Visa has joined Anthropic's Project Glasswing initiative to test its cybersecurity defences using AI models, uncovering thousands of vulnerabilities across widely used software.
The US-based payments network confirmed its participation in Project Glasswing, Anthropic's defensive cybersecurity initiative, which is designed to test organisational defences at the speed AI-driven threats now move. Visa processes hundreds of billions of transactions annually, and the company said its network has been built up over many years through zero trust architecture, layered defences, and automated security operations. Joining the initiative was intended to establish where advanced AI models could extend those existing protections further.
Scale of vulnerabilities uncovered
According to Anthropic, participants across Project Glasswing identified more than 10,000 high- or critical-severity vulnerabilities in widely used, systemically important software during the first month of testing. Anthropic noted that the constraint on software security is no longer the speed at which vulnerabilities are found, but the speed at which they can be verified, disclosed, and patched.
To support its own testing, Visa developed a multi-model security test suite, now in its fifth generation, built around a scanning harness that maps the company's codebase, deploys AI agents to identify vulnerabilities, and categorises and prioritises findings for developers. The company has open sourced this tool, called the Visa Vulnerability Agentic Harness, to support similar defensive work across the wider industry. Since its release, Visa has extended the harness beyond identification to include remediation and validation, with patch validation agents addressing and confirming fixes, while security and engineering teams retain oversight of severity assessment and remediation decisions.
Findings and lessons from testing
Visa outlined three observations from the testing period. First, the model used, referred to as Mythos, was able to carry out system-wide, context-aware analysis, including identifying vulnerabilities that could become more serious when chained together. Second, Visa introduced a metric it calls Mean Time to Adapt, which tracks how quickly a vulnerability can be confirmed as exploitable, fixed, and verified as closed in production, arguing that this measure is becoming as significant as detection speed. Third, the company highlighted rising supply chain risk, noting its involvement in IBM and Red Hat's Project Lightwell, an industry effort focused on open-source security through AI-driven validation and coordinated patching.
Visa said the testing confirmed that critical findings would have been prevented from exploitation by its existing zero trust controls and network segmentation, while also surfacing new vulnerabilities for remediation.
Implications for cyber defence
Visa said its response to these findings is organised around three priorities: reducing the attack surface earlier in its code and build pipelines, reducing dependency on high-risk open-source and commercial components, and increasing the autonomy of its detection, validation, and response capabilities under human governance. The company noted that other frontier AI models are approaching similar capabilities, suggesting these tools will become more widely accessible across the sector, with implications for how the broader payments and technology industry approaches supply chain risk and vulnerability remediation.