The Linux Foundation, in association with 19 institutions such as OpenAI, Anthropic, Google, Microsoft, Weeda, Amazon and Morgan Chase, launched Akrites with the goal of completing the coordination of the rehabilitation of key open-source software before AI drives the attackers to exploit their loopholes.
AI Compressed Hole Utilization Window
The plan is aimed at a growing time gap. As the front-line model improves the efficiency of gap scanning, the work that has been required for several weeks for security researchers in the past is likely to have multiple proven gaps within minutes.
The article mentions that Claude Opus 4.8 of Anthropic discovered a serious flaw in Zcash Orchard ' s privacy pool within one day, an issue that had existed for four years in a password review.
Participants were of the view that the traditional gap coordination disclosure process had not kept pace with AI. In the past, different agencies have scanned the same open-source reservoirs, which have been facilitated by longer internal processes, which have also exposed defenders to a large number of sporadic reports.
Endor Labs CEO Varun Badhwar stated that in recent months AI had found thousands of proven open-source loopholes, but less than 5 per cent of repairs were completed.
Akrites Unified Convergence Maintainer
Akrites tried to bring the previously dispersed process together as a secure incident response team, serving as a unified interface to the open source maintainer, rather than allowing the maintainer to receive a large number of uncoordinated reports at the same time.
The repairs are designed to return to the project original code warehouse, to be processed by the maintainer at its own pace and in line with the existing gap tracking standards. If a key package has no active maintainer, Akrites will intervene as the last maintenance supporter.
- 19 Founding Members
- Including OpenAI, Anthropic, Google, Microsoft, Weaverda, Citi and Morgan Chase.
- Other agencies may join through engineering resources or funds
Differentiated from OpenAI project division
OpenAI also launched a stand-alone project called Patch the Planet three days before Akrites was launched, with the first round using GPT-5.5-Cyber and Trail of Bits engineers, combining dozens of patches in 19 open-source projects.
The two are in a similar direction, with a different division of labour. Patch the Planet is more inclined to use AI support to detect holes and deliver patches, which are then reviewed by security experts; Akrites is more like a coordination layer at the industry level, which is responsible for bringing proven problems upstream and facilitating rehabilitation.
According to Morgan Chase Chief Information Security Officer Pat Opet, the real challenge in the AI environment is not just to issue patches, but to get the downstream system deployed as soon as possible. Because the attackers may quickly reverse the analysis after the patch is made public and construct the tools available for the attack before a large number of systems are updated.
Additional information:The Alpha-Omega Foundation under the Linux Foundation will provide seed money for Akrites. The Fund has disbursed over 70 grants to open-source security projects since 2022, totalling over $20 million.
