Breaking
SecurityDeveloping Story

Linux Foundation's Akrites Set to Operationalize in September

The Linux Foundation's Akrites initiative plans to launch its vulnerability disclosure and remediation platform in September.

··1 hour ago·3 min read
silhouette photography of man
Photo by Chris Yang on Unsplash

The Linux Foundation-backed Akrites initiative, a coalition of tech giants and AI labs formed to defend critical open-source software from AI-generated threats, is poised to make its platform operational. According to the initiative's CTO, the system is slated to begin accepting automated vulnerability reports in September, following a series of security audits and tool enhancements.

Coalition of Industry Giants

Akrites was launched in late June 2026 by the Linux Foundation, the Open Source Security Foundation (OpenSSF), and more than 20 founding members. These include AI frontier labs like Anthropic and OpenAI, as well as cloud and tech heavyweights such as Amazon Web Services, Cisco, Google, Microsoft (with its subsidiary GitHub), IBM (with Red Hat), and NVIDIA. Cybersecurity firms like Chainguard, Endor Labs, and Zscaler also joined, along with major enterprises including Citi, JPMorganChase, Ericsson, and Vodafone.

Each member organization is required to contribute between one and ten engineers to the project and pay membership fees based on one of three tiers: Associate, General, or Premier.

Two Core Missions

At launch, the Linux Foundation outlined two primary objectives for Akrites: establishing a shared security incident response team (SIRT) to mitigate and remediate vulnerabilities in open-source packages and libraries, and developing a standardized coordinated vulnerability disclosure (CVD) process built on confidentiality-first principles and industry-standard tooling.

Christopher 'CRob' Robinson, OpenSSF's CTO and chief security architect, was appointed CTO of Akrites in June. He described the initiative's sole mission as "coordinating AI-enabled vulnerability reports to upstream open-source maintainers so that the fixes are available to the whole ecosystem."

First Draft of the Toolchain

Robinson confirmed that the team responsible for the initiative's tooling, including the vulnerability management and SIRT platform, has produced the first draft of the tool chain. The platform will leverage Carnegie Mellon University's Vulnerability Information and Coordination Environment (VINCE), a vulnerability management platform developed in 2020 by the CERT/CC unit of the university's Software Engineering Institute.

"We have a substantial amount of additional capabilities leveraging large language models (LLMs) to do deduplication, patch creation and more," Robinson said.

Thousands of Reports Already

The initiative has already attracted significant attention, with Robinson revealing that he has received thousands of vulnerability reports just two months after launching the project. He estimated that roughly 30% of these are duplicates.

Security Audits and Testing Ahead

Before the platform goes live, the team is conducting penetration tests and security audits. "Today, we're bringing in some additional experts from the Akrites members to go through and do a penetration test and a security audit and then we'll be augmenting the tools to allow the input of a combination of real and synthetic data through the system to make sure it functions as we design," Robinson explained.

Once complete, the platform will be open-sourced and available for anyone to use for their own purposes.

September Launch Target

Robinson said the platform is expected to "go live" and "start taking automated vulnerability reports" sometime in September.

Reflecting on the project, Robinson added: "I have been trying to do something like Akrites my whole career. I feel right now we have the tools, the willpower and access to the technical experts, so I'm very optimistic on our chances that we're going to be able to provide a very valuable service to the global open-source ecosystem."

Why It Matters

If Akrites achieves its goals, it could significantly bolster the security of open-source software by providing a coordinated response to the growing wave of AI-enabled vulnerability reports. The initiative's success may hinge on its ability to efficiently triage and remediate the influx of reports, potentially reducing the risk of unpatched vulnerabilities in critical projects. As more organizations rely on open-source components, a functioning disclosure and remediation pipeline could set a precedent for how the community addresses AI-driven security challenges.

#linux-foundation#akrites#open-source#ai#vulnerability-disclosure#security

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories