The Linux Foundation announced a $12.5 million initiative to strengthen open-source security and help maintainers manage a surge of low-quality, AI-generated vulnerability reports that are overwhelming triage and review processes. Funding comes from Anthropic, AWS, GitHub, Google, Google DeepMind, Microsoft, and OpenAI, and the program will be run through Alpha-Omega and the Open Source Security Foundation (OpenSSF) to improve remediation workflows, expand practical security support, and build longer-term resilience for widely used open-source software.
Project leaders and maintainers said the volume of automated submissions has outpaced the capacity of many open-source teams, turning vulnerability handling into an operational burden. The effort follows complaints from groups including the Python Software Foundation and the cURL project, whose maintainer ended its bug bounty program after being flooded with poor-quality AI-generated reports; GitHub is also providing $5.5 million in Azure credits and support services, while Google said it plans to contribute security tools including Big Sleep, CodeMender, and research such as Sec-Gemini.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A new industry coalition called Athena was formed to improve how vulnerabilities in open source software are identified, triaged, and fixed. Led by Chainguard and involving roughly two dozen companies, the effort said it had already processed more than 20,000 findings and produced over 2,000 patches across 500 open source projects.
The Linux Foundation launched Akrites, an industry initiative to improve validation, remediation, and disclosure of critical open source vulnerabilities before patches reach downstream users. The program includes a shared Security Incident Response Team to validate reports, remove duplicates, and help maintainers coordinate fixes confidentially amid rising AI-driven report volume.
The Linux Foundation announced a new initiative backed by $12.5 million in grants from major technology companies to strengthen open source security and support maintainers. The effort is to be run through Alpha-Omega and the Open Source Security Foundation, with a focus on sustainable security improvements and helping projects handle rising volumes of AI-generated vulnerability reports.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcelinuxsecurity.com
Open sourceitpro.com
Open sourcemedium.com
Open sourcehelpnetsecurity.com
Open sourcego.theregister.com
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.