Under 5% of flaws patched: open-source software security faces AI threat

Something fundamental has shifted in how software gets attacked — and the people who build the open-source tools the entire internet runs on are scrambling to keep up. The Open Secure AI Alliance launched to address a specific, urgent problem: AI can now audit a codebase and surface critical vulnerabilities in minutes, a task that once took skilled human researchers weeks. That asymmetry is rewriting the rules of open-source software security, and a Linux Foundation-led coalition of major tech companies just placed a large collective bet on a shared defense.
Key takeaways
- The Open Secure AI Alliance, led by the Linux Foundation, launched to defend open-source software from AI-accelerated cyberattacks.
- Its core tool is Akrites, built around a shared Security Incident Response Team (SIRT) and a Coordinated Vulnerability Disclosure process following CVE and CVSS standards.
- At launch, fewer than 5% of recently surfaced open-source security vulnerabilities had been patched as of June 25 — a benchmark the alliance cited directly.
- The Alpha-Omega fund is providing the alliance’s initial financial backing, with the structure designed to accept additional capital and engineering resources.
- Founding participants published an open letter titled “We All Depend on Open Source. We Will Defend It Together.”
Launch of the Open Secure AI Alliance to counter AI-driven threats
The core problem the alliance is trying to solve is not new — open-source software has long carried security debt — but AI has dramatically shortened the attacker’s timeline. Where a trained security researcher might spend weeks combing through a codebase, modern AI models can perform a version of that analysis in minutes. That speed advantage, if left unanswered on the defensive side, creates a structural vulnerability at the very foundation of the global software supply chain.
… Continue reading the full article at the original source below.



