Visa has officially open-sourced the Visa Vulnerability Agentic Harness, a fifth-generation multi-model security test suite designed to map codebases, deploy AI agents, and prioritize findings. The tool, developed during Visa’s participation in Anthropic’s Project Glasswing, moves beyond simple detection to include remediation and validation workflows. This release addresses a critical bottleneck in modern security operations: while AI has made finding vulnerabilities exponentially faster, the human-driven process of verifying, disclosing, and patching those flaws has not kept pace.

Shifting from Detection to Adaptation

The core philosophy behind the harness is what Visa terms "Mean Time to Adapt." Traditional metrics focus on time to detect, but the Visa team argues that detection is no longer the hard part. The real challenge is confirming exploitability, fixing the issue, and proving the attack path is closed. The new harness supports this by allowing teams to interpret plain-language objectives and adapt to system changes without manual script maintenance. It operates continuously, enabling security teams to match the tempo of AI-accelerated threats while preserving human oversight for critical decision-making.

Lessons From Project Glasswing

During Project Glasswing, participants identified over 10,000 high- or critical-severity vulnerabilities in systemically important software in just the first month. Visa’s internal testing with the harness confirmed that their zero-trust architecture and network segmentation successfully broke the kill chain for many critical findings. However, the exercise also highlighted rising supply chain risks. Visa is now actively engaging with industry efforts like IBM and Red Hat’s Project Lightwell to strengthen open-source security through AI-driven validation, recognizing that vulnerabilities in third-party components can quickly become material exposure in an AI-accelerated threat environment.

Key Takeaways

  • The Visa Vulnerability Agentic Harness is now open source and includes remediation and validation agents, not just scanners.
  • Visa defines "Mean Time to Adapt" as the new critical metric, prioritizing the speed of confirming and fixing issues over initial detection.
  • The tool is designed for high-fidelity, low-noise analysis, specifically targeting deep-stack vulnerabilities and chained attack paths.
  • Visa is leveraging the tool to support a strategy of removing structural dependencies on high-risk open-source components.

The Bottom Line

If your security stack still relies on manual triage for every AI-discovered bug, you are already behind. Visa’s move to open-source their agentic harness signals that the future of defensive tooling isn't just about better scannersβ€”it's about autonomous pipelines that can reason, remediate, and validate at machine speed while keeping humans in the loop for governance.