Linux Foundation & Others Launch "Akrites" To Defend Open-Source Software From AI-Enabled Exploits

Given the wild pace of new security-related bug discoveries being made these days by large language models, Akrites is an industry-wide effort to help ensure that critical open-source software is mitigated and secured in a timely manner. The initial backers of Akrites include Amazon Web Services, Anthropic, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone and Zscaler.
Akrites is establishing a:
"Akrites establishes a shared Security Incident Response Team (SIRT) and a single, standardized Coordinated Vulnerability Disclosure (CVD) process, built on confidentiality-first principles and industry-standard tooling.
...
Confidentiality is central to the effort. Bug fixes flow back into each project’s original home, on maintainers’ terms. Where a critical package has no active maintainer, Akrites will serve as maintainer of last resort so fixes to the latest version reach everyone in a timely fashion. The initiative will also coordinate with government efforts so public and private defenders move together."
More details can be found via today's launch press release.
General information on the Akrites project and other details via the new project site at Akrites.org.
6 Comments
