RC RANDOM CHAOS

Tech giants launch Akrites to patch open-source flaws before AI weaponizes them

· via Hacker News

Original source

We All Depend on Open Source. We Will Defend It Together

Hacker News →

A coalition of nearly two dozen major companies — including AWS, Anthropic, Google, Microsoft and GitHub, OpenAI, IBM, NVIDIA, Red Hat, Cisco, and banks like Citi and JPMorganChase — has announced Akrites, a coordinated program under the Linux Foundation to find, fix, and confidentially disclose vulnerabilities in the open-source libraries that underpin critical infrastructure. The launch, dated June 25, 2026, frames itself as the largest joint security effort of its kind, built on the premise that no single vendor can wall itself off from shared upstream defects.

The driving argument is that AI has broken the old balance between attackers and defenders. Discovering a serious flaw in a major project once took an expert weeks; a model can now surface several in minutes, turning vulnerability hunting into an automated pipeline that outpaces volunteer maintainers’ ability to patch. The signatories also warn that publishing a fix is itself a risk, since adversaries can use AI to reverse-engineer patches into exploits almost immediately — so the program intends to measure success by patch deployment rather than disclosure.

Operationally, Akrites aims to replace today’s fragmented, duplicative reporting with a single confidential channel and a shared Security Incident Response Team, keeping maintainers in control while routing fixes back into each project’s own repository. For abandoned but widely used packages, the group pledges to act as “maintainer of last resort.” Participants are committing engineering talent, security expertise, and funding, and say they intend to coordinate with governments and infrastructure operators rather than working in isolation.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.