Linux Foundation, Tech Giants Launch Akrites to Protect Open Source Against AI-Powered Attacks



In short

  • The Linux Foundation launched Akrites on Thursday with 19 founding members to help fix open source vulnerabilities so that AI-powered attackers can exploit them.
  • Less than 5% of the thousands of vulnerabilities discovered by AI in recent months have been patched, according to Endor Labs CEO Varun Badhwar.
  • Akrites was designed to bridge this gap.

Linux Foundation he started Akrites Thursday together with 19 startups – Amazon, Anthropic, Citi, Google, JPMorganChase, Microsoft, NVIDIA, OpenAI, and others – to coordinate the implementation of complex open source applications that have not yet started to use AI-powered.

This project solves the time problem that AI has created quickly. Frontier Models can now analyze a large open source project and recover multiple confirmed vulnerabilities in minutes—a task that used to take weeks for professional security researchers. Like Decrypt he saidClaude Opus 4.8 exposed a major flaw in Zcash’s Orchard secret pool within a day, revealing a bug that survived four years of cryptographer review.

If white hat hackers find the error, all is well. If the wrongdoers act, things can go wrong, really fast. Anthropic CISO Deputy Jason Clinton said in the letter that the current disclosure model “has been successful in how AI can quickly find vulnerabilities”—and that reaching the surface requires integrating the findings “before they are disclosed and used.”

The existing connected display model Akrites was not built for that speed. Multiple organizations can look into the same libraries independently and go through long organizational processes before correcting errors – a process that an open letter signed by all 19 organizations that launched the so-called burial “noise management.”

The CEO of Endor Labs, Varun Badhwar, went even further: Of the thousands of open security breaches that AI has exposed in recent months, “less than 5% have been caught.”

Akrites replaces that approach with a single, private Security Incident Response Team—an obvious partner for caregivers rather than a flurry of unrelated reports. Maintenance goes back to the original database for each project based on management input, using risk tracking levels. If a required package does not have a maintainer, Akrites volunteers to step in as the final maintainer.

The program was first built to protect the release – an open letter called an unknown bug in a widely distributed package “tool.” The director of the Rust Foundation, Rebecca Rumbul, said that the goodwill of open source maintainers has been taken for granted for a long time and this will help them to work together.

“Akrites promises a reliable partnership with onshore operators, funding, and ongoing support to find, fix and disclose security vulnerabilities effectively, as well as a true commitment from the most influential companies in technology and finance to solve the problem,” he said.

JPMorganChase CISO Pat Opet explained what success requires from hard work. “AI has greatly compressed the time between discovery of a vulnerability and exploitation to real time,” Opet said – meaning that attackers can quickly modify a patch that has been published and create a way to exploit many underlying systems before they begin to fix it.

Success, according to Opet, is “sending patches, not spreading patches.”

OpenAI limits he started his own effort, Patch the Planet, three days before Akrites – the first speed using GPT-5.5-Cyber ​​and Trail of Bits developers through 19 open projects that included many patches. OpenAI Cyber​​​​Lead Clint Gibler called open source “a long-term commitment” for the company and said Akrites helps “enhance collaboration across the industry.”

Although similar, the two efforts are distinctly different: Patch the Planet focuses on AI-assisted discovery and provides patches and human reviews to experts; Akrites creates an integrated platform that validates the data found in the upstream of the company.

Alpha-Omega, a Linux Foundation-led fund, will provide seed funding to Akrites. The fund has awarded more than 70 grants totaling $20 million to defense projects through 2022. Other organizations can join by donating engineering or financial resources at akrites.org.

Daily Debrief A letter

Start each day with top stories right here, including originals, podcasts, videos and more.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *