AI觉醒星球
Awakening is here
Knowledge File / 全球热点解读
2026-06-26 4 浏览 公开

Linux基金会与20家科技巨头推出Akrites,在AI驱动攻击到来前修复开源缺陷

Linux基金会联合约20家科技公司启动Akrites计划,旨在协调修复开源软件漏洞,应对AI工具快速扫描代码带来的安全威胁。计划设立共享安全事件响应团队,处理漏洞报告并协调修复,针对被遗弃项目自行发布补丁。创始成员包括亚马逊、谷歌、微软、OpenAI等。

SOURCE / 全球热点解读 MIN / 4 ACCESS / 公开 POST / 2026-06-26 18:07:05

原贴

查看原文
作者:Maximilian Schreiner 来源站点:the-decoder.com 原贴时间:

原文

The Linux Foundation and about 20 tech companies have launched the Akrites initiative to protect open-source software vulnerabilities from AI-powered attacks. As AI models can scan code in minutes and give even non-experts the tools for complex attacks, Akrites replaces the current uncoordinated system for reporting security flaws. A central team will vet reports confidentially and coordinate fixes. For abandoned projects, the initiative will ship the needed patches itself. About twenty tech companies, AI labs, and banks are joining forces through Akrites to fix vulnerabilities in critical open-source software before AI tools can exploit them. The Linux Foundation has announced Akrites, a coordinated industry initiative to patch security flaws in widely used open-source software alongside maintainers before attackers can take advantage. Founding members include Amazon Web Services, Anthropic, Cisco, Citi, Google, IBM, JPMorganChase, Microsoft, NVIDIA, OpenAI, Red Hat, the Rust Foundation, Vodafone, and Zscaler. The reason is a shift in the balance of power: finding and fixing serious bugs in open-source code used to require comparable expertise on both sides. Modern AI models can now scan a large project in minutes instead of weeks, exposing flaws far faster. Once those abilities are widely available, even attackers without deep technical skills get the tools for sophisticated exploits. Ad The Linux Foundation describes the current security response model as patchwork. Many organizations scan the same packages independently, report the same findings multiple times, and sometimes deliver conflicting patches. Maintainers get buried under duplicates while real, exploitable bugs get lost in AI-generated noise. Endor Labs CEO Varun Badhwar put the urgency in sharp terms: of thousands of validated open-source vulnerabilities from recent months, fewer than five percent have been patched. Ad DEC_D_Incontent-1 At the core of Akrites is a shared Security Incident Response Team (SIRT). It acts as a single, reliable point of contact for open-source project maintainers instead of dozens of organizations independently flagging the same flaws. The team vets incoming reports, filters out duplicates, and then coordinates fixes. Akrites uses a standardized process for confidential vulnerability disclosure, known in the industry as Coordinated Vulnerability Disclosure. It builds on established standards like the CVE identifier system, the CVSS severity scoring framework, and the TLP traffic-light protocol that governs who gets to see what. Confidentiality is central: every report starts at TLP:RED, the highest classification level, and only the assigned case team can access it. That way, details about a flaw don't leak before a patch is ready. Ad Finished fixes flow back into the original project on the maintainer's terms keeping developers in control. When a critical package no longer has an active maintainer - a common problem with volunteer-run projects - Akrites plans to step in as a "maintainer of last resort" and ship the fix itself, so the patch reaches all users in time. The initiative also plans to coordinate with government agencies so private and public defenders move in lockstep. Seed funding comes from Alpha-Omega, a directed fund under the Linux Foundation. Other organizations that want to contribute engineering resources or funding are invited to join. Ad DEC_D_Incontent-2 Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.

中文翻译

Linux基金会与约20家科技公司启动了Akrites计划,以保护开源软件漏洞免受AI驱动的攻击。由于AI模型可以在几分钟内扫描代码,甚至为非专家提供复杂攻击的工具,Akrites取代了当前报告安全缺陷的不协调系统。一个中央团队将保密地审查报告并协调修复。对于被遗弃的项目,该计划将自行发布所需的补丁。

约20家科技公司、AI实验室和银行正在通过Akrites联手,在AI工具能够利用漏洞之前,修复关键开源软件中的漏洞。Linux基金会宣布了Akrites,这是一项协调的行业计划,旨在与维护者一起在攻击者利用之前修补广泛使用的开源软件中的安全缺陷。创始成员包括亚马逊云服务、Anthropic、思科、花旗、谷歌、IBM、摩根大通、微软、英伟达、OpenAI、红帽、Rust基金会、沃达丰和Zscaler。原因是力量平衡的转变:过去,发现和修复开源代码中的严重漏洞需要双方具备相当的专业知识。现在,现代AI模型可以在几分钟内扫描大型项目,而不是几周,从而更快地暴露漏洞。一旦这些能力广泛可用,即使是缺乏深厚技术技能的攻击者也能获得进行复杂攻击的工具。

核心信息

Linux基金会联合约20家科技公司启动Akrites计划,旨在协调修复开源软件漏洞,应对AI工具快速扫描代码带来的安全威胁。计划设立共享安全事件响应团队,处理漏洞报告并协调修复,针对被遗弃项目自行发布补丁。创始成员包括亚马逊、谷歌、微软、OpenAI等。

  • Linux基金会联合约20家科技公司启动Akrites计划,旨在协调修复开源软件漏洞,应对AI工具快速扫描代码带来的安全威胁。计划设立共享安全事件响应团队,处理漏洞报告并协调修复,针对被遗弃项目自行发布补丁。创始成员包括亚马逊、谷歌、微软、OpenAI等。
  • 原贴提到:The Linux Foundation and about 20 tech companies have launched the Akrit
  • 来源:the-decoder.com

详细解读

这是什么信号?

Linux基金会联合20家科技巨头推出Akrites,标志着开源安全从“各自为战”转向“协同防御”。AI工具(如代码扫描模型)大幅降低了漏洞发现和利用的门槛,传统的分散式漏洞报告模式已无法应对。Akrites通过设立统一安全事件响应团队(SIRT),构建从报告、审核到修复的标准化流程,尤其针对无人维护的项目主动提供补丁,体现了行业对开源供应链安全的高度重视。

为什么重要?

AI加速了攻防不对称:过去只有顶尖专家才能挖掘漏洞,现在AI可将扫描时间从数周缩短到分钟,且非专家也能发起攻击。据Endor Labs数据,近千个已验证开源漏洞中,只有不到5%被修复。Akrites通过集中化协调、保密披露和“最后维护者”机制,有望显著缩短漏洞暴露窗口,防止AI大规模利用。此举对依赖开源组件的企业(如金融、云服务)至关重要,因为一个漏洞可能波及整个供应链。

对谁有价值?

开源维护者:减少重复报告和噪音,获得专业支持;企业安全团队:提前获得补丁,降低被攻击风险;AI安全公司:可能获得协作机会;政府网络安全机构:可与Akrites协调,共同防御。对个人开发者,尤其是使用流行开源库的开发者,间接提升了所依赖代码的安全性。

可以怎么行动?

企业可加入Akrites贡献工程资源或资金,获取第一手漏洞情报;安全团队应关注Akrites披露的漏洞,及时应用补丁;开发者在选择开源库时优先考虑有Akrites覆盖的项目;个人可参与开源项目维护,降低被遗弃风险。同时,建议企业建立内部AI安全扫描流程,与Akrites形成互补。

风险或限制

Akrites依赖成员参与度,若关键项目维护者不配合,效果打折;“最后维护者”机制可能引发控制权争议;保密披露流程仍存在泄露风险;AI攻击技术演进迅速,需要持续投入;仅覆盖部分项目,大量小型库仍无人问津。此外,政府协调可能带来合规复杂性。

信息差价值

这条内容的真正价值,不只是“有人发布了一个新功能”,而是它揭示了 the-decoder.com 背后的产品方向、工作流变化或竞争信号。对 OPC 来说,这种信息可以转化成持续追踪的栏目选题。

如果把《Linux基金会与20家科技巨头推出Akrites,在AI驱动攻击到来前修复开源缺陷》放到你的内容系统里,它最大的价值在于帮助读者更快看懂“为什么值得关注”,而不是只看到一条碎片化动态。

参考来源

上一篇 作为Hubber的转型 下一篇 近400家美国报纸起诉微软和OpenAI:未经授权抓取新闻内容训练AI