The Linux Foundation and a coalition of major technology and financial firms have launched Akrites, a new initiative designed to protect critical open-source software as AI accelerates vulnerability discovery and exploitation risks. Backers include Amazon Web Services, Anthropic, Cisco, Citi, Ericsson, Google, IBM, JPMorganChase, Microsoft, GitHub, Nvidia, OpenAI, Red Hat, and the Rust Foundation, reflecting broad industry concern over the security of widely used open-source components.
Akrites is intended to streamline coordinated vulnerability disclosure and remediation by providing a shared security incident response capability for critical projects. The effort aims to reduce fragmented reporting, duplicate submissions, conflicting fixes, and pressure on already overburdened maintainers, while improving how serious flaws are disclosed and patched across the open-source ecosystem. Early reaction has framed the program as a significant step toward collective defense, though its effectiveness is expected to depend on scaling response capacity, avoiding centralized bottlenecks, and earning the trust of project maintainers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
The Linux Foundation announced the launch of Akrites, a new initiative to help defend critical open-source software against AI-enabled cyber threats. The effort is backed by multiple industry members and is intended to coordinate vulnerability remediation and disclosure for open-source projects.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
reversinglabs.com
Open sourcelinuxfoundation.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.