Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left
Back to News

Visa launches AI that automatically patches production code vulnerabilities

Visa has launched an automated security AI that detects vulnerabilities and applies patches to production code without human review, running by default unless opted out. This innovation could transfoโ€ฆ

Visa ships a security AI that patches production code before any human reviews it
VentureBeat โ€” 27 August 2026
Text:
2 0 0

Visa has launched an automated security system that can detect vulnerabilities, generate a fix, and apply the patch to a production code repository before any human engineer reviews it. The new tool, part of Visaโ€™s openโ€‘source Security Harness, is shipped with the default setting enabled, meaning the process runs automatically unless the operator chooses to stop it at the detection stage.

The move follows a recent demonstration by Tenet Security at DEFโ€ฏCONโ€ฏ34 that highlighted a new attack called GhostJacking. In the demo, an attackerโ€™s payload was read from a log file and used to rewrite DNS settings with valid credentials, showing how quickly a system can be compromised. Visaโ€™s announcement also dovetails with the companyโ€™s expansion of its Visa Consulting & Analytics advisory practice, positioning the harness as a core component of its security services.

The harness runs through 11 stages of analysis, automatically editing source files in the target repository. If an operator opts out, the tool can be capped at the detection phase. The AI writes the patch code itself and then subject it to an adversarial panel that tests the patch against potential attack vectors. The entire loopโ€”detection, patch creation, adversarial testing, and deploymentโ€”is enabled by default, allowing for rapid response to newly discovered threats.

Critics, including Steve Wilson of Exabeam, argue that such a default is risky. Wilson, who coโ€‘led the OWASP Topโ€ฏ10 for LLM Applications, said the first step should be an authorization gate outside the model. His concern points to broader questions about the safety of fully automated patching. If Visaโ€™s approach proves reliable, it could reshape how financial services and other highโ€‘risk sectors handle code security, but it may also invite regulatory scrutiny as the industry balances speed with oversight.

Read Full Story at VentureBeat โ†’
Advertisement
React:
Sources
Sponsored

More to Read

Woman alleges stepfather used Grok to create explicit imageโ€ฆ
๐Ÿ’ป Technology
Woman alleges stepfather used Grok to create explicit images of her childhood
TechCrunch ยท 14 days ago
California engineers develop plasma tunnel-boring machine fโ€ฆ
๐Ÿ’ป Technology
California engineers develop plasma tunnel-boring machine for secure underground infrastrโ€ฆ
BBC Business ยท 11 days ago
Robotaxis launch in San Francisco and Phoenix, raising safeโ€ฆ
๐Ÿ’ป Technology
Robotaxis launch in San Francisco and Phoenix, raising safety concerns
NPR News ยท 14 days ago
Iran voids 60-day nuclear negotiation deadline with US
๐ŸŒ World News
Iran voids 60-day nuclear negotiation deadline with US
France 24 ยท 11 days ago
Iran demands U.S. recognize defeat in Strait of Hormuz tensโ€ฆ
๐Ÿ›๏ธ Politics
Iran demands U.S. recognize defeat in Strait of Hormuz tensions
NBC News ยท 14 days ago
Russian strikes kill Ukrainian woman as NATO jet downs dronโ€ฆ
๐ŸŒ World News
Russian strikes kill Ukrainian woman as NATO jet downs drone over Romania
Al Jazeera ยท 13 days ago
Full view