
Visa's open-source security harness now auto-patches vulnerabilities before human review.
The default runs all 11 stages and edits code.
This follows a GhostJacking attack demo at DEF CON 34.
What happened
Visa's open-source security harness now finds vulnerabilities, writes fixes, and runs an adversarial panel on its own patch before any human review. The full loop ships on by default, running all 11 stages and editing source files unless capped at detection.
Why it matters
The default is the opposite of what Steve Wilson, Exabeam's Chief AI and Product Officer and OWASP Top 10 for LLM Applications co-lead, advised two days earlier: 'put an authorization gate outside the model.' This could raise concerns about AI autonomy in security.
What to watch
The release follows Tenet Security's GhostJacking demo at DEF CON 34, where an agent read a payload from a log file and rewrote DNS with a valid credential—illustrating risks that Visa's harness aims to counter.
Ask the AI about this article →
Visa's release comes amid growing debate over AI safety in code generation. The harness's default autonomy—patching before human review—contrasts sharply with advice from security leaders like Steve Wilson, who advocates for an authorization gate. This tension highlights the balancing act between speed and control in AI-driven security. The GhostJacking demonstration at DEF CON 34 showed how agents can be exploited, underscoring the need for robust safeguards.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Chinese large-model developer Z.ai says it can now support large-scale inference using roughly 100,000 domesti…

A UK study by UK AI Security Institute and Limbic AI surveyed 6,474 British adults

Broadcom's Clayton Donley says companies are doing mission-critical work with AI agents quickly, but without t…
Bank of England governor Andrew Bailey warned that advanced AI poses risks to financial infrastructure in a le…
As AI agents perform real business tasks, 'Agentic Identity' (giving each AI a unique employee-like ID) and 'D…

Andrew Bailey, head of the world's financial stability watchdog, warned in a letter to G20 finance ministers a…
