News
Linux Foundation, Nineteen Companies Launch Akrites to Coordinate Open Source Vulnerability Fixes
- By John K. Waters
- July 27, 2026
Artificial intelligence is changing cybersecurity in an unexpected way: it is making it dramatically easier to find flaws in the open-source software that underpins much of the world's digital infrastructure. In response, the Linux Foundation and 19 technology companies have launched Akrites, a new effort to coordinate how those vulnerabilities are reported, fixed, and disclosed.
Akrites is a collaborative security initiative that gives participating organizations a single process for reporting, coordinating, and disclosing vulnerabilities in critical open-source projects. The effort combines a shared Security Incident Response Team, a standardized coordinated disclosure process, and a "maintainer of last resort" program to ensure critical packages continue receiving security fixes even when no active maintainer is available.
The initiative is backed by 19 founding organizations, including Amazon Web Services, Anthropic, Chainguard, Cisco, Citi, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, the Rust Foundation, Sonatype, Vodafone, Endor Labs, and Zscaler. Members are contributing engineering talent, security expertise, and funding, according to the Foundation.
"Frontier AI models have given defenders the ability to find and fix vulnerabilities in open source software at a speed and scale that were never possible before," said Matt Wilson, Vice President and Distinguished Engineer at Amazon Web Services, in a statement. "That's an enormous opportunity for defenders, and Akrites ensures we seize it together. Maintainers deserve a coordinated partnership, not a flood of reports. AWS is committed to securing the projects our customers depend on and building this shared infrastructure alongside the community."
Open-source software underpins much of the world's digital infrastructure, including banking, healthcare, energy, transportation, telecommunications, and government systems. Historically, finding and fixing serious flaws required roughly comparable expertise on both the attacking and defending sides. Frontier AI models can now scan major open-source projects and surface vulnerabilities in minutes; a shift it warned could allow attackers with far less technical expertise to identify sophisticated exploits once those tools become widely available.
Akrites is designed to replace what the Linux Foundation described as a fragmented response, in which multiple organizations often investigate the same vulnerabilities independently, sometimes producing conflicting patches or overwhelming maintainers with duplicate reports. Instead, findings are routed through a shared Security Incident Response Team and a standardized Coordinated Vulnerability Disclosure process built on what the foundation called confidentiality-first principles and existing industry standards, including CVE, TLP, CWE, CVSS, EPSS, SSVC, and VEX.
"For years we have believed finding vulnerabilities was never the hard part. Fixing them was. AI has made that gap impossible to ignore," said Varun Badhwar, CEO and Co-Founder of Endor Labs. "Of the thousands of validated open-source vulnerabilities surfaced in recent months, fewer than 5% have been patched. Endor Labs is a founding member of Akrites because it is built for the response this moment needs: coordinated remediation upstream, handled confidentially, with maintainers in control, so one trusted fix reaches everyone who depends on the code."
To mark the launch, the founding organizations also published a joint open letter, titled "We All Depend on Open Source. We Will Defend It Together," at akrites.org/letter.
About the Author
John K. Waters is the editor in chief of a number of Converge360.com sites, with a focus on high-end development, AI and future tech. He's been writing about cutting-edge technologies and culture of Silicon Valley for more than two decades, and he's written more than a dozen books. He also co-scripted the documentary film Silicon Valley: A 100 Year Renaissance, which aired on PBS. He can be reached at [email protected].