Radar / AI security / Visa open-sources VVAH
Visa open-sources VVAH: agentic vulnerability discovery and remediation harness
Visa Vulnerability Agentic Harness - a model-agnostic open framework whose agents discover, verify, remediate and validate software vulnerabilities through a multi-stage pipeline: attack-surface mapping, deep analysis, adversarial verification, then fixes.
Why it matters
A payments giant publishing its internal cyber-defence agents (built from Anthropic's Project Glasswing learnings) for inspection and adaptation - enterprise-grade offensive/defensive security as open code instead of a closed platform.
What you could build with it
A small security consultancy can run VVAH against a client's codebase and hand back adversarially verified fixes with proof, not just a list of lint warnings.
Built with Visa open-sources VVAH
- Visa Open-Sources AI Cyber Defence Toolopensourceforu.com · Coverage of Visa's VVAH open-source release: model-agnostic multi-agent framework for vulnerability discovery, verification, remediation and validation, with Markdown/SARIF outputs and human oversight at critical decision points.
- VVAH v2 release notes analysis (pithomlabs/solvent)github · Independent analysis of the VVAH release that extends the pipeline past reporting into remediate/validate/iterate, with AST call-graph scanning, MTTA observability, and a critical reading of the three different Mean Time to Adapt definitions Visa uses.
- maximalfocus/visa-vulnerability-agentic-harnessgithub · 1 ★ · Community-maintained fork of Visa's VVAH (explicitly unaffiliated, follows upstream via release tags; version 1.4.0). Verified to exist via GitHub API.
- malikjpalamar/visa-vulnerability-agentic-harnessgithub · 1 ★ · Community fork of Visa's VVAH (v1.2.0) tracking the upstream harness for autonomous vulnerability discovery and validation. Verified to exist via GitHub API.
First spotted on newsletter: source.
More AI security
Cloudflare security-audit-skill: multi-phase security audits for coding agentsA coding-agent skill that runs multi-phase security audits with independently verified, machine-checkable findings.security · JEV 0.63Sandlock 0.8.8: deferred commit for agent sandboxesThe process-based Linux AI sandbox (no container, no VM) ships deferred commit: every run returns a changeset of what…security · JEV 0.56ClawSecure: free security scanner for OpenClaw AI agent skillsFree scanner that audits OpenClaw agent skills for vulnerabilities; the maker's audit of 2,890+ OpenClaw skills found…security · JEV 0.5Google DeepMind SynthID BioWatermarking technology that embeds an imperceptible, verifiable signature into AI-designed protein sequences and…security · JEV 0.49GitHub Security Lab Taskflow Agent: autonomous LLM fuzzing for C/C++Open-source agent that automates the full fuzzing lifecycle - entry-point discovery, harness generation, AFL++ runs…security · JEV 0.47LLM Agents Can Easily Tamper With Their Own TracesAn empirical study (arXiv 2026-09-24) showing that all tested local coding-agent harnesses except Muse Code allowed…security · JEV 0.4
Get the week's best AI launches, plus 3 ideas worth building
One email every Saturday. Ranked by traction, not hype. Free.