The Linux Foundation has launched a new open source security initiative called Akrites, aimed at addressing vulnerabilities in the open source software ecosystem through a coordinated Security Incident Response Team (SIRT). This effort comes in response to the rising threat posed by AI in cyberattacks, which has significantly reduced the time available for responses between vulnerability disclosure and exploitation. Akrites, backed by prominent organizations such as AWS, Google, and Microsoft, will focus on confidentially managing and deploying fixes for security defects, especially for critical infrastructure, to prevent attacks before patches are publicly available.
AWS: AWS is a major cloud computing platform. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
IBM: IBM provides enterprise software, cloud, and consulting services. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
Citi: Citi is a global financial services company. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
Cisco: Cisco provides networking and cybersecurity solutions. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
GitHub: GitHub operates a leading platform for software development and collaboration. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
Google: Google develops cloud, search, and AI technologies. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
NVIDIA: NVIDIA designs GPUs and AI computing hardware and software. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
OpenAI: OpenAI develops artificial intelligence models and tools. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
Akrites: Akrites is a new open source security project announced by the Linux Foundation to establish a shared SIRT for coordinated vulnerability discovery, patching, and disclosure in the OSS ecosystem. It prioritizes confidential reporting and rapid fix deployment to critical infrastructure before public release of patches. The initiative is backed by the Linux Foundation’s Alpha-Omega directed fund along with engineering support from multiple organizations.
Red Hat: Red Hat delivers enterprise open source software and cloud solutions. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
Zscaler: Zscaler delivers cloud-native security solutions. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
Ericsson: Ericsson develops telecommunications infrastructure and technology. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
Sonatype: Sonatype offers software supply chain management and security tools. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
Vodafone: Vodafone is a global telecommunications company. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
Anthropic: Anthropic is an artificial intelligence research company. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
Microsoft: Microsoft develops software, cloud platforms, and AI tools. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
RapidFort: RapidFort provides container security and hardening solutions. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
Chainguard: Chainguard develops tools for secure software supply chains. Less than two weeks before the Akrites announcement, it launched the Athena coalition of fintech and technology organizations to address OSS vulnerabilities before public disclosure and noted plans to collaborate with the Linux Foundation on a coordinated SIRT.
Endor Labs: Endor Labs offers software security and dependency analysis tools. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
JPMorganChase: JPMorganChase is a global financial services firm. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
Rust Foundation: The Rust Foundation supports the Rust programming language and its ecosystem. It is listed among the supporting organizations for the Linux Foundation’s Akrites project focused on open source security.
Linux Foundation: The Linux Foundation is a nonprofit organization dedicated to supporting open source software development and ecosystem growth. It recently launched the Akrites project to create a coordinated Security Incident Response Team for handling OSS vulnerabilities with a focus on pre-disclosure patching. The Foundation positions Akrites as a maintainer of last resort for unmaintained packages while emphasizing confidentiality to avoid weaponization of flaws.
`json
{
“Infrastructure Focus”: “Akrites aims to work with critical infrastructure operators to ensure fixes are deployed before any exploitation attempts occur in the wild.”,
“Security Coordination”: “Major technology and financial organizations are collaborating through the Linux Foundation to manage OSS vulnerabilities confidentially prior to public disclosure.”,
“AI-Accelerated Threats”: “The increased use of AI in cyberattacks is reducing the time between vulnerability disclosure and potential exploitation, necessitating pre-publication patching processes.”
}
`
