
The Linux Foundation has launched Akrites, a coordinated initiative with about twenty major tech companies to patch security vulnerabilities in open-source software before AI tools can exploit them.
Because AI models can now find flaws in large projects in minutes instead of weeks, the industry faces a critical window to fix bugs faster than attackers can weaponize them.
The initiative consolidates scattered vulnerability reports into a single response team that coordinates fixes with maintainers and steps in to patch critical packages that lack active maintainers.
What happened
The Linux Foundation announced Akrites, a coordinated industry initiative bringing together about twenty tech companies—including Amazon Web Services, Anthropic, Google, IBM, Microsoft, NVIDIA, and OpenAI—to fix security vulnerabilities in widely used open-source software before attackers can exploit them. At its core is a shared Security Incident Response Team that acts as a single point of contact for maintainers instead of dozens of organizations independently reporting the same flaws.
Why it matters
AI models can now scan large open-source projects in minutes instead of weeks, exposing flaws far faster than before. This shifts the balance: attackers without deep technical skills will soon have the tools for sophisticated exploits. Currently, fewer than five percent of validated open-source vulnerabilities from recent months have been patched, and maintainers get buried under duplicate reports while real bugs get lost in noise. A shared response team aims to cut through this inefficiency.
What to watch
When a critical package no longer has an active maintainer—a common problem in volunteer-run projects—Akrites plans to step in as a "maintainer of last resort" and ship fixes itself so patches reach all users in time. Seed funding comes from Alpha-Omega, a directed fund under the Linux Foundation, and other organizations can contribute engineering resources or funding.
Ask the AI about this article →
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
ABI Research projects that AI inference data center power demand will grow from 2GW in 2026 to 46GW by 2035, w…

Nvidia has agreed to buy Hugging Face for $12.9 billion, as reported by The Information, citing a source famil…

Z.ai Co. released the code for GLM-5.3-Flash, an LLM with 320 billion parameters that activates 18 billion per…
Deep Cogito Inc. raised $43 million in a Series A round led by TQ Ventures, with participation from Benchmark…
Alibaba's Qwen team released Qwen3.8-Flash-Next, an open-weights multimodal MoE model that also serves as an e…

A Spiceworks article explores whether 'vibe-coded' applications—AI-generated software built through natural-la…
