RL Blog

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Why RL Built Spectra Assure Community

Why RL Built Spectra Assure Community

We set out to help dev and AppSec teams secure the village: OSS dependencies, malware, more. Learn how our free tier works.

Read More about Why RL Built Spectra Assure Community
Why RL Built Spectra Assure Community

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsBlack Hat 2026
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
AppSec & Supply Chain SecurityJuly 22, 2026

Akrites marshals the open source community to counter AI threats

Industry heavyweights bring new focus to vulnerabilities in the age of AI. Here’s how it might help improve OSS security.

John P. Mello Jr.
John P. Mello Jr., Freelance technology writer.John P. Mello Jr.
FacebookFacebookXX / TwitterLinkedInLinkedInblueskyBlueskyEmail Us
Open Source Hardening

Open-source software underpins some of the world’s most critical infrastructure. Banking, telecommunications, and utilities all run on software that shares the same OSS libraries. Finding vulnerabilities in that software is pressingly important, but it can take experts weeks to do so. Now, artificial intelligence can find them in minutes.

As good as that might sound, the speed of discovery does bring problems. With that in mind, the Linux Foundation and industry heavyweights including Amazon Web Services, Anthropic, Cisco, Citi, Ericsson, Google, IBM, JP MorganChase, Microsoft, GitHub, Nvidia, OpenAI, Red Hat, and the Rust Foundation are launching Akrites, which provides a trusted place to coordinate, remediate, and disclose security issues in OSS projects.

Akrites includes a single, standardized Coordinated Vulnerability Disclosure (CVD) process operated by a shared Security Incident Response Team (SIRT), built on confidentiality-first principles and the industry’s established standards and tooling, such as CVE, TLP, CWE, CVSS, EPSS, SSVC, and VEX, said Matt Wilson, vice president and distinguished engineer at Amazon Web Services, in a statement. 

“Frontier AI models have given defenders the ability to find and fix vulnerabilities in open source software at a speed and scale that were never possible before. That’s an enormous opportunity for defenders, and Akrites ensures we seize it together. Maintainers deserve a coordinated partnership, not a flood of reports.”
—Matt Wilson

Here’s what you need to know about Akrites — and what it means for the state of OSS security. Plus: Learn why your application security (AppSec) strategy needs to go beyond vulnerabilities alone.

[ Why RL created Spectra Assure Community | Join for free and secure your OSS ]

Defragging vulnerability coordination

The software supply chain is only as strong as the upstream it draws from, and we are seeing how thin that layer is, said Dan Lorenc, founder and CEO of Chainguard. 

“As AI finds more vulnerabilities, the industry will rush to patch them. Without coordination, those fixes will fragment across different patches and forks.”
—Dan Lorenc

Complicating matters, he added, is that most OSS maintainers are already overwhelmed (see related webinar), and some can’t be contacted or haven’t even touched their project in years. Akrites leaves maintainers in control while providing a coordinated way to fix upstream vulnerabilities before they can be exploited. “Now the work is making sure there’s always someone on the other end to catch them,” Lorenc said. 

John Bambenek, president of Bambenek Consulting, sees Akrites as a solid effort, contrasting it to previous initiatives that were project-based or one-time efforts to shore things up. Improvements were made, but the underlying problem remained. “This is an effort to create a long-term, sustainable organization to tackle the problem, showing that everyone involved understands throwing cash at projects and patting themselves on the back is no longer sufficient,” he said. In particular, he thinks the emphasis on maintainers is a wise approach.

“Open source is predominantly a volunteer effort, which means people are using their free time. If we are going to tackle security vulnerabilities here, we have to make it as easy as possible for those volunteers by taking the administrative overhead off of them.”
—John Bambenek

Ensar Seker, CISO of SOCRadar, said that Akrites is an important step toward addressing one of OSS security’s biggest structural weaknesses: fragmented vulnerability coordination. “Critical open-source projects underpin global digital infrastructure, yet many are maintained by small teams with limited security resources. A centralized, trusted coordination framework can improve the speed, consistency, and quality of vulnerability remediation before attackers have an opportunity to weaponize newly discovered flaws,” he said.

“A single coordination point reduces duplication, improves communication between researchers, maintainers, vendors, and downstream users and helps standardize responsible disclosure practices. It also creates greater trust throughout the ecosystem by ensuring vulnerabilities are validated, prioritized based on real-world risk, and disclosed in a coordinated manner. Ultimately, this shortens remediation timelines and reduces unnecessary exposure.”
—Ensar Seker

Akrites’ 19 founding members were scanning the same open-source libraries independently, filing duplicate reports and sometimes shipping conflicting patches, noted Jacob Krell, senior director for secure AI solutions and cybersecurity at Suzu Labs. “Maintainers got buried while each additional company holding an undisclosed flaw raised the leak risk,” he said.

“A single security incident-response team that deduplicates findings, validates one fix, and manages one disclosure timeline is overdue.”
—Jacob Krell

One key focus: Avoiding bottlenecks

Akrites is similar to the EU’s European Vulnerability Database (EUVD), which provides a centralized European framework for vulnerability information and coordinated disclosure. “Similarly, Akrites creates a common operational model for handling vulnerabilities upstream in open-source projects,” said Boris Cipot, a security engineer at Black Duck Software. “The key difference is that EUVD focuses on vulnerability visibility and coordination across Europe, while Akrites focuses on actively coordinating remediation and disclosure before vulnerabilities become public,” he said.

Cipot said that the biggest challenge for Akrites will be scaling coordination as AI dramatically increases the number of vulnerabilities being discovered. “Akrites must efficiently validate findings, prioritize the most critical issues, and maintain trust across many stakeholders,” he said.

Another challenge is avoiding the creation of a new bottleneck, he said.

“Centralization only works if response capacity grows alongside reporting volume. Similar concerns exist for large vulnerability coordination initiatives, including European efforts, such as EUVD, where the value depends on timely processing, information quality, and broad ecosystem participation.”
—Boris Cipot

And then there is the threat of user dependency with no guarantee of continuity, as we have seen with the National Vulnerability Database (NVD), he added.

Jason Soroko, a senior fellow at Sectigo, a global digital certificate provider, agreed that Akrites must avoid becoming a bottleneck or shifting control away from project communities. “AI did not create the open-source security problem,” he said, “but it has made it more urgent.”

“AI can discover vulnerabilities and generate reports faster, including duplicates and low-quality findings, while human teams still need time to validate, patch, and deploy fixes. Akrites is an effort to close that growing gap between machine-speed discovery and human-speed remediation.”
—Jason Soroko

What’s critical — and what’s not?

Trust could be a challenge for Akrites. “Open source has always run on distributed trust, and that works until it doesn’t,” said Seemant Sehgal, CEO and founder of BreachLock. The developers who maintain the most depended-on packages are often individuals who built something useful and watched the world adopt it, he said.

“They answer to no one, which is exactly why any framework that looks like oversight makes them walk away. Akrites has to earn that relationship, not assume it.”
—Seemant Sehgal

Damon Small, a board member of Xcape, argued that vulnerability disclosure efforts such as Akrites all have the same challenge: finding bugs before the bad guys do. “The focus on ‘critical’ software hopes to fix problems before they become the next big adversarial campaign,” he said.

Small said AppSec teams still need to keep an eye on supply chain issues. 

“Sure, we now have a coordinated effort to patch open-source projects more quickly and efficiently, with the appropriate disclosure rules, but what happens when a potentially noncritical library is poisoned upstream?”
—Damon Small

Suzu Labs’ Krell is also wary of how Akrites will define “critical.” “Every one of those 19 founding members depends on a different slice of the open-source ecosystem. A library invisible to a bank might be foundational to an AI lab’s inference pipeline,” he said.

“The selection methodology for which projects get attention determines whether Akrites protects the commons broadly or just the dependencies its founding members care about most. Alpha-Omega’s seed funding gets this started, but sustained remediation across thousands of packages requires sustained investment well past launch day.”
—Jacob Krell

SOCRadar’s Seker argued that Akrites has the potential to become an important piece of the open-source security ecosystem if it focuses not only on disclosure, but also on risk-based prioritization. “Organizations are already overwhelmed by vulnerability volume. Success should not be measured by the number of CVEs processed, but by how effectively the initiative helps maintainers and defenders identify and remediate the vulnerabilities that attackers are most likely to exploit,” he said.

“If Akrites can combine coordinated disclosure with threat intelligence and exploitation context, it will provide significantly greater value to the community.”
—Ensar Seker

Going beyond vulnerabilities is essential

Recent reports make it clear organizations must look beyond vulnerability mitigation alone, Jai Vijayan reported for RL Blog.

Gareth Lindahl-Wise, CISO at Ontinue, said that making vulnerability remediation your sole defense in such an environment is dangerous and misguided.

"Patching everything is a race to the bottom as far as security resources go. Too much, too fast, too hard."
—Gareth Lindahl-Wise

In addition to reports — and the rise of artificial intelligence-derived coding and software supply chain attacks — demonstrate that the time has come for organizations to look beyond just vulnerability mitigation when it comes to shoring up their AppSec.

Jasmine Noel, a senior product marketing manager at ReversingLabs, said that while the exact impact of AI-powered tooling remains to be seen, one thing is for sure:

"Continuing with the same approach to vulnerability management isn’t going to produce different results."
—Jasmine Noel

Keep learning

  • Take a deep dive into ClickFix with RL's new report, and join the webinar to learn more about the attack technique. Plus: Get RL's open-source YARA rule.
  • Learn how Gartner® named RL a supply chain security 'Visionary.' Download: Gartner® Magic Quadrant™ for Software Supply Chain Security.
  • Get up to speed on the Agentic Development Security tools landscape in this webinar with Forrester Sr. Analyst Janet Worthington.
  • Understand the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar discussing the findings.

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

Plus: Join the free Spectra Assure Community today to get hands-on with RL's binary analysis-based software supply chain security platform.

Tags:AppSec & Supply Chain Security

More Blog Posts

AI threat advisor robot

New OWASP tool structures AI threat modeling

Threat Advisor could help teams with AI-specific risks. But a broader AppSec strategy rethink is needed in the AI era.

Learn More about New OWASP tool structures AI threat modeling
New OWASP tool structures AI threat modeling
AI-BOM minimum requirements

AI-BOM push borrows from the SBOM playbook

The Institute for Security and Technology's 'Driving AI Transparency' policy paper makes the case for AI-BOM minimum requirements.

Learn More about AI-BOM push borrows from the SBOM playbook
AI-BOM push borrows from the SBOM playbook
5 takeaways

2026 Gartner® Magic Quadrant™ for Software Supply Chain Security: 5 takeaways

The Magic Quadrant™ for Software Supply Chain Security is a 45-minute read. Here's what we feel security leaders need to pull from it.

Learn More about 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security: 5 takeaways
2026 Gartner® Magic Quadrant™ for Software Supply Chain Security: 5 takeaways
OSS security

Should frontier AI firms fund OSS ecosystem security?

With a ‘vulnpocalypse’ expected, AppSec leaders are calling for the companies to invest in a Great Refactor Fund to secure open source.

Learn More about Should frontier AI firms fund OSS ecosystem security?
Should frontier AI firms fund OSS ecosystem security?

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top