Exclusive: Linux Foundation's Akrites to Go Live in September
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Vendors and products
- Linux
- Reported by
- 1 outlet
A major industry coalition set up to defend critical open-source software against AI-enabled cyber threats is expected to operationalize its vulnerability disclosure and remediation platform in September, Infosecurity has learned.
The initiative, called Akrites, was launched at the end of June 2026 by the Linux Foundation, the Open Source Security Foundation (OpenSSF) and over 20 founding members.
These include AI frontier labs Anthropic and OpenAI; cloud and tech giants like Amazon Web Services, Cisco, Google, Microsoft and its subsidiary GitHub, IBM and its subsidiary Red Hat and NVIDIA; cybersecurity firms like Chainguard, Endor Labs and Zscaler; and large enterprises, such as Citi, JPMorganChase, Ericsson and Vodafone.
Each member of the coalition must donate between one and 10 engineers to the project and pay membership fees based on which of the three membership tiers they chose – Associate, General and Premier –, each corresponding to a level of benefits.
At launch, the Linux Foundation announced two major missions for the initiative:
- Establish a shared security incident response team (SIRT) for mitigating and remediating vulnerabilities in open-source packages and libraries
- Develop a standardized coordinated vulnerability disclosure (CVD) process, built on confidentiality-first principles and industry-standard tooling
Infosecurity spoke to Christopher ‘CRob’ Robinson, OpenSSF’s CTO and chief security architect, who was appointed as CTO of Akrites in June.
He described Akrites’ sole mission as “coordinating AI-enabled vulnerability reports to upstream open-source maintainers so that the fixes are available to the whole ecosystem.”
Read more: Chainguard, JPMorgan, BNY Team Up to Secure Open Source from AI Threats
He said the team responsible for the initiative’s tooling, including the vulnerability management and SIRT platform, had now produced “the first draft of the tool chain.”
He revealed that the initiative’s main platform will be based on Carnegie Mellon University's Vulnerability Information and Coordination Environment (VINCE), a vulnerability management platform developed in 2020 by the Computer Emergency and Response Team Coordination Center (CERT/CC), a unit of the university’s Software Engineering Institute (SEI).
“We have a substantial amount of additional capabilities leveraging large language models (LLMs) to do deduplication, patch creation and more,” added the Akrites CTO, who confessed he’s already received thousands of vulnerability reports after two months of launching the project, an estimated 30% of these are duplicates.
“Today, we’re bringing in some additional experts from the Akrites members to go through and do a penetration test and a security audit and then we’ll be augmenting the tools to allow the input of a combination of real and synthetic data through the system to make sure it functions as we design,” Robinson explained.
When ready, the finished platform will be open-sourced and available for anyone to use for their own purposes.
Additionally, Robinson said the Akrites-run platform is expected to “go live” and “start taking automated vulnerability reports” some time in September.
“I have been trying to do something like Akrites my whole career,” he said. “I feel right now we have the tools, the willpower and access to the technical experts, so I’m very optimistic on our chances that we’re going to be able to provide a very valuable service to the global open-source ecosystem.”
Stay tuned to Infosecurity for further updates on Akrites and similar initiatives to tackle the explosion of AI-enabled vulnerability reports in open-source projects.
Image credits: Linux Foundation / IB Photography / Shutterstock.com
Reproduced in full under licence from Infosecurity Magazine. © Infosecurity Magazine.
Coverage
One outlet has carried this so far.
2026-08-19 15:30 UTC
Related stories
- Malware bypasses browser checks to force install Chrome, Edge extensions
BleepingComputer · 2026-09-16
- Google Pixel phones pwned in zero-click attacks
The Register · 2026-09-16
- Spain's data agency gets first report of AI-powered data breach
BleepingComputer · 2026-09-16
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16