The Linux Foundation launched Akrites on Thursday with 19 founding members including Amazon, Anthropic, Google, Microsoft, NVIDIA, and OpenAI to coordinate the patching of critical open-source vulnerabilities before AI-powered attackers can exploit them.
According to Endor Labs CEO Varun Badhwar, fewer than 5% of thousands of validated open-source vulnerabilities surfaced by AI in recent months have been patched. Akrites establishes a single, confidential Security Incident Response Team to replace uncoordinated disclosure processes, serving as the predictable upstream partner for open-source maintainers and stepping in as maintainer of last resort when critical packages lack active maintenance.