惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
S
SegmentFault 最新的问题
MyScale Blog
MyScale Blog
有赞技术团队
有赞技术团队
V
Visual Studio Blog
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿
Vercel News
Vercel News
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Y
Y Combinator Blog
Blog — PlanetScale
Blog — PlanetScale
D
DataBreaches.Net
美团技术团队
Microsoft Security Blog
Microsoft Security Blog
大猫的无限游戏
大猫的无限游戏
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
酷 壳 – CoolShell
酷 壳 – CoolShell
GbyAI
GbyAI
A
About on SuperTechFans
云风的 BLOG
云风的 BLOG
The Cloudflare Blog
宝玉的分享
宝玉的分享
V
V2EX
Microsoft Azure Blog
Microsoft Azure Blog

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY Frontier AI models reap rapid discovery of security vulnerabilities
Software, AI companies form alliance to tackle open-sourc...
David Jones · 2026-06-26 · via Cybersecurity Dive - Latest News

An article from site logo

The emergence of frontier AI models has increased the speed and capabilities of malicious hackers.

Published June 26, 2026

Pair of hands type on keyboard while coding

Getty Images

A coalition of technology companies, including Anthropic, AWS, IBM and Microsoft, announced a joint effort to find, disclose and remediate security flaws in open-source software. 

The group, called Akrites, will establish a shared security incident response team as well as a coordinated vulnerability disclosure process. 

The founding members, led by the Linux Foundation, will commit extensive resources to the effort, including funding, engineers and cybersecurity expertise. 

Officials said the plan was mainly driven by the emergence of frontier AI models that radically accelerated the ability to discover vulnerabilities in critical software applications. In recent months, malicious actors have demonstrated the ability to weaponize AI for use in sophisticated attacks. 

The existing open-source ecosystem does not have the ability to discover and remediate vulnerabilities fast enough to protect millions of users from potential attacks. The group outlined some of these concerns in an open letter to the industry. 

“Artificial intelligence has collapsed the previous equilibrium between attackers and defenders, changing the equation of ease and reuse of software,” the coalition wrote in the letter

Disclosure backlog

Akrites is designed to address some of the systemic challenges facing the open-source community in terms of developing a coordinated vulnerability disclosure process, according to Christopher Robinson, CTO of Open Source Security Foundation and chief security architect of the Linux Foundation. 

The emergence of large language models and sophisticated scanning tools in recent years has made all of those historic challenges even more serious.

“Upstream projects are being inundated with vulnerability reports of varying degrees of quality which far exceeds these volunteer developers’ ability to evaluate and keep up,” Robinson told Cybersecurity Dive.

Seed funding for Akrites will be provided by Alpha Omega, which is a directed fund under the Linux Foundation. Other organizations are being asked to provide additional resources or engineering talent. 

The open-source community has faced mounting concerns in recent years about the inability of traditional maintainers to quickly discover and disclose vulnerabilities in order to prevent widespread supply chain attacks. 

Varun Badhwar, co-founder and CEO of Endor Labs, said more than 23,000 vulnerabilities were discovered just one month after the announcement of Project Glasswing, impacting about 1,000 open-source projects. These include about 6,000 vulnerabilities that were considered high severity or critical. 

In addition, Glasswing’s partners found another 10,000 high-severity or critical flaws. Only 5% of these vulnerabilities have been fixed. 

“No volunteer ecosystem was built to absorb that,” Badhwar told Cybersecurity Dive. 

Other founding companies in Akrites include Cisco, Citi, JPMorgan Chase, NVIDIA, OpenAI, Ericsson and others.