Linux Foundation tech firms launch Akrites to protect open source

The Linux Foundation launched Akrites with 19 founding members to coordinate confidential patching of critical open-source vulnerabilities before AI-enabled attackers can exploit them.

The Linux Foundation on Thursday launched Akrites, an industry initiative formed by 19 founding members to coordinate rapid, confidential remediation of critical open-source vulnerabilities discovered by advanced AI tools.

Founding organizations include Amazon, Anthropic, Citi, Google, JPMorgan Chase, Microsoft, NVIDIA and OpenAI, among others. The group intends to provide a single channel for validated vulnerability reports and to work directly with project maintainers to deliver fixes upstream.

Organizers said the effort responds to faster discovery timelines created by large AI models that can scan large codebases and surface confirmed bugs in minutes. Anthropic’s deputy CISO, Jason Clinton, wrote in the founding letter that the prior coordinated disclosure process “has been outpaced by how quickly AI can now find vulnerabilities.” Endor Labs CEO Varun Badhwar reported that fewer than 5% of thousands of validated open-source vulnerabilities surfaced by AI in recent months have been patched.

Akrites will run a confidential Security Incident Response Team to receive validated findings and coordinate remediation with maintainers. The initiative will return fixes to each project’s original repository using standard vulnerability-tracking practices. When a critical package lacks active maintainership, Akrites has pledged to act as maintainer of last resort.

The founding letter highlighted cases in which advanced AI models quickly found severe bugs that had not been detected by earlier reviews. Organizers said those incidents show a risk that publicly disclosed flaws could be exploited before downstream systems install fixes.

Pat Opet, CISO at JPMorgan Chase, wrote that adversaries can reverse-engineer a published patch and build an exploit before many users update, and that success requires “patch deployment, not patch publication.” The initiative therefore emphasizes not only producing fixes but also helping ensure they reach production environments.

OpenAI launched a related project, Patch the Planet, three days before Akrites. Patch the Planet centers on AI-assisted discovery and rapid patch delivery with human review. Akrites is intended to serve as an industry-wide coordination layer that routes validated findings upstream and helps maintainers apply fixes.

The Alpha-Omega fund, directed by the Linux Foundation, will provide seed funding for Akrites. The fund has issued more than 70 grants totaling over $20 million to open-source security projects since 2022. The Linux Foundation said other organizations can join by contributing engineering resources or funding and directed interested parties to akrites.org for details.

Rebecca Rumbul, chief executive of the Rust Foundation, wrote that the initiative will provide maintainers with financial support and full-time assistance to find, fix and disclose security vulnerabilities responsibly, and that the program aims to reduce the burden on voluntary maintainers.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author