- 23,000 potential vulnerabilities identified by AI in one month across 1,000+ open source projects
- Only <5% of critical flaws patched, creating a security gap
- $7M annual budget from Alpha-Omega fund to support Akrites' operations
Experts would likely conclude that Akrites represents a necessary and strategic industry response to the accelerating AI-driven cybersecurity threat, offering a coordinated defense framework to protect critical open source infrastructure.
Industry Titans Launch Akrites to Defend Open Source from AI Onslaught
SAN FRANCISCO, CA – June 25, 2026 – In a landmark move to counter a new generation of AI-enabled cyber threats, The Linux Foundation today announced the launch of Akrites, a sweeping industry-wide initiative to secure the open source software that underpins the global economy. Backed by an unprecedented coalition including Amazon Web Services, Google, Microsoft, IBM, NVIDIA, and OpenAI, alongside financial powerhouses like JPMorganChase and Citi, the effort establishes a unified front to find, fix, and responsibly disclose vulnerabilities before they can be weaponized.
Akrites represents a strategic shift from a fragmented, reactive security posture to a coordinated, proactive defense. By creating a shared Security Incident Response Team (SIRT) and a single, standardized disclosure process, the initiative aims to protect the critical digital infrastructure—from banking and healthcare to power grids and telecommunications—that relies on a shared foundation of open source code.
An Arms Race at Machine Speed
The urgency behind Akrites is a direct response to a dramatic acceleration in the cybersecurity arms race. Where expert hackers once spent weeks hunting for flaws, new frontier AI models can now scan vast codebases and pinpoint exploitable vulnerabilities in minutes. "Finding a serious open source vulnerability used to take an expert weeks. It now takes a machine minutes," said Vijoy Pandey, SVP and GM at Outshift by Cisco. "When maintainers lose that race, so does everyone else."
This isn't a theoretical threat. Recent findings from Anthropic's Project Glasswing, an effort involving many of the same founding members, revealed the staggering scale of the problem. In its first month, an AI model identified over 23,000 potential vulnerabilities across more than 1,000 open source projects. More than 6,000 of these were deemed high or critical severity, yet an alarming fewer than 5% have been patched. This chasm between discovery and remediation has created a fertile ground for attackers.
The speed of exploitation has now outpaced the speed of disclosure. The mean time to exploit a known vulnerability is now estimated to be negative seven days, meaning malicious actors are often finding and using flaws before a patch is even publicly available. "AI has changed the speed of both offense and defense," noted Deepen Desai, Chief Security Officer at Zscaler. "Vulnerabilities can now be found at machine speed, which means defenders have to move just as fast."
From Patchwork to Unified Command
Historically, the response to a major open source vulnerability has been chaotic. Multiple organizations would independently discover the same flaw, burying already-overwhelmed project maintainers under a flood of duplicate reports and sometimes shipping conflicting patches that could fragment the ecosystem. Akrites is designed to dismantle this inefficient model.
The initiative provides a single, trusted, and confidential channel for coordinating vulnerability remediation. The shared SIRT will serve as a central hub, validating reports, eliminating duplicates, and working directly with upstream project maintainers to develop and test fixes. "Maintainers deserve a coordinated partnership, not a flood of reports," stated Matt Wilson, Vice President and Distinguished Engineer at Amazon Web Services.
This coordinated process is built upon a bedrock of industry-standard tooling, including CVE for identification, CVSS for scoring, and VEX for communicating exploitability, ensuring a common language and methodology across the industry. Confidentiality is paramount; bug fixes are handled discreetly and flow back to the original project on the maintainer's own terms, preserving the integrity of the open source commons. As Pat Opet, Chief Information Security Officer at JPMorganChase, explained, the goal is to provide maintainers with a "single, reliable signal: confirmed vulnerabilities, well-tested proposed fixes, and a predictable partner they can trust."
A Lifeline for the Guardians of the Code
At the heart of the open source ecosystem are the maintainers—often volunteers or small, under-resourced teams—who build and sustain the software we all depend on. Akrites is not just a technical solution but a structural one, designed to support this critical human infrastructure.
"The software supply chain is only as strong as the upstream it draws from, and we see how thin that layer really is," said Dan Lorenc, CEO and Co-founder of Chainguard. By centralizing the response, Akrites shields maintainers from the chaos of uncoordinated disclosures and provides them with the resources to act effectively. For years, the industry has grappled with the problem of abandoned but still critical open source projects. Akrites addresses this head-on by committing to serve as a "maintainer of last resort," ensuring that fixes for vital, unmaintained packages reach everyone in a timely fashion.
The Rust Foundation, a founding member, lauded this new approach. "For too long, the goodwill and sense of responsibility among upstream maintainers has been taken for granted in security response processes," said Rebecca Rumbul, the foundation's Executive Director and CEO. "Akrites promises meaningful coordination with upstream maintainers, financial, and full-time support to find, fix and disclose security vulnerabilities responsibly."
Fortifying the World's Digital Foundation
The implications of Akrites extend far beyond the developer community. The open source software it aims to protect is the digital backbone of modern society. "Open source powers the systems we rely on every day—running everything from banks and hospitals to power grids and AI platforms," remarked Jamie Thomas, Enterprise Security Executive at IBM.
The initiative's long-term viability is supported by a robust funding model. Seed funding is provided by Alpha-Omega, a Linux Foundation fund backed by major tech companies with an annual budget exceeding $7 million. A tiered membership structure invites further participation, with dues supporting the neutral operation of the SIRT and its secure infrastructure. This signifies a durable commitment from an industry that recognizes the shared risk.
The participation of firms like Citi, JPMorganChase, Vodafone, and Ericsson underscores that this is a matter of critical infrastructure resilience. "In partnership with the Linux Foundation and Project Akrites, Citi is committed to supporting the open-source ecosystem," said Al Tarasiuk, the bank's Chief Information Security Officer. By uniting defenders, Akrites aims to turn the speed of AI from a liability into an advantage, fortifying the foundational code that supports the global digital economy for the challenges ahead.
