Technology and AI companies form alliance to jointly address open source software security vulnerabilities
Several technology companies, including Anthropic, AWS, IBM, and Microsoft, have announced the formation of the Akrites Alliance to discover, disclose, and fix security vulnerabilities in open source software. Led by the Linux Foundation, the alliance will establish shared security incident response teams and coordinated vulnerability disclosure mechanisms to address the dramatically increased speed of vulnerability discovery and the risk of malicious exploitation brought by cutting-edge AI models.

Several technology companies, including Anthropic, AWS, IBM, and Microsoft, have announced the formation of a coalition aimed at jointly discovering, disclosing, and fixing security vulnerabilities in open-source software. The coalition, named Akrites, will establish a shared security incident response team and develop coordinated vulnerability disclosure processes.
Led by the Linux Foundation, the founding members will invest significant resources, including funding, engineers, and cybersecurity experts. Officials stated that this initiative is primarily driven by the emergence of cutting-edge AI models, which have greatly accelerated the ability to identify vulnerabilities in critical software applications. In recent months, malicious actors have demonstrated the ability to weaponize AI for sophisticated attacks.
The existing open-source ecosystem lacks sufficiently fast vulnerability discovery and remediation capabilities to protect millions of users from potential attacks. The group outlined these concerns in an open letter to the industry.
"Artificial intelligence has already broken the original balance between attackers and defenders, changing the equation of software usability and reusability," the coalition wrote in the letter.
Disclosure Backlog
According to Christopher Robinson, CTO of the Open Source Security Foundation and Chief Security Architect at the Linux Foundation, Akrites aims to address some of the systemic challenges the open-source community faces in developing coordinated vulnerability disclosure processes. In recent years, the emergence of large language models and sophisticated scanning tools has made these historical challenges more severe.
"Upstream projects are being flooded with a large volume of vulnerability reports of varying quality, far exceeding the capacity of these volunteer developers to assess and handle them," Robinson told Cybersecurity Dive.
Seed funding for Akrites will be provided by Alpha Omega, a directed fund under the Linux Foundation. Other organizations are also being asked to provide additional resources or engineering talent.
In recent years, the open-source community has faced growing concerns that traditional maintainers cannot quickly discover and disclose vulnerabilities to prevent widespread supply chain attacks.
Varun Badhwar, co-founder and CEO of Endor Labs, noted that within just one month after the announcement of Project Glasswing, more than 23,000 vulnerabilities were discovered, affecting approximately 1,000 open-source projects, with about 6,000 identified as high or critical severity. Additionally, Glasswing's partners discovered another 10,000 high or critical vulnerabilities, but only 5% of them were fixed.
"No volunteer ecosystem can withstand this scale," Badhwar told Cybersecurity Dive.
Other founding companies of Akrites include Cisco, Citi, JPMorgan Chase, NVIDIA, OpenAI, Ericsson, and others.