Rajat Taneja

visa vulnerability agentic harness ai patching a upright shield pointed base

Visa Ships a Security AI That Patches Your Code Before Any Human Reviews It

Visa has open-sourced the Visa Vulnerability Agentic Harness, the tooling it used to hunt for bugs across its own payment network, and its documentation contains a line worth pausing on: “A plain scan edits your code.” In its default configuration the harness runs discovery, remediation and validation end to end, writing candidate fixes straight into source files before any person has looked at the finding or the patch. Nothing reaches production without a human, but nobody approves the patch before it is written. This breakdown covers the four-phase, eleven-stage pipeline, exactly where the “no human review” claim holds and where it collapses, what Visa itself says about oversight, and the independent evidence that only 26% of AI-generated security patches fix the flaw without changing what the software does.

Read more
CHAT