Connect with us

Tech News

Visa’s Advanced Security AI: Preventing Vulnerabilities with Preemptive Code Patches

Published

on

Visa ships a security AI that patches production code before any human reviews it

Visa has introduced an open-source security tool called the Visa Vulnerability Agentic Harness, which automates the process of finding vulnerabilities, fixing them, and validating the fixes without human intervention. This tool runs on 11 stages and can edit source files in the target repository. The default setting ships with the tool, but users can limit it to detection only.

The release of this tool comes after a demonstration of a cyberattack called GhostJacking at DEF CON 34. In response to this, Visa has implemented an automated approach to security to address vulnerabilities quickly. The company’s president of technology, Rajat Taneja, emphasizes the importance of quickly fixing vulnerabilities, stating that AI can find vulnerabilities faster than humans can historically.

The Visa Vulnerability Agentic Harness (VVAH) has gained popularity since its launch, with many high-profile companies using it. The tool is designed to protect Visa’s ecosystem but is also made available to other companies as a way to give back to the cybersecurity community.

One key feature of VVAH is the ability to automate the entire process of discovering, verifying, remediating, validating, and iterating vulnerabilities. The tool uses advanced models for semantic reasoning and leverages AI to provide better context and exploitability analysis.

Visa has introduced a new metric called Mean Time to Adapt (MTTA), which measures the time between discovering and resolving attack paths. The company claims that using VVAH has reduced resolution times from weeks to hours. The tool focuses on how quickly an enterprise can adapt to security threats rather than just finding them.

See also  Maximizing Healthcare Efficiency: AI Solutions for Cost Reduction and ROI

VVAH incorporates multiple AI models for different stages of the process, allowing users to choose the most suitable model for each stage. The tool is designed to work with different AI providers and does not rely on a single model for all tasks.

Visa emphasizes the importance of human oversight in the security process, with multiple approval gates in place to ensure that fixes are thoroughly reviewed before implementation. The company also highlights the need for context in security decisions, as VVAH takes into account factors like threat models and business risks.

In conclusion, Visa’s Visa Vulnerability Agentic Harness is a powerful tool for automating the security process and addressing vulnerabilities quickly. The company’s focus on speed to remediation highlights the importance of adapting to cybersecurity threats in a timely manner. By leveraging AI and advanced models, VVAH aims to provide better security outcomes for enterprises.

Trending