Akrites Project
Over the past year, we've seen how much the industry depends on small open source projects. In many cases, software used by thousands of companies is maintained by one or two people working on it in their free time.
The release of the Mythos and Fable models made the situation even worse. They demonstrated how many vulnerabilities AI can find across thousand of projects, putting the whole enterprise IT infrastructure at risk.
Last Thursday (June 25), the Linux Foundation and a set of big IT companies announced a new initiative called Akrites, "a coordinated effort to remediate and disclose vulnerabilities in critical open source software."
The goal is simple: bring engineering resources together to identify, fix (!!!), and responsibly disclose vulnerabilities in critical open source software before they can be exploited.
If a package has no active maintainer, Akrites will serve as a "maintainer of last resort so fixes to the latest version reach everyone in a timely fashion".
And of course, they will do that with the help of AI frontier models.
The list of members is impressive: AWS, Anthropic, Cisco, Google, Microsoft, NVIDIA, IBM, OpenAI, Red Hat, and many others. It's one of the largest coordinated industry initiatives we've seen in recent years.
Personally, I think this is a very important shift. For years, the biggest challenge was finding enough people to make security fixes on time. AI has made the situation much more critical by flooding maintainers with newly discovered vulnerabilities.
The great thing about this initiative is that engineering resources are finally being focused not on reporting vulnerabilities, but on fixing them.
So the idea looks promising. Let's see how well it works in practice.
#news #opensource #security

Akrites
Coordinated, confidential vulnerability remediation for the open source software critical infrastructure depends on
2
2
1July 3, 2026 259