Back
Akrites: a coordinated industry effort to defend open source security
SiTech AI Team3 წთ. საკითხავი

Akrites: a coordinated industry effort to defend open source security

An open letter published on 25 June 2026 by AWS, Google, Microsoft, OpenAI and others launches Akrites — one confidential channel to find, fix and responsibly disclose vulnerabilities in open source software.

On 25 June 2026 a group of technology companies and foundations published an open letter titled "We All Depend on Open Source. We Will Defend It Together", announcing Akrites — a coordinated effort to find, fix and responsibly disclose vulnerabilities in the open source software that critical infrastructure depends on. The authors call it the largest coordinated effort in history, and the document is published under the Linux Foundation.

Among the signatories are Amazon Web Services, Anthropic, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, the Rust Foundation, Sonatype, Vodafone and Zscaler. The CNCF, OpenInfra, OpenSSF and the PyTorch Foundation support the effort.

Why now: AI changed the equation

The letter's central argument is that artificial intelligence has collapsed the previous equilibrium between attackers and defenders. "Finding a serious vulnerability in a major open source project used to take an expert weeks. This now takes a machine minutes, and often the AI model returns multiple vulnerabilities in a single pass," it states. The result is a discovery and disclosure cycle that is outstripping maintainers' capacity to patch — not a theoretical risk but "the present condition of every system we are responsible for".

Coordination, rather than more scanning, is the missing piece. When dozens of companies independently scan the same library and each file a separate report, maintainers are buried in noise; every additional party holding an unpatched vulnerability raises the odds that it leaks before a fix exists. "No vendor's walls are high enough to make this someone else's problem," the authors write.

What Akrites promises

Akrites is presented as one confidential, trusted place to coordinate discovery, remediation and disclosure, with a shared, dedicated Security Incident Response Team that gives maintainers "a single, predictable partner instead of a hundred uncoordinated reports". The work happens upstream, where maintainers live, and fixes flow back into each project's own home. Where a critical package has no maintainer at all, Akrites says it will stand as the maintainer of last resort so a fix can still reach everyone in time.

Confidentiality is described as non-negotiable — "an undisclosed flaw in a widely deployed package is, in effect, a weapon" — and success will be measured in patch deployment rather than publication, because adversaries can use AI to reverse-engineer released patches and build exploits quickly. Participants will contribute engineering talent, security expertise or funding.

What the participants say

The letter is accompanied by statements from most of the organisations involved. Endor Labs notes that of the thousands of validated open source vulnerabilities surfaced in recent months, fewer than 5% have been patched. The OpenInfra Foundation offers a scale check: the OpenStack community issued 20 security advisories in a single quarter, against just two in all of 2025. JPMorganChase frames the goal as compressing the time from fix to deployment, while Microsoft cites OpenSSF and Alpha-Omega as the precedent.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.