The Linux Foundation has launched Akrites, a coordinated security initiative aimed at fixing vulnerabilities in critical open source software before they are broadly disclosed and weaponized.

The project is framed around a specific pressure point: AI tools can speed up both vulnerability discovery and exploit development, shrinking the time maintainers have to coordinate patches after a flaw becomes public. Akrites is intended to create a shared Security Incident Response Team and a standardized coordinated vulnerability disclosure process for widely used open source components.

The founding group includes major AI labs, cloud providers, banks, infrastructure vendors, and open source organizations, including AWS, Anthropic, Chainguard, Cisco, Citi, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, Red Hat, the Rust Foundation, Sonatype, Vodafone, and Zscaler. The Linux Foundation says members will contribute engineering talent, security expertise, and funding, with seed funding from its Alpha-Omega directed fund.

For developers, the important part is the shift in where remediation work happens. Akrites is designed to operate confidentially before public disclosure, reduce duplicate private reports sent to maintainers, and help critical infrastructure deploy fixes before active exploitation follows.

That approach is also an implicit acknowledgement that open source security is now an operations problem, not just a bug-reporting problem. If AI-assisted analysis makes vulnerability turnaround faster on both sides, the defensive side needs coordination, trusted channels, and maintainers who can receive help before a disclosure clock starts.