惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
aimingoo的专栏
aimingoo的专栏
WordPress大学
WordPress大学
人人都是产品经理
人人都是产品经理
酷 壳 – CoolShell
酷 壳 – CoolShell
L
LangChain Blog
Blog — PlanetScale
Blog — PlanetScale
阮一峰的网络日志
阮一峰的网络日志
Microsoft Azure Blog
Microsoft Azure Blog
云风的 BLOG
云风的 BLOG
Google DeepMind News
Google DeepMind News
T
The Blog of Author Tim Ferriss
G
Google Developers Blog
Hugging Face - Blog
Hugging Face - Blog
Y
Y Combinator Blog
D
DataBreaches.Net
Engineering at Meta
Engineering at Meta
MyScale Blog
MyScale Blog
大猫的无限游戏
大猫的无限游戏
S
SegmentFault 最新的问题
The GitHub Blog
The GitHub Blog
Recent Announcements
Recent Announcements

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
Critical open-source projects get a new security framewor...
Anamarija Pogorelec · 2026-06-26 · via Help Net Security

Open source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation.

The Linux Foundation has launched Akrites, an industry initiative that brings together technology companies, financial institutions, security vendors, AI companies, and open source projects to support the remediation and disclosure of vulnerabilities affecting widely used open source software. Akrites aims to establish a common process for addressing security issues in software used across critical infrastructure and enterprise environments.

A shared approach to vulnerability response

Akrites establishes a shared Security Incident Response Team (SIRT) and a Coordinated Vulnerability Disclosure (CVD) process. Participating organizations will use common workflows and industry-standard tools to exchange vulnerability information, manage remediation, and coordinate disclosures until fixes are available.

The project focuses on software used in sectors including finance, healthcare, telecommunications, energy, government, and AI infrastructure. Many of these projects are maintained by small teams, even though their software is used by thousands of organizations.

“Open source powers the systems we rely on every day, running everything from banks and hospitals to power grids and AI platforms. As frontier AI accelerates vulnerability discovery, the risk has grown too large for any one organization to address alone. That’s why an ecosystem approach is critical, bringing the community, technology providers, and enterprises together to ensure vulnerabilities are addressed at the speed required,” Jamie Thomas, Enterprise Security Executive at IBM, explained.

Founding members include Amazon Web Services, Anthropic, Cisco, Citi, Endor Labs, Ericsson, GitHub, Google, IBM, JPMorganChase, Microsoft, NVIDIA, OpenAI, Red Hat, Sonatype, Vodafone, and Zscaler.

AI is changing vulnerability management

In an open letter published alongside the launch, the founding organizations said AI is accelerating vulnerability discovery and exploit development. They added that many open source maintainers lack the resources to keep up, increasing the need for a shared approach to vulnerability handling across the software ecosystem.

“Frontier AI models have given defenders the ability to find and fix vulnerabilities in open source software at a speed and scale that were never possible before. That’s an enormous opportunity for defenders, and Akrites ensures we seize it together. Maintainers deserve a coordinated partnership, not a flood of reports. AWS is committed to securing the projects our customers depend on and building this shared infrastructure alongside the community,” said Matt Wilson, Vice President and Distinguished Engineer at Amazon Web Services.

Akrites provides operational support from vulnerability reporting through public disclosure. The project includes procedures for receiving reports, assigning response teams, managing remediation, communicating with affected organizations, and preparing security advisories before vulnerabilities are disclosed publicly.

Building on existing security initiatives

Akrites builds on existing Linux Foundation security efforts. Alpha-Omega funds security improvements for critical open source projects and supports maintainers. The Open Source Security Foundation (OpenSSF) develops security initiatives, standards, and tooling for the open source ecosystem. It adds a coordinated incident response capability focused on handling vulnerabilities before public disclosure.

Mark Russinovich, Azure Chief Technology Officer, Deputy Chief Information Security Officer, and Technical Fellow at Microsoft, said OpenSSF and Alpha-Omega demonstrated how industry collaboration can strengthen open source security. He said Akrites builds on that work to address the growing impact of AI-powered vulnerability discovery and defense. As a founding member, Microsoft and GitHub will contribute expertise, resources, and AI technologies to help identify and fix vulnerabilities across the open source software ecosystem.

Organizations that can contribute engineering resources, security expertise, or funding are invited to participate in the initiative.