Vulnerabilities

Akrites Open Source Security Project

June 28, 2026 08:02 · 10 min read
Akrites Open Source Security Project

Akrites: A New Industry Effort for Open Source Security

The Linux Foundation has announced a new industry effort, Akrites, aimed at efficiently addressing vulnerabilities in the open source software (OSS) ecosystem. This project establishes a shared Security Incident Response Team (SIRT) for coordinated discovery, patching, and public disclosure of OSS security defects.

Akrites is supported by a range of organizations, including Anthropic, AWS, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler. Seed funding for the project comes from the Linux Foundation's directed fund Alpha-Omega, with other organizations providing engineering resources and additional funding.

Goals and Objectives

The primary goal of Akrites is to provide a confidential, trusted partner for vulnerability disclosure, eliminating hundreds of uncoordinated independent reports. The project will also work with critical infrastructure to help deploy fixes before in-the-wild exploitation. By doing so, Akrites aims to prevent vulnerability weaponization before patches are delivered and act as the maintainer of last resort, ensuring that fixes can still be delivered for packages that are no longer maintained.

According to the Linux Foundation, the success of Akrites will be measured in patch deployment, not publication. This is because when patches are released to the public, adversaries are able to utilize AI to rapidly reverse engineer the underlying vulnerabilities, develop exploits, and launch attacks.

Relationship to Other Initiatives

Akrites is not the only initiative aimed at addressing OSS bugs. Less than two weeks ago, Chainguard announced Athena, a coalition of over two dozen fintech and technology organizations aimed at addressing OSS bugs before public disclosure. While the Linux Foundation's announcement makes no mention of Athena, Akrites walks the same path, offering the tools and channels to report, validate, and address OSS vulnerabilities before their coordinated public disclosure.

Many of the organizations supporting Akrites were also mentioned as members of Athena, highlighting the collaborative effort to improve open source security. The Linux Foundation's directed fund Alpha-Omega provides seed funding for Akrites, and other organizations are providing engineering resources and additional funding to support the project.

Importance of Open Source Security

The importance of open source security cannot be overstated. As the use of AI in cyberattacks increases, the window between public disclosure and patching is closing rapidly. This makes it essential to have a coordinated effort to address vulnerabilities in the OSS ecosystem. Akrites is a step in the right direction, providing a shared SIRT and a confidential, trusted partner for vulnerability disclosure.

In addition to Akrites, other initiatives are also underway to improve open source security. For example, IBM and Red Hat have committed $5 billion to secure open source supply chains under Project Lightwell. Tech giants have also invested $12.5 million in open source security, and RSAC has released Quantickle, an open source threat intelligence visualization tool.

Conclusion

Akrites is a significant step forward in improving open source security. By establishing a shared SIRT and providing a confidential, trusted partner for vulnerability disclosure, Akrites aims to prevent vulnerability weaponization and ensure that fixes can still be delivered for packages that are no longer maintained. As the use of AI in cyberattacks continues to increase, initiatives like Akrites are essential to improving the security of the OSS ecosystem.


Source: SecurityWeek

Source: SecurityWeek

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free