Visa initially released VVAH in June after participating in Anthropic’s frontier AI cybersecurity initiative, Project Glasswing. While the first release of VVAH showed how AI can help security teams uncover vulnerabilities and assess exploitability, the latest release extends the workflow into remediation and validation of those vulnerabilities, according to the release.
Visa also announced in the release that to help clients navigate the evolving threat landscape driven by AI, it has expanded its Visa Consulting and Analytics (VCA) Cybersecurity Advisory Practice to include new advisory services focused on assessing risk, prioritizing remediation efforts and strengthening resilience.
The new advisory services include AI Cyber Leadership Education, VVAH-Informed Cybersecurity Maturity Assessment and VVAH Cyber Risk Prioritization and Roadmap, per the release.
“AI is compressing the time between vulnerability discovery and exploitation, which means defenders need a faster, more reliable path to action,” Rajat Taneja, president, technology at Visa said in the release. “By advancing VVAH and expanding our cybersecurity advisory capabilities, we’re helping organizations move from insight to validated remediation while strengthening resilience in an increasingly AI-driven threat landscape.”
Carl Rutstein, global head of Visa Consulting & Analytics, said in the release: “Our enhanced cybersecurity advisory services combine insights from implementing frontier AI models for cybersecurity, VVAH, and decades of payments expertise to help clients prioritize risk areas, act quickly and build sustainable cyber resilience.”
PYMNTS reported Aug. 11 that AI is starting to find vulnerabilities, test attack paths and, in some cases, act in ways that stretch the limits of the systems built to contain it.
Modern cyberattacks rarely begin with brute force. Instead, they exploit misconfigured APIs, compromised credentials or vulnerabilities introduced by third-party vendors, Jeremiah Dewey, head of Cyber Solutions at Visa, told PYMNTS in an interview posted in February.
In addition, zero-day exploits can now be weaponized in hours, not weeks, Dewey said.
“Threats are evolving very quickly,” Dewey said. “They can turn new entry points and new methodologies into fraud and monetary losses very quickly.”
For all PYMNTS AI coverage, subscribe to the daily AI Newsletter.