Mark Russinovich Details Akrites Project for Securing Open Source Software

M

Mark Russinovich

LinkedIn Author

CTO, Deputy CISO and Technical Fellow, Microsoft Azure

In a recent LinkedIn post, Mark Russinovich discusses the formation of Akrites, a new Linux Foundation project aimed at enhancing the security of critical open source software. Microsoft and GitHub are contributing engineering expertise and technology as founding members to this initiative.

Russinovich frames the ongoing challenge of open source software security not as a question of whether vulnerabilities will be found, but rather how quickly they can be addressed. He highlights the urgency of the situation:

“The question is no longer whether vulnerabilities in Open Source Software will be found. It is who finds them first, how quickly they can be validated and fixed, and how quickly those fixes are consumed the organizations that depend on them.”

The post emphasizes the foundational role of open source software in global infrastructure and the increasing risk posed by advancements in Artificial Intelligence, which are accelerating vulnerability discovery. Russinovich explains that Akrites is designed to fill a critical gap in the industry.

Addressing the Vulnerability Management Gap

According to Russinovich, a significant challenge exists in establishing a scalable, industry-wide mechanism for handling vulnerabilities discovered through AI. He outlines the specific areas Akrites aims to address:

“AKRITES is designed to address a gap that has become increasingly apparent: there is no scalable industry mechanism for intake, validation, prioritization, coordinated remediation, and disclosure of AI-discovered vulnerabilities in OSS.”

He further elaborates that Akrites will integrate a common workflow, facilitate shared response coordination, and provide engineering resources to assist maintainers in transforming vulnerability findings into deployed fixes. This collaborative approach is seen as essential for the health of the software ecosystem.

Industry Collaboration as a Security Imperative

Russinovich connects this new project to Microsoft’s ongoing commitment to open source security. He mentions previous work with the Linux Foundation, OpenSSF, and Alpha-Omega, underscoring a core belief that securing the software ecosystem necessitates broad industry collaboration.

He argues that the evolving landscape, particularly with AI impacting the economics of vulnerability discovery, requires defenders to adapt their speed and scale. As Russinovich notes:

“Defenders need to move with the same speed and scale. Akrites is one step toward making that possible.”

The formation of Akrites represents a proactive step by Microsoft and GitHub, alongside other founding members, to bolster the security of the open source software that underpins so much of modern technology. The project’s focus on a coordinated and efficient response to AI-driven vulnerability discovery is positioned as a critical development for the industry.

📝 About This Content

This article is based on insights shared by Mark Russinovich on LinkedIn.

📅 Originally posted on June 25, 2026 | View original post on LinkedIn →