The post has been translated automatically. Original language: Russian
The IT industry has reached the point of no return. On June 25, 2026, the Linux Foundation, together with twenty technology giants (including Google, Microsoft, AWS, NVIDIA, as well as Anthropic and OpenAI), announced the creation of the Akrites alliance.
This is not just another paper initiative or a compliance committee. This is an urgent attempt to rebuild the cybersecurity architecture of the entire global Open Source, in which the balance of power has been completely destroyed by the development of large language models (LLM).
What is the fundamental crisis?
Previously, searching for critical vulnerabilities (0-day) and writing working exploits (attack code) required weeks of painstaking manual work and the rarest competencies from hackers. The defenders had time.
Today, advanced specialized AI agents scan the most complex repositories in a matter of minutes. At the UN Open Source Conference, the head of the Linux Foundation, Jim Zemlin, voiced a frightening thesis:
"The average time to exploit a software vulnerability is now minus seven days."
This means that attackers use AI to find and automate code base breaches before the maintainers (project authors) even realize the problem exists. The situation is aggravated by statistics from Citi: out of thousands of validated vulnerabilities of recent times, less than 5% have been patched. Open Source developers (often volunteers) are simply buried under the avalanche of AI generation.
Akrites Strategy: How the new "IT shield" works
Instead of producing hundreds of disparate security reports that paralyze code authors, Akrites implements a tightly centralized, confidential protection model.
1.Single Point of Entry (Shared SIRT):Noise filtering.
Instead of hundreds of emails to maintainers, all AI reports are sent to a single Response Team (SIRT). The alliance's experts and AI defenders filter out false positives, duplicates, and compile clean data.
2.TLP Mode:RED:Absolute privacy.
Any confirmed vulnerability gets the highest security status. Only an isolated workgroup has access to it to prevent data leakage until the fix is ready.
3.Joint patch development:Control over the authors.
Akrites takes over writing the correction code, coordinating it with the maintainers. If a mission-critical package is abandoned (there are no active developers), the alliance officially acts as the "last defender" (maintainer of last resort) and releases the patch on its own.
4.Proactive deployment:Perimeter closure.
Ready-made patches are coordinated and secretly transmitted to administrators of critical infrastructure (banks, energy, clouds) for deployment BEFORE the vulnerability is published in open CVE databases.
The main paradox of 2026
The most ironic and at the same time important marker of this story is the composition of the participants. Along with the defenders of the infrastructure are Anthropic and OpenAI. Companies whose technologies actually gave hackers this super-technological weapon are now forced to sponsor the creation of counteraction systems.
In fact, Akrites is a recognition of the industry: the human factor in DevSecOps can no longer cope with the speed of machines. The only way for the open source ecosystem to survive is to counter the attacking AI with exactly the same coordinated AI defense tool.
Whether the alliance will be able to reverse this trend will be shown by the statistics of cyber attacks in the coming months, but the rules of the Software Supply Chain security game have changed forever.
ИТ-индустрия подошла к точке невозврата. 25 июня 2026 года Linux Foundation совместно с двадцатью технологическими гигантами (включая Google, Microsoft, AWS, NVIDIA, а также Anthropic и OpenAI) объявили о создании альянса Akrites.
Это не очередная бумажная инициатива или комплаенс-комитет. Это экстренная попытка перестроить архитектуру кибербезопасности всего мирового Open Source, баланс сил в котором полностью разрушен развитием больших языковых моделей (LLM).
В чём фундаментальный кризис?
Раньше поиск критических уязвимостей (0-day) и написание рабочих эксплойтов (кода для атаки) требовали от хакеров недель кропотливой ручной работы и редчайших компетенций. У защитников было время.
Сегодня передовые специализированные ИИ-агенты сканируют сложнейшие репозитории за считанные минуты. На конференции ООН по Open Source глава Linux Foundation Джим Землин озвучил пугающий тезис:
«Среднее время до эксплуатации уязвимости в программном обеспечении теперь составляет минус семь дней».
Это означает, что злоумышленники с помощью ИИ находят и автоматизированно тестируют бреши в кодовой базе до того, как мейнтейнеры (авторы проектов) вообще осознают наличие проблемы. Ситуацию усугубляет статистика от Citi: из тысяч валидированных уязвимостей последнего времени реа пропатчено менее 5%. Open Source-разработчики (часто волонтеры) просто погребены под лавиной ИИ-генерации.
Стратегия Akrites: Как работает новый «ИТ-щит»
Вместо того чтобы плодить сотни разрозненных отчетов безопасности, которые парализуют авторов кода, Akrites внедряет жестко централизованную, конфиденциальную модель защиты.
1.Единая точка входа (Shared SIRT):Фильтрация шума.
Вместо сотен писем мейнтейнерам все ИИ-отчеты направляются в единую Команду реагирования (SIRT). Эксперты и ИИ-дефендеры альянса отсеивают ложные срабатывания, дубликаты и компилируют чистые данные.
2.Режим TLP:RED:Абсолютная конфиденциальность.
Любая подтвержденная уязвимость получает наивысший статус секретности. Доступ к ней имеет только изолированная рабочая группа, чтобы предотвратить утечку данных до готовности исправления.
3.Совместная разработка патча:Контроль за авторами.
Akrites берет на себя написание кода исправления, согласовывая его с мейнтейнерами. Если критически важный пакет заброшен (нет активных разработчиков), альянс официально выступает как «последний защитник» (maintainer of last resort) и выпускает патч самостоятельно.
4.Упреждающий деплой:Закрытие периметра.
Готовые патчи координированно и скрытно передаются администраторам критической инфраструктуры (банки, энергетика, облака) для развертывания ДО того, как уязвимость будет опубликована в открытых базах CVE.
Главный парадокс 2026 года
Самый ироничный и одновременно важный маркер этой истории — состав участников. В одном ряду с защитниками инфраструктуры стоят Anthropic и OpenAI. Компании, чьи технологии фактически и дали хакерам это сверхтехнологичное оружие, теперь вынуждены спонсировать создание систем противодействия.
По сути, Akrites — это признание индустрии: человеческий фактор в DevSecOps больше не справляется со скоростью машин. Единственный способ выжить для экосистемы открытого ПО — противопоставить атакующему ИИ точно такой же координированный ИИ-инструмент защиты.
Удастся ли альянсу переломить этот тренд — покажет статистика кибератак ближайших месяцев, но правила игры в безопасности снабжения ПО (Software Supply Chain) изменились навсегда.