Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial
Open-source software underpins some of the world’s most critical infrastructure. Banking, telecommunications, and utilities all run on software that shares the same OSS libraries. Finding vulnerabilities in that software is pressingly important, but it can take experts weeks to do so. Now, artificial intelligence can find them in minutes.
As good as that might sound, the speed of discovery does bring problems. With that in mind, the Linux Foundation and industry heavyweights including Amazon Web Services, Anthropic, Cisco, Citi, Ericsson, Google, IBM, JP MorganChase, Microsoft, GitHub, Nvidia, OpenAI, Red Hat, and the Rust Foundation are launching Akrites, which provides a trusted place to coordinate, remediate, and disclose security issues in OSS projects.
Akrites includes a single, standardized Coordinated Vulnerability Disclosure (CVD) process operated by a shared Security Incident Response Team (SIRT), built on confidentiality-first principles and the industry’s established standards and tooling, such as CVE, TLP, CWE, CVSS, EPSS, SSVC, and VEX, said Matt Wilson, vice president and distinguished engineer at Amazon Web Services, in a statement.
“Frontier AI models have given defenders the ability to find and fix vulnerabilities in open source software at a speed and scale that were never possible before. That’s an enormous opportunity for defenders, and Akrites ensures we seize it together. Maintainers deserve a coordinated partnership, not a flood of reports.”
—Matt Wilson
Here’s what you need to know about Akrites — and what it means for the state of OSS security. Plus: Learn why your application security (AppSec) strategy needs to go beyond vulnerabilities alone.
[ Why RL created Spectra Assure Community | Join for free and secure your OSS ]
The software supply chain is only as strong as the upstream it draws from, and we are seeing how thin that layer is, said Dan Lorenc, founder and CEO of Chainguard.
“As AI finds more vulnerabilities, the industry will rush to patch them. Without coordination, those fixes will fragment across different patches and forks.”
—Dan Lorenc
Complicating matters, he added, is that most OSS maintainers are already overwhelmed (see related webinar), and some can’t be contacted or haven’t even touched their project in years. Akrites leaves maintainers in control while providing a coordinated way to fix upstream vulnerabilities before they can be exploited. “Now the work is making sure there’s always someone on the other end to catch them,” Lorenc said.
John Bambenek, president of Bambenek Consulting, sees Akrites as a solid effort, contrasting it to previous initiatives that were project-based or one-time efforts to shore things up. Improvements were made, but the underlying problem remained. “This is an effort to create a long-term, sustainable organization to tackle the problem, showing that everyone involved understands throwing cash at projects and patting themselves on the back is no longer sufficient,” he said. In particular, he thinks the emphasis on maintainers is a wise approach.
“Open source is predominantly a volunteer effort, which means people are using their free time. If we are going to tackle security vulnerabilities here, we have to make it as easy as possible for those volunteers by taking the administrative overhead off of them.”
—John Bambenek
Ensar Seker, CISO of SOCRadar, said that Akrites is an important step toward addressing one of OSS security’s biggest structural weaknesses: fragmented vulnerability coordination. “Critical open-source projects underpin global digital infrastructure, yet many are maintained by small teams with limited security resources. A centralized, trusted coordination framework can improve the speed, consistency, and quality of vulnerability remediation before attackers have an opportunity to weaponize newly discovered flaws,” he said.
“A single coordination point reduces duplication, improves communication between researchers, maintainers, vendors, and downstream users and helps standardize responsible disclosure practices. It also creates greater trust throughout the ecosystem by ensuring vulnerabilities are validated, prioritized based on real-world risk, and disclosed in a coordinated manner. Ultimately, this shortens remediation timelines and reduces unnecessary exposure.”
—Ensar Seker
Akrites’ 19 founding members were scanning the same open-source libraries independently, filing duplicate reports and sometimes shipping conflicting patches, noted Jacob Krell, senior director for secure AI solutions and cybersecurity at Suzu Labs. “Maintainers got buried while each additional company holding an undisclosed flaw raised the leak risk,” he said.
“A single security incident-response team that deduplicates findings, validates one fix, and manages one disclosure timeline is overdue.”
—Jacob Krell
Akrites is similar to the EU’s European Vulnerability Database (EUVD), which provides a centralized European framework for vulnerability information and coordinated disclosure. “Similarly, Akrites creates a common operational model for handling vulnerabilities upstream in open-source projects,” said Boris Cipot, a security engineer at Black Duck Software. “The key difference is that EUVD focuses on vulnerability visibility and coordination across Europe, while Akrites focuses on actively coordinating remediation and disclosure before vulnerabilities become public,” he said.
Cipot said that the biggest challenge for Akrites will be scaling coordination as AI dramatically increases the number of vulnerabilities being discovered. “Akrites must efficiently validate findings, prioritize the most critical issues, and maintain trust across many stakeholders,” he said.
Another challenge is avoiding the creation of a new bottleneck, he said.
“Centralization only works if response capacity grows alongside reporting volume. Similar concerns exist for large vulnerability coordination initiatives, including European efforts, such as EUVD, where the value depends on timely processing, information quality, and broad ecosystem participation.”
—Boris Cipot
And then there is the threat of user dependency with no guarantee of continuity, as we have seen with the National Vulnerability Database (NVD), he added.
Jason Soroko, a senior fellow at Sectigo, a global digital certificate provider, agreed that Akrites must avoid becoming a bottleneck or shifting control away from project communities. “AI did not create the open-source security problem,” he said, “but it has made it more urgent.”
“AI can discover vulnerabilities and generate reports faster, including duplicates and low-quality findings, while human teams still need time to validate, patch, and deploy fixes. Akrites is an effort to close that growing gap between machine-speed discovery and human-speed remediation.”
—Jason Soroko
Trust could be a challenge for Akrites. “Open source has always run on distributed trust, and that works until it doesn’t,” said Seemant Sehgal, CEO and founder of BreachLock. The developers who maintain the most depended-on packages are often individuals who built something useful and watched the world adopt it, he said.
“They answer to no one, which is exactly why any framework that looks like oversight makes them walk away. Akrites has to earn that relationship, not assume it.”
—Seemant Sehgal
Damon Small, a board member of Xcape, argued that vulnerability disclosure efforts such as Akrites all have the same challenge: finding bugs before the bad guys do. “The focus on ‘critical’ software hopes to fix problems before they become the next big adversarial campaign,” he said.
Small said AppSec teams still need to keep an eye on supply chain issues.
“Sure, we now have a coordinated effort to patch open-source projects more quickly and efficiently, with the appropriate disclosure rules, but what happens when a potentially noncritical library is poisoned upstream?”
—Damon Small
Suzu Labs’ Krell is also wary of how Akrites will define “critical.” “Every one of those 19 founding members depends on a different slice of the open-source ecosystem. A library invisible to a bank might be foundational to an AI lab’s inference pipeline,” he said.
“The selection methodology for which projects get attention determines whether Akrites protects the commons broadly or just the dependencies its founding members care about most. Alpha-Omega’s seed funding gets this started, but sustained remediation across thousands of packages requires sustained investment well past launch day.”
—Jacob Krell
SOCRadar’s Seker argued that Akrites has the potential to become an important piece of the open-source security ecosystem if it focuses not only on disclosure, but also on risk-based prioritization. “Organizations are already overwhelmed by vulnerability volume. Success should not be measured by the number of CVEs processed, but by how effectively the initiative helps maintainers and defenders identify and remediate the vulnerabilities that attackers are most likely to exploit,” he said.
“If Akrites can combine coordinated disclosure with threat intelligence and exploitation context, it will provide significantly greater value to the community.”
—Ensar Seker
Recent reports make it clear organizations must look beyond vulnerability mitigation alone, Jai Vijayan reported for RL Blog.
Gareth Lindahl-Wise, CISO at Ontinue, said that making vulnerability remediation your sole defense in such an environment is dangerous and misguided.
"Patching everything is a race to the bottom as far as security resources go. Too much, too fast, too hard."
—Gareth Lindahl-Wise
In addition to reports — and the rise of artificial intelligence-derived coding and software supply chain attacks — demonstrate that the time has come for organizations to look beyond just vulnerability mitigation when it comes to shoring up their AppSec.
Jasmine Noel, a senior product marketing manager at ReversingLabs, said that while the exact impact of AI-powered tooling remains to be seen, one thing is for sure:
"Continuing with the same approach to vulnerability management isn’t going to produce different results."
—Jasmine Noel