K

KeyAudit

· ·audit-finding·infrastructure·social-engineering

Linux Foundation Launches Akrites to Coordinate Open-Source Security Patches Amid AI Threats

The Linux Foundation launched Akrites on Thursday with 19 founding members, including Amazon, Google, Microsoft, and OpenAI, to coordinate the remediation of critical open-source vulnerabilities before AI-powered attackers can exploit them. The initiative addresses a timeline problem exacerbated by AI: frontier models can now scan major projects and return multiple confirmed vulnerabilities in minutes, a task that previously took weeks. According to Endor Labs CEO Varun Badhwar, fewer than 5% of thousands of validated open-source vulnerabilities surfaced by AI have been patched. Akrites replaces the current fragmented disclosure process with a single, confidential Security Incident Response Team, providing maintainers with a predictable partner. When critical packages lack active maintainers, Akrites commits to acting as maintainer of last resort. The program aims to ensure faster patch deployment, not just publication, as noted by JPMorganChase CISO Pat Opet. Funded by the Alpha-Omega directed fund, Akrites seeks to close the coordination gap and prevent leaks from becoming weapons. OpenAI's parallel effort, Patch the Planet, focuses on AI-assisted discovery with human review, while Akrites builds the industry-wide coordination layer.

Key facts

  • Akrites launched with 19 founding members including Amazon, Google, Microsoft, and OpenAI.
  • Less than 5% of AI-identified open-source vulnerabilities have been patched.
  • Akrites provides a single confidential response team for maintainers.
  • It commits to act as maintainer of last resort for abandoned critical packages.
  • Alpha-Omega fund provides seed funding; others can join with resources.

← Back to list