The Linux Foundation announced Akrites, a new initiative to coordinate how the open source world handles security vulnerabilities before they become public.
Think of it as a shared Security Incident Response Team (SIRT) for open source. Akrites gives maintainers tools and channels to report, validate, and patch vulnerabilities — then disclose them in a coordinated way that prioritizes fixing over publishing.
The timing matters. AI has dramatically shortened the window between a patch going live and attackers reverse-engineering the flaw. Akrites aims to get fixes deployed before that window closes.
Heavyweights are backing the project: Anthropic, AWS, Chainguard, Cisco, Google, IBM, Microsoft, NVIDIA, OpenAI, Red Hat, and several others. Many of these same companies recently signed onto Chainguard’s Athena coalition, which shares similar goals.
Seed funding comes from the Linux Foundation’s Alpha-Omega directed fund, with member organizations contributing engineering resources and additional money.
“When patches are released to the public, adversaries are able to utilize AI to rapidly reverse engineer the underlying vulnerabilities, develop exploits, and launch attacks,” the Linux Foundation said. “The success of our efforts will be measured in patch deployment, not publication.”
Akrites will also act as a maintainer of last resort, ensuring fixes get delivered even for packages that are no longer actively maintained.
