Skip to main content
CybersecurityVulnerability Management

Linux Foundation's Akrites to Launch Vulnerability Platform in September

Collaborative software development workspace with team members working on laptops and whiteboards surrounded by notes and…

"Coordinating AI-enabled vulnerability reports to upstream open-source maintainers so that the fixes are available to the whole ecosystem."

Akrites' stated missions

Launched at the end of June 2026 by the Linux Foundation, the Open Source Security Foundation (OpenSSF) and more than 20 founding members, Akrites is organized around two concrete objectives. The initiative will establish a shared security incident response team (SIRT) to mitigate and remediate vulnerabilities in open-source packages and libraries, and it will develop a standardized coordinated vulnerability disclosure (CVD) process built on "confidentiality-first principles and industry-standard tooling," according to the launch materials.

Christopher “CRob” Robinson—identified by the Linux Foundation release as OpenSSF’s CTO and chief security architect, and appointed as CTO of Akrites in June—summarized the project’s sole mission as the coordination of AI-enabled reports to upstream maintainers so fixes reach the wider ecosystem.

Founding membership, engineering donations and tiers

The coalition’s founding roster includes AI frontier labs Anthropic and OpenAI; cloud and tech companies Amazon Web Services, Cisco, Google, Microsoft and its subsidiary GitHub, IBM and its subsidiary Red Hat, and NVIDIA; cybersecurity firms such as Chainguard, Endor Labs and Zscaler; and large enterprises including Citi, JPMorganChase, Ericsson and Vodafone.

Membership is structured in three tiers—Associate, General and Premier—each carrying a set of benefits and corresponding fees. Each member is required to contribute between one and 10 engineers to the project as part of their membership commitment.

Technical foundation: VINCE plus LLM augmentation

Akrites has selected an existing academic platform as its technical base: Carnegie Mellon University’s Vulnerability Information and Coordination Environment (VINCE), a vulnerability management platform originally developed in 2020 by the Computer Emergency and Response Team Coordination Center (CERT/CC), a unit of CMU’s Software Engineering Institute (SEI).

On top of VINCE, the Akrites team is adding automated capabilities that leverage large language models (LLMs). Robinson described “a substantial amount of additional capabilities leveraging large language models (LLMs) to do deduplication, patch creation and more.” The goal, as described, is to reduce noise, assist with remediation workflows and scale the handling of large numbers of reports.

Current status, testing and the September go-live

Robinson told Infosecurity that Akrites’ tooling team has produced “the first draft of the tool chain.” The project has already received thousands of vulnerability reports in the roughly two months since launch; Robinson estimated roughly 30% of those reports are duplicates. To harden the platform ahead of live operations, Akrites is bringing in additional experts from member organizations to perform a penetration test and a security audit.

Those tests will be paired with functional enhancements that allow the platform to accept a combination of real and synthetic data as input, Robinson said, so the system can be exercised across a range of realistic conditions. When ready, the finished platform will be open-sourced and made available for anyone to use.

The Akrites-run platform is expected to “go live” and “start taking automated vulnerability reports” some time in September.

How open-source maintainers, member enterprises, and security teams are likely to respond

  • Open-source maintainers: They will be the recipients of coordinated, AI-enabled vulnerability reports routed by the shared SIRT and the VINCE-based platform; the stated aim is to deliver fixes upstream so the broader ecosystem benefits.
  • Member enterprises and tech vendors: Members have committed engineering resources—between one and 10 engineers each—and have paid for tiered membership. They will provide additional experts for penetration testing and audits as part of Akrites’ pre-launch hardening work.
  • Security teams and technologists: Teams operating at member companies and across the open-source supply chain will monitor the platform’s deduplication and automated patch-generation capabilities, and will evaluate how the confidentiality-first CVD process integrates with existing vulnerability workflows and industry-standard tooling.

Akrites arrives as a collective experiment in scaling vulnerability coordination where AI has increased both the number and the volume of automated findings. Its approach combines an academic-origin platform, VINCE, with LLM-driven tooling and a membership-backed SIRT model. The next observable milestone is concrete: a September go-live when the platform will begin accepting automated reports, followed by the planned open-sourcing of the finished platform.

Original story on Infosecurity