The Akrites project for coordinating the operational elimination of vulnerabilities

The Akrites project has been announced to coordinate the remediation of vulnerabilities and disclosure of security issues in critically important open-source software. The project is established under the auspices of the Linux Foundation with participation from companies such as Amazon Web Services, Anthropic, Cisco, Ericsson, Google, IBM, Microsoft/GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Sonatype, and Vodafone, as well as the non-profit organization Rust Foundation.

Project participants will provide funding, engineering resources, and expertise in computer security to create a collaborative Security Incident Response Team (SIRT). The team will focus on identifying new vulnerabilities, analyzing and verifying vulnerability reports, assessing the severity level, developing fixes in conjunction with maintainers of open projects, and coordinating the vulnerability disclosure process. Disclosures will be synchronized with the release of fixes in primary projects, distributions, and dependent products.

It is noted that while creating exploits previously required expert knowledge and a lengthy development process, today's AI tools allow unqualified malicious actors to create operational exploits within hours by utilizing patch information. If a fix for a vulnerability is released without explicit disclosure related to security issues, users and developers of dependent projects may overlook the update, while attackers can quickly prepare an exploit using AI tools to start targeting unpatched systems.

In such conditions, the promptness of issue resolution becomes crucial, along with preventing information leaks during patch development. Concurrently with the publication of a fix, it is important to disclose vulnerability information and communicate the necessity of installing updates to users. Work will also be conducted to inform operators of critical infrastructure, important services, and projects about vulnerabilities, as the timely application of the patch is essential for blocking potential attacks.

In addition, the project aims to alleviate the burden on maintainers by taking on tasks such as filtering duplicate problem reports, confirming the presence of vulnerabilities, and assisting in the development and testing of fixes.
When vulnerabilities are discovered in critical packages without active maintainers, the Akrites project will take on the work of preparing and integrating fixes for them.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster