
    Categories
    • Bitcoin News
    • Blockchain
    • Cricket
    • eSports
    • Ethereum
    • Finance
    • Football
    • Formula 1
    • Healthy Habits
    • Latest News
    • Mindful Wellness
    • NBA
    • Opinions
    • Politics
    • Sports
    • Sports Trends
    • Tech Analysis
    • Tech News
    • Tech Updates
    • US News
    • Weight Loss
    • World Economy
    • World News
    Most Popular

    Run a Node Grants Round Grantee Announcement

    July 29, 2026

    SEC Chairman Wants To Advance Crypto Clarity Act

    July 29, 2026

    Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible

    July 29, 2026

    Inside the rogue ChatGPT hack of Hugging Face

    July 29, 2026

    League of Legends World Championship tickets are appearing for over $3,000, but Riot may not be the one to blame

    July 29, 2026

    “If I say this, people might laugh at me…”: Deep Dasgupta hails Team India despite their inconsistent T20I performances

    July 29, 2026

    Micah Parsons Injury Updates: Latest News Surrounding Packers Edge Rusher

    July 29, 2026
    Our Picks

    Ethereum Network Experiences Rapid Growth In Daily Transactions Amid Rising ETH Prices

    March 27, 2026

    Analyst Says XRP’s $15 Target Has Still Not Changed, Here’s Why

    February 28, 2026

    Malick Thiaw poised to complete £35m Magpies move following medical

    August 12, 2025

    COVID Has Killed 15 Million People Worldwide, WHO Says

    July 22, 2025

    Queen Elizabeth Under Medical Supervision, Doctors “Concerned”

    July 13, 2025

    Dogecoin Cracks Again: BTC Pair Collapse Signals Imminent Drop To $0.07

    April 12, 2026

    Ethereum’s growing pains and the crypto landscape

    July 5, 2025
    Categories
    • Bitcoin News
    • Blockchain
    • Cricket
    • eSports
    • Ethereum
    • Finance
    • Football
    • Formula 1
    • Healthy Habits
    • Latest News
    • Mindful Wellness
    • NBA
    • Opinions
    • Politics
    • Sports
    • Sports Trends
    • Tech Analysis
    • Tech News
    • Tech Updates
    • US News
    • Weight Loss
    • World Economy
    • World News
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    Copyright © 2025 Freshusnews.com All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.