Connect with us

Tech News

Unleashing the Power of Mythos: How Visa Open-Sourced Bug Hunting in its Payment Network

Published

on

Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible

Visa’s Claude Mythos, developed by Anthropic, was aimed at enhancing the infrastructure supporting billions of daily transactions worldwide. This network spans over 200 countries, facilitates transactions in approximately 160 currencies, and connects nearly 5 billion payment credentials to more than 175 million merchant locations.

The model created by Anthropic, known as Mythos, was able to identify and address vulnerabilities deep within the system stack, providing insights that would typically only be discovered during late-stage penetration testing. Visa’s President of Technology, Rajat Taneja, shared the journey of how Visa embraced this innovative approach. The company decided to release the harness used for the hunt as open source, deviating from traditional remediation metrics in favor of a new measurement invented by their team.

Taneja, who has been leading technology strategy at Visa since 2019, highlighted the importance of building trust through a combination of pessimism and paranoia when it comes to global payments. The network’s robust security measures have been developed over many years, incorporating zero-trust architecture, layered defenses, and automated security operations to ensure the reliability and security of global payments.

When Anthropic invited organizations to test Mythos under Project Glasswing, Visa participated eagerly. The results were impressive, with over 10,000 high-severity vulnerabilities identified within the first month of testing. The Mythos model demonstrated the ability to analyze the system comprehensively, identifying critical vulnerabilities and potential exploit chains that could pose significant risks.

Visa’s response to these findings was the development of the Visa Vulnerability Agentic Harness, a sophisticated pipeline that integrates advanced AI models to enhance security measures. The harness operates through structured security tasks, enforcing controls and human oversight at every stage to ensure the quality of findings.

See also  Claude for Chrome: Secure Beta Launch Amid Ongoing Injection Attack Threats

One of the key innovations introduced by Visa is the concept of Mean Time to Adapt (MTTA), which focuses on how quickly a team can confirm, fix, and validate exploitable issues within their systems. This metric replaces traditional measures like mean time to detect, emphasizing the importance of effectively closing exploit paths rather than simply applying patches.

Moving forward, Visa is prioritizing supplier due diligence, making AI-specific security posture a crucial aspect of vendor evaluation. The company has also joined Project Lightwell, a collaboration with IBM and Red Hat aimed at strengthening open-source components through AI-driven validation.

In conclusion, Visa’s proactive approach to security, innovative use of AI models, and commitment to continuous improvement reflect the evolving landscape of cybersecurity in a rapidly advancing digital age. By embracing cutting-edge technology and fostering a culture of adaptability and resilience, Visa is setting the standard for secure global payments.

Trending