Visa's autonomous security tool now writes and self-tests patches before human sign-off
Visa has released an open-source security harness that automatically detects vulnerabilities, generates fixes, and runs an adversarial review on its own patch before any human involvement. The system, which operates by default across 11 stages, can edit source files in the target repository unless operators restrict it to detection only. The announcement also expands Visa's consulting advisory practice, arriving 18 days after a demonstration of GhostJacking at DEF CON 34.
The new open-source harness from Visa operates through 11 default stages, scanning for flaws and drafting code fixes before running its own adversarial checks. Unless operators explicitly limit it to detection, the system can directly modify source files in the target repository, meaning human review occurs only after the patch is fully formed and self-tested. This release accompanies an expansion of Visa’s consulting advisory practice, and arrives just 18 days after the company demonstrated GhostJacking at DEF CON 34, signaling a broader push into proactive security tooling.
By packaging autonomous detection, patch generation, and self-critique into a single pipeline, Visa aims to shorten the window between vulnerability discovery and remediation. The open-source nature allows external teams to inspect or adapt the harness, though the default editing capability underscores a shift toward machine-driven code changes that humans later approve rather than initiate. The timing relative to the DEF CON demo suggests a deliberate sequence of public security research followed by practical tooling.
This tool could significantly reduce the burden on security teams, who may now rely on automated patches for routine vulnerabilities, freeing humans for complex threats. However, it also introduces risks: if the self-testing misses edge cases, flawed patches could propagate quickly across repositories, affecting developers and downstream users. Organizations adopting it may need to balance speed with oversight, as the default editing mode could lead to unintended code changes. Ultimately, its impact hinges on trust in the system’s adversarial review and the willingness of operators to constrain its autonomy.