A coalition of technology companies including Anthropic, AWS, IBM, and Microsoft has announced that it will jointly work on discovering, disclosing, and fixing security vulnerabilities in open-source software. The organization, named Akrites, will establish a shared security incident response team and a coordinated vulnerability disclosure process.

The founding members, led by the Linux Foundation, have committed substantial resources to this initiative, including funding, engineers, and cybersecurity expertise. Officials stated that the program is primarily driven by the rise of frontier AI models, which have significantly accelerated the speed of identifying vulnerabilities in critical software applications. In recent months, malicious actors have demonstrated the ability to weaponize AI for sophisticated attacks.

The current open-source ecosystem is not fast enough in discovering and fixing vulnerabilities to protect millions of users from potential attacks. The organization outlined these concerns in an open letter to the industry.

"Artificial intelligence has broken the original balance between attackers and defenders, changing the landscape of software usability and reusability," the coalition wrote in the letter.

Disclosure backlog issues

According to Christopher Robinson, CTO of the Open Source Security Foundation and Chief Security Architect at the Linux Foundation, Akrites aims to address the systemic challenges the open-source community faces in establishing a coordinated vulnerability disclosure process. In recent years, the emergence of large language models and advanced scanning tools has made these historical challenges more severe.

"Upstream projects are being flooded with a large number of vulnerability reports of varying quality, far exceeding the capacity of these volunteer developers to assess and handle them," Robinson told Cybersecurity Dive.

Akrites' seed funding will be provided by Alpha Omega, a directed fund under the Linux Foundation. Other organizations are being asked to provide additional resources or engineering talent.

The open-source community has faced growing concerns in recent years that traditional maintainers cannot quickly discover and disclose vulnerabilities to prevent widespread supply chain attacks.

Varun Badhwar, co-founder and CEO of Endor Labs, noted that within just one month after the announcement of Project Glasswing, more than 23,000 vulnerabilities were discovered, affecting approximately 1,000 open-source projects, of which about 6,000 were considered high or critical severity. Additionally, Glasswing's partners found another 10,000 high or critical severity flaws. Only 5% of these vulnerabilities were fixed.

"No volunteer ecosystem can withstand such pressure," Badhwar told Cybersecurity Dive.

Other founding companies of Akrites include Cisco, Citi, JPMorgan Chase, NVIDIA, OpenAI, Ericsson, and others.