search

LEMON BLOG

Visa Expands Open-Source VVAH Tool to Help Security Teams Move From Vulnerability Discovery to Remediation

Artificial intelligence is changing cybersecurity on both sides of the battlefield. Attackers can now identify weaknesses, test potential exploits and automate parts of an attack far more quickly than before. For defenders, that means simply discovering vulnerabilities is no longer enough. The real challenge is how quickly those vulnerabilities can be assessed, fixed and verified before someone else takes advantage of them.

Visa is responding to that shift by expanding its open-source Visa Vulnerability AI Helper, or VVAH, with new capabilities focused on vulnerability remediation and validation. At the same time, the company is broadening its Visa Consulting & Analytics (VCA) Cybersecurity Advisory Practice, giving organisations additional services for evaluating cyber risk, prioritising remediation work and improving long-term resilience.

The overall direction is fairly clear: Visa wants cybersecurity teams to spend less time moving findings between disconnected tools and more time turning those findings into verified fixes.

Cybersecurity Is Becoming a Race Against Time

One of the biggest changes introduced with the updated VVAH is the emphasis on what Visa describes as "Mean Time to Adapt."

Traditionally, cybersecurity teams have spent a great deal of effort measuring how quickly incidents are detected and resolved. But as AI accelerates vulnerability research and exploitation, the period between discovering a weakness and seeing it actively targeted can become dramatically shorter.

Visa says its updated approach is intended to reduce the time between identifying an attack path and successfully resolving it. In some cases, remediation processes that once required weeks of work have reportedly been reduced to hours.

Rajat Taneja, President of Technology at Visa, described the situation as an increasingly compressed security window, where AI allows vulnerability discovery and exploitation to happen much faster than before.

For organisations, that changes the priority from simply asking "Do we know where our vulnerabilities are?" to something more urgent:

That last point is particularly important. Applying a patch does not necessarily mean a problem has been solved. Security teams still need to validate that the remediation works and has not introduced another issue elsewhere.

VVAH Is Moving Beyond Vulnerability Discovery

VVAH originally emerged from Visa's involvement with Project Glasswing, Anthropic's frontier AI cybersecurity initiative.

Its earlier capabilities demonstrated how artificial intelligence could support security teams in areas such as discovering vulnerabilities, analysing whether those weaknesses could be exploited and producing structured security findings.

The latest version extends that idea much further.

Rather than ending the workflow once a vulnerability has been identified, VVAH can now continue through remediation and validation. This creates something closer to an end-to-end vulnerability management workflow.

The process can broadly move through:

Bringing those stages together could reduce one of the biggest inefficiencies in enterprise cybersecurity: handing information between several different systems, teams and processes before anything actually gets fixed.

Closed-Loop Remediation Could Make Fixing Vulnerabilities Faster

One of the most notable additions is what Visa calls closed-loop remediation.

In a conventional workflow, a security tool might identify a vulnerability and suggest a fix. If that fix fails testing, someone may need to investigate the problem manually, modify the recommendation and restart portions of the process.

VVAH instead introduces structured feedback into the remediation cycle.

If a proposed fix fails validation, the result can be fed back into the workflow so that the remediation can be refined rather than starting everything again from scratch.

Conceptually, this creates a loop:

For security teams dealing with hundreds or thousands of findings, reducing the amount of repetitive manual work involved in that process could make a meaningful difference.

It also reflects a broader direction in AI-assisted software development. AI systems are gradually moving beyond simply generating answers or code snippets and toward workflows where outputs are automatically checked, corrected and tested.

Security Teams Are No Longer Locked to a Single AI Model

Another important change is improved model flexibility.

AI technology is evolving extremely quickly, and organisations may not want their cybersecurity infrastructure permanently tied to one model or one AI provider.

Visa says VVAH now allows teams to swap or introduce AI models through configuration instead of modifying the underlying code.

That means a security team could potentially evaluate models from providers such as Anthropic, OpenAI or other AI platforms without rebuilding the entire vulnerability-management pipeline.

This model-agnostic approach could become increasingly valuable.

Different AI models may perform better at different cybersecurity tasks. One model might be stronger at analysing code, while another might provide better reasoning around attack paths or remediation strategies.

It also means organisations can experiment with newer models as they become available without completely redesigning their security workflow.

Real-Time Progress Makes Long Security Jobs Easier to Follow

VVAH is also introducing optional real-time progress visibility for longer-running scans and remediation activities.

That may sound like a relatively small interface improvement compared with AI-assisted remediation, but it addresses a practical problem.

Large vulnerability scans can take time, particularly when an AI system is analysing numerous attack paths, validating findings and generating remediation steps.

Instead of simply waiting for a process to finish, security teams can monitor what the system is doing while the job is still running.

For operational teams, that visibility can make automated cybersecurity processes easier to supervise and potentially easier to troubleshoot.

Visa Is Expanding Cybersecurity Consulting Alongside the Technology

Visa is not treating VVAH purely as a software project.

Its Visa Consulting & Analytics Cybersecurity Advisory Practice is also introducing three services intended to help organisations translate technical security findings into broader business and risk-management decisions.

The first is AI Cyber Leadership Education.

This focuses on executives and organisational leaders through workshops, specialist training and Visa University certification courses. The goal is to help leadership teams better understand how AI is changing cybersecurity and what that means for organisational risk.

This matters because cybersecurity decisions increasingly extend beyond IT departments. Executives may need to make decisions about investment, governance, operational resilience, data protection and acceptable levels of risk.

The second offering is the VVAH-Informed Cybersecurity Maturity Assessment.

Rather than looking at vulnerabilities individually, this service evaluates an organisation's overall cybersecurity maturity. VVAH findings can then contribute to identifying weaknesses, evaluating risk areas and deciding which remediation efforts should receive priority.

The third service is the VVAH Cyber Risk Prioritization and Roadmap.

This goes a step further by helping organisations transform security findings into a longer-term improvement plan.

Instead of trying to fix every vulnerability at once, organisations can evaluate factors such as:

That prioritisation is becoming increasingly important because modern organisations rarely suffer from a shortage of vulnerability findings. The bigger challenge is deciding which vulnerabilities matter most and what should be fixed first.

Finding Vulnerabilities Is Only Half the Job

Carl Rutstein, Global Head of Visa Consulting & Analytics, highlighted this changing dynamic by arguing that vulnerability discovery itself is becoming less of a challenge.

The bigger competitive advantage for defenders is now the speed at which they can move from identifying a security weakness to successfully fixing it.

That argument makes sense in an environment where automated scanners and AI tools can potentially generate enormous numbers of findings.

A security dashboard containing 20,000 vulnerabilities is not necessarily useful if the organisation does not know which 50 vulnerabilities represent the most immediate threat.

This is where AI-powered prioritisation and remediation tools could have their greatest impact.

Rather than simply increasing the number of problems an organisation knows about, the technology can potentially help narrow those findings into actions that security teams can realistically address.

Cybersecurity Advisory Services Are Already Being Used by Clients

Visa says its cybersecurity advisory practice has spent the past year working with organisations on areas including cybersecurity maturity assessments, risk evaluation and operational resilience.

One publicly identified client is CAIXA Cartões.

The organisation worked with Visa's advisory practice to evaluate its cybersecurity maturity and establish priorities around risk management and operational resilience.

Lessandro Thomaz, Executive Director at CAIXA Cartões, described cybersecurity as an important foundation for both customer trust and long-term business sustainability.

According to Thomaz, the partnership with Visa helped the organisation gain a broader strategic view of cybersecurity by providing a structured assessment of its existing processes and helping prioritise future risk-management initiatives.

That type of engagement illustrates the role Visa appears to be positioning itself for: not simply providing another cybersecurity scanning tool, but helping organisations connect technical vulnerability data with larger business-risk decisions.

Open-Source Adoption Is Growing

The open-source nature of VVAH is another interesting part of the strategy.

Visa says the tool has been downloaded by tens of thousands of developers worldwide since its open-source release in June 2026.

That suggests there is considerable interest in practical applications of AI within vulnerability management rather than AI being treated purely as an experimental cybersecurity technology.

Open-source availability also allows developers and security researchers to inspect the framework, experiment with different models and potentially adapt it to their own environments.

That could be especially useful as organisations develop different approaches to AI security depending on their infrastructure, regulatory requirements and risk tolerance.

Visa Is Also Working With Wider Industry Security Initiatives

Visa's cybersecurity work is increasingly connected to larger industry collaborations.

The company has joined NVIDIA's Open Secure AI Alliance, contributing VVAH as a model-agnostic framework.

That aligns with the broader idea of preventing AI-powered cybersecurity systems from becoming dependent on a single model provider or technology stack.

Visa is also participating alongside other organisations in Project Lightwell, an initiative involving IBM and Red Hat focused on strengthening the security of open-source software.

The collaborations highlight another reality of modern cybersecurity: vulnerabilities rarely exist within the boundaries of a single organisation.

A company might rely on thousands of open-source libraries, cloud platforms, APIs and third-party services. Weaknesses discovered somewhere in that software supply chain can eventually affect organisations that have never interacted directly with the original developer.

That makes cooperation between software vendors, financial institutions, infrastructure providers and cybersecurity researchers increasingly important.

AI Is Changing What Vulnerability Management Looks Like

The bigger story behind Visa's VVAH update is not really about another cybersecurity tool gaining several new features.

It reflects how vulnerability management itself is beginning to change.

For years, the industry's focus was heavily centred on finding vulnerabilities. Organisations deployed scanners, penetration-testing tools and monitoring platforms designed to uncover as many weaknesses as possible.

Today, discovery is becoming increasingly automated.

The next challenge is managing everything that comes afterward.

Security teams need to understand which vulnerabilities are genuinely dangerous, determine the appropriate fix, verify the remediation and continuously repeat the process as new weaknesses appear.

AI could potentially make each of those stages faster.

However, automation does not remove the need for experienced security professionals. AI-generated remediation still needs appropriate controls, testing and oversight, particularly when changes affect production systems or critical infrastructure.

The most effective model may therefore be one where AI handles much of the repetitive analysis while human security professionals remain responsible for higher-level judgement, verification and risk decisions.

Final Thoughts

Visa's expansion of VVAH shows how quickly the conversation around AI and cybersecurity is evolving.

Only a short time ago, much of the discussion focused on whether AI could discover vulnerabilities or assist security researchers. Now the focus is moving toward something much more operational: using AI to help organisations actually fix vulnerabilities, validate those fixes and prioritise security work at scale.

That shift could become increasingly important as attackers begin using the same generation of AI technologies.

If attackers can scan software, identify weaknesses and experiment with exploits faster than before, defenders cannot afford remediation workflows that still take weeks to complete.

Tools such as VVAH point toward a future where vulnerability management becomes a much more continuous cycle of discovery, analysis, remediation and verification.

And ultimately, that may be where AI delivers some of its most practical value in cybersecurity—not simply finding more problems, but helping organisations solve the important ones before attackers get there first.

What Belongs in the Medical Record When AI Is Part...
GunSpin – A Recoil-Powered Arcade Shooting Game Bu...

Related Posts

 

Comments 0

Loading latest comments...
Wednesday, 02 September 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection