Surprisingly Useful AI Article Enhancements
Chainguard has expanded its Athena coalition, an industry group focused on coordinated defence of open source software, adding new members including Akamai, Black Duck, Cycode, JFrog, Morgan Stanley, Qualys, Upwind and Zafran.
The coalition has now processed more than 40,000 vulnerabilities, doubling its intake since launching three weeks ago. Of the vulnerabilities submitted so far, 42 per cent are rated critical or high severity, and 86 per cent are network reachable, meaning they can be accessed and triggered by attackers at the network level.
About 7 per cent of the findings sit in packages more than five years old, representing latent flaws in mature, widely trusted dependencies that survived extensive expert review without detection.
AI-Driven Vulnerability Discovery
The coalition’s formation is driven by the growing capability of AI models to discover vulnerabilities in open source code at speed. Chainguard argues that frontier AI models can now find and chain together zero-day vulnerabilities at machine speed, compressing the gap between discovery and exploitation from weeks or years to hours.
Dan Lorenc, CEO and Co-founder of Chainguard, framed the challenge in terms of collective response.
“Frontier models are finding zero-days in open source faster than anyone can respond with discovery to exploitation is now measured in hours, and no one company is going to get ahead of that alone. Athena proves that orchestrated defence works,” Lorenc commented. “The volume and severity of what Athena is already finding make clear just how much depends on getting this right. The more of the ecosystem that joins, the less room attackers have to operate.”
The coalition noted that even the 42 per cent critical-or-high figure understates the real exposure, because AI models can chain low- and medium-severity bugs into more serious attacks that no single CVSS score captures.
How The Coalition Works
Athena’s partners work across a defence pipeline. Findings are pooled and de-duplicated, hardened fixes are built under embargo, partners stack non-patch protection around them, silent fixes are surfaced to exposed downstream users, and durable fixes are driven upstream to maintainers.
Cyber partners, which now form the largest cohort in the coalition, receive a dedicated pre-disclosure feed and use it to build mitigations at the network, endpoint and traffic layers that hold even before a clean patch exists or can be deployed. They also help surface “silent” vulnerabilities – flaws that are fixed upstream but never assigned a CVE – that conventional scanning tools generally miss.
New Members Weigh In
Boaz Gelbord, Chief Security Officer at Akamai, pointed to the need for speed in the current threat environment.
“Defending digital infrastructure in the age of AI requires a rapid, unified response,” Gelbord noted. “Athena allows us to protect customers with pre-embargo hardened software and platform-level mitigations before vulnerabilities can be exploited.”
Gal Marder, Chief Strategy Officer at JFrog, described the shift in the threat landscape.
“Frontier AI models are not only discovering thousands of zero days, but also chaining vulnerabilities together to exploit existing ones at machine speed, collapsing the gap between discovery and exploitation from weeks to hours,” Marder commented. “In this new reality, the era of ‘scan and hope’ is definitively over. Attackers are actively weaponising the trusted models and agentic tools driving today’s development.”
Marder added that JFrog’s role in the coalition centres on providing a source of truth for software assets, enabling automated updates of patched components at scale.
Qualys Joins The Coalition
Dilip Bachwani, Chief Technology Officer at Qualys, positioned the company’s involvement as an extension of its existing open source vulnerability research.
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop
“As consistent contributors to open-source vulnerability research and disclosure, Qualys welcomes the invitation to participate in Chainguard’s Athena coalition and secure open-source software by safely validating the exploitability of vulnerabilities with our technology,” Bachwani commented. “We believe creating a safer digital future is a shared industry responsibility. This builds on our ongoing work to help customers, partners and stakeholders prepare for a future where vulnerability discovery and remediation pressure move faster than ever.”
Runtime Visibility
Tomer Hadassi, COO at Upwind, highlighted the runtime intelligence dimension.
“AI is fundamentally changing the pace of vulnerability discovery, making coordinated defence more important than ever. By joining Athena, Upwind is bringing pre-disclosure vulnerability intelligence together with runtime visibility, helping organisations identify affected workloads and reduce the window between discovery and defence,” Hadassi commented.
Upstream Fixes Through Akrites
Pre-disclosure protection buys time, but the coalition’s goal is to land durable fixes in the upstream codebase. To close that loop, Chainguard has joined Akrites, the Linux Foundation’s coordinated effort to remediate and disclose open source vulnerabilities upstream.
Once a fix is built, shielded and surfaced through Athena, the finding is handed to Akrites, which operates a shared Security Incident Response Team and a single standardised disclosure process. This means maintainers receive notifications from one trusted partner rather than a flood of overlapping reports. For critical packages with no active maintainer, Akrites serves as a maintainer of last resort.
Coalition Membership
Athena’s membership now spans submitters, platform and network providers, cybersecurity vendors and global professional services firms. Members include BNY, Chainguard, Cisco, Cloudflare, JPMorganChase, Morgan Stanley, PwC and the newly added partners.
Organisations that discover vulnerabilities can submit them to the coalition for carry-through to a durable upstream fix. Those that build detections or mitigations, or carry fixes into production environments at scale, can join as cyber partners and access the pre-disclosure feed.
More information is available at chainguard.dev/athena.
Last Updated on July 22, 2026 by Nick Ross



