A new wave of AI-driven cyberattacks targets open-source software, and the pace of vulnerability patching is alarmingly slow. Less than 5% of identified flaws in open-source projects have been fixed as of late June, exposing critical weaknesses across widely used codebases.
A rapid shift in software security
The Open Secure AI Alliance, spearheaded by the Linux Foundation, emerged as a response to an urgent challenge. AI tools can now scan entire codebases in minutes, uncovering security holes that once took weeks for human researchers to find. This dramatic acceleration in attack capabilities creates a pressing need for a coordinated, faster defense strategy.
Rather than a single company action, the alliance represents a collaborative effort involving major tech players sharing resources, intelligence, and expertise. Its flagship tool, Akrites, operates through a Security Incident Response Team and follows established protocols like CVE and CVSS for vulnerability disclosure.
Financial backing comes from the Alpha-Omega fund, designed to scale support as the coalition grows. Founding members stressed their commitment in an open letter titled "We All Depend on Open Source. We Will Defend It Together," underscoring the shared risk and collective responsibility.
Open-source software forms the backbone of countless applications, including those underpinning critical internet infrastructure. With only 5% of recent vulnerabilities patched by June 25, the risk of exploitation escalates sharply as attackers use AI tools unmatched by current defensive measures.



