Software and AI Companies Form Alliance to Combat Open Source Software Security Vulnerabilities
Several technology companies, including Anthropic, AWS, IBM, and Microsoft, announced a joint effort to discover, disclose, and fix security vulnerabilities in open source software. The alliance, named Akrites, will establish a shared security incident response team and a coordinated vulnerability disclosure process. This initiative is primarily driven by the emergence of frontier AI models, which have greatly accelerated the speed of vulnerability discovery, while the existing open source ecosystem struggles to respond quickly.

Software and AI companies form alliance to combat open source software security vulnerabilities
The rise of cutting-edge AI models has significantly enhanced the speed and capability of malicious hackers.
A coalition of technology companies, including Anthropic, AWS, IBM, and Microsoft, announced a joint effort to discover, disclose, and fix security vulnerabilities in open source software.
The coalition, named Akrites, will establish shared security incident response teams and develop coordinated vulnerability disclosure processes.
The founding members, led by theLinux Foundation, will invest significant resources, including funding, engineers, and cybersecurity expertise.
Officials say the initiative stems largely from theemergence of cutting-edge AI models, which have greatly accelerated the ability to identify vulnerabilities in critical software applications. Meanwhile, malicious actors have demonstrated the ability to weaponize AI for sophisticated attacks.
The existing open source ecosystem cannot discover and fix vulnerabilities quickly enough to protect millions of users from potential attacks. The coalition outlined these concerns in an open letter to the industry.
"Artificial intelligence has broken the original balance between attackers and defenders, changing the landscape of software usability and reuse,"the coalition wrote in the letter。
Disclosure backlog issues
According to Christopher Robinson, Chief Technology Officer of the Open Source Security Foundation and Chief Security Architect at the Linux Foundation, Akrites aims to address some systemic challenges the open source community faces in establishing coordinated vulnerability disclosure processes.
In recent years, the emergence of large language models and sophisticated scanning tools has made these historical challenges more severe.
"Upstream projects are being overwhelmed by a flood of vulnerability reports of varying quality, far exceeding the capacity of these volunteer developers to assess and handle," Robinson told Cybersecurity Dive.
Akrites' seed funding will be provided by Alpha Omega, a directed fund under the Linux Foundation. Other organizations are also invited to contribute additional resources or engineering talent.
In recent years, the open source community has faced growing concerns that traditional maintainers cannot quickly discover and disclose vulnerabilities to prevent widespread supply chain attacks.
Varun Badhwar, co-founder and CEO of Endor Labs, said that within just one month after the announcement of Project Glasswing, more than23,000 vulnerabilitieswere discovered, affecting about 1,000 open source projects, with approximately 6,000 identified as high-risk or critical.
Additionally, Glasswing's partners found another10,000 high-risk or critical flaws. Currently, only 5% of the vulnerabilities have been fixed.
"No volunteer ecosystem can withstand this impact," Badhwar told Cybersecurity Dive.
Other founding companies of Akrites include Cisco, Citi, JPMorgan Chase, NVIDIA, OpenAI, Ericsson, and others.