---
url: "https://xcademia.com/news/visa-expands-ai-powered-cybersecurity-support-from-vulnerability-discovery-to-remediation"
title: "Visa Expands AI-Powered Cybersecurity Support From Vulnerability Discovery to Remediation"
description: "Visa expands its AI cybersecurity portfolio with VVAH remediation tools and new services for vulnerability management, risk prioritisation and resilience."
publishedAt: "2026-08-28T10:40:30.314+00:00"
updatedAt: "2026-08-28T12:03:24.513824+00:00"
type: news
category: cybersecurity
source_name: Visa Worldwide Pte Ltd via PR Newswire
source_url: "https://www.prnewswire.com/apac/news-releases/visa-expands-support-for-its-clients-and-the-industry-as-organisations-navigate-new-ai-era-of-cybersecurity-302861657.html"
tags:
  - "#Cybersecurity"
  - "#ArtificialIntelligence"
  - "#AICybersecurity"
  - "#VulnerabilityManagement"
  - "#CyberRisk"
  - "#AIAgents"
  - "#SecurityOperations"
  - "#OpenSourceSecurity"
---

# Visa Expands AI-Powered Cybersecurity Support From Vulnerability Discovery to Remediation

> Visa has expanded its AI-powered cybersecurity portfolio with a new release of its open-source Vulnerability Agentic Harness and three advisory services focused on vulnerability remediation, cyber risk prioritisation and security resilience.

Source: **Visa Worldwide Pte Ltd via PR Newswire** · 28 August 2026

**V**isa is expanding its cybersecurity portfolio as organisations face a security environment shaped by increasingly capable AI systems and faster-moving cyber risks.

On August 28, 2026, Visa announced the latest evolution of its **Visa Vulnerability Agentic Harness (VVAH)**, an open-source, model-agnostic framework designed to help security teams move from vulnerability discovery toward remediation and validation.

Visa says the latest release is intended to help organisations identify vulnerabilities, assess their exploitability, remediate issues and validate fixes through a structured workflow.

The company also announced three new cybersecurity advisory services from **Visa Consulting & Analytics (VCA)**. The services are designed to help organisations assess cybersecurity risk, prioritise remediation efforts and develop longer-term approaches to cyber resilience.

Visa says the expanded portfolio reflects a shift in how organisations should evaluate cyber risk, with greater emphasis on how quickly important vulnerabilities can be addressed rather than simply counting the number of vulnerabilities discovered.
The company reports that some vulnerability resolutions have been reduced from weeks to hours, although the announcement does not provide broader performance benchmarks or details about the specific environments in which those results were achieved.

**From Vulnerability Discovery to Validated Remediation**

VVAH was originally released following Visa's participation in Anthropic's frontier AI cybersecurity initiative, **Project Glasswing**.

The initial framework demonstrated how AI could assist security teams with vulnerability discovery, exploitability assessment and the generation of structured findings.

The latest release extends that workflow.

Visa says VVAH can now support a more complete process covering:

**Discover → Triage → Remediate → Validate**

This moves the framework beyond identifying potential weaknesses and toward helping security teams evaluate remediation efforts and determine whether fixes have addressed the identified issues.

The approach is designed around a closed workflow rather than treating vulnerability discovery and remediation as separate activities.

## 
What Is New in the Latest VVAH Release?

Visa highlights three key enhancements in the latest version of the Vulnerability Agentic Harness.

**Closed-Loop Remediation**

The updated framework introduces structured feedback for remediation attempts that do not pass validation.

Visa says this feedback allows teams to refine fixes without restarting the entire process.

The concept creates a loop between remediation and validation, allowing failed fixes to be reconsidered as part of the same workflow.

This is an important distinction from a discovery-only security process because the objective is not simply to identify a vulnerability, but to continue through remediation and validation.

**Flexible AI Model Choice**

The latest VVAH release is also designed to support greater flexibility in model selection.

Visa says organisations can deploy approved **Anthropic models and OpenAI models**, as well as other AI models through configuration rather than code changes.

The model-agnostic approach is intended to separate the framework's workflow from dependence on a single AI model.

Visa does not provide a complete list of supported models in the announcement.

**Greater Visibility Into Long-Running Workflows**

Visa has also added optional real-time progress views.

The company says these views provide additional transparency into long-running scanning and remediation workflows.

For security teams, visibility into ongoing processes can make it easier to understand the status of a workflow while it is running.

The announcement does not provide additional technical specifications for the progress-view implementation.

## 

![info-1](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1787913149894-info-1--109-.webp)

## 
Why Mean Time to Adapt Is Becoming a Focus

Visa's announcement places particular emphasis on **Mean Time to Adapt (MTTA)**.

The company describes MTTA as the time between the discovery and resolution of attack paths.

Visa argues that simply identifying large numbers of vulnerabilities is not enough in an environment where AI can accelerate both cyber threats and the exploitation of vulnerabilities.

The company's stated focus is therefore on determining which risks matter most and reducing the time required to respond to them.

Prateek Sanghi, Head of Visa Consulting & Analytics, Asia Pacific, said the focus is shifting from the **"number of vulnerabilities identified"** toward Mean Time to Adapt.

This represents Visa's stated perspective rather than an industry-wide measurement standard established by the announcement.

For organisations, the concept highlights a broader operational question: how quickly can security teams move from identifying a meaningful risk to implementing and validating a response?

## 
Three New Cybersecurity Advisory Services

Alongside the VVAH update, Visa Consulting & Analytics is expanding its cybersecurity advisory practice with three new services.

The services are intended to help organisations translate security findings into prioritised remediation and longer-term cybersecurity planning.

**1. AI Cyber Leadership Education**

The first service focuses on executive education and organisational preparedness.

Visa says the offering includes executive workshops, training and Visa University certification courses led by its AI and cybersecurity specialists.

The programme is designed to share lessons from Visa's experience with frontier AI cybersecurity and help leaders prepare for an increasingly AI-driven threat environment.

**2. VVAH-Informed Cybersecurity Maturity Assessment**

The second service uses the VVAH framework as part of a cybersecurity maturity assessment.

Visa says the service helps organisations identify and evaluate potential vulnerabilities, understand areas of risk and prioritise remediation efforts.

The objective is to provide organisations with a structured view of their security posture and help determine where remediation should receive attention.

The announcement does not provide a specific scoring methodology or maturity-rating framework.

**3. VVAH Cyber Risk Prioritisation and Roadmap**

The third service focuses on longer-term cyber risk planning.

Visa says the service provides strategic guidance to help organisations evaluate findings, prioritise remediation efforts and develop a long-term cyber risk management roadmap.

This connects the technical findings generated through vulnerability assessment with broader organisational planning.

## 
From Security Findings to Risk Prioritisation

The three advisory services reflect a broader structure within Visa's announcement:

**Understand → Assess → Prioritise → Remediate → Strengthen**

The first step is understanding the organisation's cybersecurity environment.

The next involves assessing vulnerabilities and broader areas of risk.

Organisations can then prioritise remediation based on the risks they consider most important.

VVAH focuses on the technical workflow around vulnerability discovery, remediation and validation, while the advisory services address leadership, maturity assessment and longer-term risk planning.

Together, Visa presents these capabilities as complementary components of its expanded cybersecurity support.

## 

![info-2](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1787913178225-info-2--90-.webp)

## 
CAIXA Cartões Uses Visa for Cybersecurity Maturity Assessment

Visa also highlighted an example involving **CAIXA Cartões**.

According to Visa, the organisation worked with Visa to support a cybersecurity maturity assessment and prioritise initiatives related to risk management and operational resilience.

Lessandro Thomaz, Executive Director at CAIXA Cartões, said the engagement helped broaden the organisation's strategic perspective on cybersecurity through a structured assessment of process maturity and prioritisation of initiatives.

The example illustrates how Visa's advisory services can be applied alongside an organisation's broader cybersecurity planning.

The announcement does not provide quantitative performance results from the CAIXA Cartões engagement.

## 
Growing Interest in AI-Powered Vulnerability Management

Visa says VVAH has seen growing interest since its open-source release in June 2026.

According to the company, the framework has been downloaded by **tens of thousands of developers worldwide**.

Visa presents this as an indication of interest in practical AI-powered vulnerability management.

Because the announcement does not provide a detailed breakdown of downloads, developer activity or geographic distribution, the figure should be understood as a company-reported measure rather than an independently verified adoption benchmark.

The open-source nature of VVAH also places the framework within a wider security community rather than limiting it to Visa's own internal environment.

## 
Visa Expands Its Role in Open Security Initiatives

The announcement also describes Visa's participation in broader initiatives focused on secure AI and open-source security.

Visa says it has joined NVIDIA's **Open Secure AI Alliance**, where it is contributing VVAH as a model-agnostic framework.

The company also says it is participating in IBM and Red Hat's **Project Lightwell**, collaborating with other organisations on efforts to secure open-source software.

These initiatives position VVAH within a wider ecosystem of organisations working on AI and software security.

The announcement does not provide specific details about Visa's individual contributions to Project Lightwell beyond its stated collaboration.

## 

![info-3](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1787913301621-info-3--84-.webp)

## 
What This Means for Security Teams

Visa's announcement highlights a broader industry shift toward using AI not only to discover security issues, but also to support the operational processes that follow discovery.

For security teams, this could mean placing greater emphasis on the complete vulnerability lifecycle.

Finding a vulnerability is one stage.

Understanding its importance, deciding how quickly it should be addressed, implementing a fix and validating that fix are separate operational activities.

VVAH is designed around bringing these stages into a structured workflow.

The introduction of advisory services adds another layer by addressing cybersecurity maturity, leadership education and longer-term risk prioritisation.

The combination reflects a model in which technical vulnerability management and organisational cybersecurity planning are treated as connected activities.

## 
Why Validation Matters

A vulnerability remediation process can become more difficult if teams cannot determine whether a fix has actually addressed the underlying issue.

Visa's latest VVAH release specifically adds validation to the workflow and introduces feedback when remediation attempts fail validation.

This closed-loop approach is one of the more notable changes in the announcement.

Rather than stopping after a vulnerability is identified or a remediation attempt is made, the workflow continues toward validation.

For enterprises, this highlights the importance of measuring security processes through outcomes and response actions, rather than focusing solely on the volume of vulnerabilities discovered.

## 
Model Agnosticism and AI Security

Visa's decision to describe VVAH as model-agnostic is another significant element of the announcement.

The company says the framework can work with approved Anthropic and OpenAI models, as well as other models through configuration rather than code changes.

This approach reflects the rapidly changing AI model landscape, where organisations may need flexibility in selecting models for security workflows.

The announcement does not specify how different models perform within VVAH or provide comparative benchmarks.

As a result, the significance of model flexibility should be understood as an architectural characteristic described by Visa rather than evidence that one model performs better than another.

## 
From Vulnerability Counts to Risk-Based Response

One of the strongest themes in Visa's announcement is the argument that vulnerability management should focus on risk rather than volume alone.

A large number of findings does not necessarily indicate which issues require the most immediate attention.

Visa's MTTA concept places greater emphasis on the time required to move from discovery to resolution.

This approach aligns with a broader industry focus on prioritisation and operational resilience.

For security leaders, the challenge is therefore not simply identifying more vulnerabilities. It is determining which vulnerabilities matter most and ensuring that the organisation has a process for addressing and validating them.

Visa's new advisory services are designed around this broader risk-management perspective.

## 
The Bigger Picture

The announcement reflects a broader industry shift toward integrating AI into security operations while maintaining structured processes for risk assessment and remediation.

VVAH represents Visa's approach to the technical side of that challenge, extending an AI-powered vulnerability workflow into remediation and validation.

The three VCA services address the organisational side, including leadership education, cybersecurity maturity assessment and long-term risk prioritisation.

For enterprises, this could mean that the value of AI-powered cybersecurity will increasingly depend on what happens after vulnerabilities are discovered.

The ability to identify a potential weakness is useful, but organisations also need processes for deciding which risks matter most, implementing appropriate remediation and validating the results.

Visa's announcement is centered on that transition from discovery to action.

## 
Conclusion

Visa is expanding its cybersecurity portfolio with an updated Vulnerability Agentic Harness and three new cybersecurity advisory services.

The latest VVAH release extends the framework from vulnerability discovery and assessment into remediation and validation, with closed-loop feedback designed to help teams refine fixes that do not pass validation.

The framework also adds support for multiple AI model options through configuration and optional real-time progress views for long-running workflows.

Alongside VVAH, Visa Consulting & Analytics is introducing services focused on AI cybersecurity leadership education, cybersecurity maturity assessment and cyber risk prioritisation.

Visa says the expansion reflects a changing security environment in which organisations need to focus not only on finding vulnerabilities, but also on determining which risks matter most and how quickly they can be addressed.

The broader development reflects growing demand for AI-assisted cybersecurity processes that connect discovery, prioritisation, remediation and validation within a more structured operational lifecycle.

## Original source

https://www.prnewswire.com/apac/news-releases/visa-expands-support-for-its-clients-and-the-industry-as-organisations-navigate-new-ai-era-of-cybersecurity-302861657.html

## Tags

`#Cybersecurity` · `#ArtificialIntelligence` · `#AICybersecurity` · `#VulnerabilityManagement` · `#CyberRisk` · `#AIAgents` · `#SecurityOperations` · `#OpenSourceSecurity`

---

## About this content

This Markdown news article is the citation-grade twin of [Visa Expands AI-Powered Cybersecurity Support From Vulnerability Discovery to Remediation](https://xcademia.com/news/visa-expands-ai-powered-cybersecurity-support-from-vulnerability-discovery-to-remediation). It is published by **Xcademia** (UK Companies House 12322710) and is available for AI search engines and large language models to index, summarise, and cite.

When citing or quoting, please attribute *Xcademia* and link back to the source URL above.

- Source: https://xcademia.com/news/visa-expands-ai-powered-cybersecurity-support-from-vulnerability-discovery-to-remediation
- Publisher: Xcademia — https://xcademia.com
- Catalogue index: https://xcademia.com/llms-full.txt
