The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Linux Foundation press release and coverage from SecurityWeek, The Decoder, and others confirm the June 25, 2026 launch of Akrites with ~20 founding partners including AWS, Anthropic, Google, Microsoft, NVIDIA, OpenAI, and JPMorganChase to coordinate open source vulnerability fixes amid AI threats.

Sourcing
1source

via Decrypt

From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/Linux Foundation Debuts Akrites to Speed Up Open Source Vulnerability Fixes
VERIFIEDBy Xavier Rivera· ·3 min read

Linux Foundation Debuts Akrites to Speed Up Open Source Vulnerability Fixes

The Linux Foundation launched Akrites on Thursday with 19 founding members including major tech firms and banks to organize remediation of critical open source vulnerabilities before AI-powered attackers can exploit them. The project tackles the reality that fewer than 5% of thousands of AI-identified flaws have received patches by instituting one confidential response team in place of scattered reports.

Source:Decrypt
Post
Linux Foundation Debuts Akrites to Speed Up Open Source Vulnerability Fixes
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

The Linux Foundation launched Akrites with 19 founding organizations to create a central security response team for open source projects. It coordinates vulnerability fixes and acts as maintainer of last resort. AI now finds flaws far faster than prior processes allow, with under 5 percent currently patched, so faster coordinated repairs are required before exploitation.

The Linux Foundation introduced Akrites on Thursday together with 19 founding organizations to organize the repair of serious open source weaknesses ahead of exploitation by AI-enabled adversaries.

Akrites forms a dedicated security response team for open source. Founding participants include Amazon, Anthropic, Citi, Google, JPMorganChase, Microsoft, NVIDIA, OpenAI and additional entities. The project establishes one confidential Security Incident Response Team that serves as a reliable contact for maintainers, replacing the previous deluge of separate notifications from various groups.

Repairs are contributed back to each project's native repository according to the preferences of its maintainers and following established vulnerability tracking protocols. Should a vital package lack an active maintainer, Akrites pledges to assume the role of maintainer of last resort.
Akrites forms a dedicated security response team for open source.

AI has accelerated vulnerability discovery beyond current coordination models. Advanced models can now examine a large open source codebase and identify several verified issues within minutes, a task that formerly demanded weeks from experienced security analysts. As Decrypt has reported, Claude Opus 4.8 detected a critical flaw in Zcash's Orchard privacy pool inside one day, revealing a defect that had persisted through four years of examination by cryptographers.

Anthropic Deputy CISO Jason Clinton stated in the open letter that the prior coordinated disclosure framework "has been outpaced by how quickly AI can now find vulnerabilities" and that upstream repairs demand alignment on discoveries "before they're disclosed and exploited." Earlier workflows often resulted in separate teams reviewing identical libraries through extended administrative steps prior to resolution.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Fewer than 5% of AI-surfaced vulnerabilities have been patched. Endor Labs CEO Varun Badhwar reported that of the thousands of validated open source flaws surfaced by AI during recent months, "fewer than 5% have been patched." The letter endorsed by all 19 founding organizations described the former method as one that buries maintainers "under noise."

Rust Foundation CEO Rebecca Rumbul observed that the goodwill of open source maintainers has been presumed for too long, and the new project will enable better coordinated efforts among them. She added that Akrites "promises meaningful coordination with upstream maintainers, financial, and full-time support to find, fix and disclose security vulnerabilities responsibly, and a genuine commitment from the most influential companies across tech and finance to solve this problem."
AI has accelerated vulnerability discovery beyond current coordination models.

Success metric shifts from patch publication to deployment. JPMorganChase CISO Pat Opet explained that AI has greatly shortened the interval between flaw identification and exploitation to nearly instantaneous levels. Consequently, opponents may analyze a released patch and create a functional attack before numerous downstream users have implemented the correction.

Opet declared that true success consists of "patch deployment, not patch publication." OpenAI introduced its separate initiative, Patch the Planet, three days prior to Akrites. That project employed GPT-5.5-Cyber along with Trail of Bits engineers on 19 open source projects and integrated dozens of repairs.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
OpenAI Cyber Lead Clint Gibler described securing open source as "a long-term commitment" for the firm and noted that Akrites helps "strengthen coordination across the industry." Although the programs overlap, Patch the Planet centers on AI-supported identification plus patch application backed by specialist human oversight, whereas Akrites constructs the underlying coordination framework.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
Open SourceSecurityAI
More fromDecrypt
  • Robinhood Chain Launches as Ethereum L2 for Tokenized Stocks

    Markets · 2mo
  • Robinhood Chain racks up $1B DEX volume in debut week

    Markets · 2mo
  • Paradigm Closes $1.2 Billion Fund Aimed at Crypto, AI and Robotics Startups

    Markets · 2mo
More inTech
  • CISA Adds WordPress Core Flaw CVE-2026-87902 to KEV Catalog

    Tech · 3h
  • CISA Adds Microsoft SharePoint Code Injection Flaw CVE-2026-65660 to KEV

    Tech · 5h
  • CISA Adds MikroTik RouterOS SSH Flaw CVE-2026-67279 to KEV Catalog

    Tech · 5h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    IBM Discloses Two More Guardium Data Protection 12.2 Flaws, Including a CVSS 8.8 Bug

    NVD published two more high-severity CVE records for IBM Guardium Data Protection 12.2 on September 25: CVE-2026-85542 (CVSS 8.8), a command injection bug, and CVE-2026-85029 (CVSS 7.5), a path traversal flaw. IBM lists fix pack SqlGuard_12.0p233.

  • Tech· 

    Microsoft Outlook Flaw CVE-2026-100208 Could Allow Remote Code Execution

    Microsoft Office Outlook has an integer overflow flaw, CVE-2026-100208, that could let an unauthorized attacker run code over a network. Microsoft scores it 7.5 (High), and an attack needs user interaction.

  • Tech· 

    IBM Power Server Firmware Flaw CVE-2026-93306 Can Crash the ASMI Web Interface

    CVE-2026-93306, published by NVD on September 25, lets an unauthenticated attacker on the management network crash the ASMI web server in IBM server firmware with a malformed HTTPS request. IBM rates it 7.1 (High) and has released fixed firmware for Power11, Power10 and Power9 systems.

  • Tech· 

    IBM Patches Two High-Severity Flaws in Guardium Data Protection 12.2

    NVD published two high-severity CVE records for IBM Guardium Data Protection 12.2 on September 25. CVE-2026-84884 (CVSS 7.5) covers REST service-account passwords stored in a reversible format, and CVE-2026-84862 (CVSS 7.2) is an insecure deserialization flaw that could allow code execution. IBM points customers to fix pack SqlGuard_12.0p233.

  • Tech· 

    CISA KEV Entry for Adobe Commerce CVE-2026-71362

    CISA KEV entry for the CVE-2026-71362 incorrect authorization flaw in Adobe Commerce and Magento shows date added 2026-09-24. Federal agencies must apply mitigations by 2026-09-27 under BOD 26-04 rules.