Skip to main content

Discovery Is Outrunning Remediation Everywhere. That Is Not Just a Technology Problem.

Discovery Is Outrunning Remediation Everywhere. That Is Not Just a Technology Problem.

A model found 1,596 unpatched vulnerabilities in open source projects last month. The industry’s answer was more infrastructure for finding problems. That was never the part that was broken.

Anthropic, Google, OpenAI, Microsoft, and more than a dozen other organizations just did something companies rarely do voluntarily. They pooled money into a shared body, called Akrites and hosted by the Linux Foundation, because none of them could keep pace with open source vulnerability discovery and remediation on their own.

Organizations build shared infrastructure at this speed for one reason. A risk got too expensive for any single balance sheet to absorb quietly. That is what a captive insurance pool is. A group of companies decides a risk is real and common enough that carrying it alone costs more than carrying it together. Nobody calls that admission a taskforce. They call it underwriting, and they usually get a board resolution and a name plate before anyone says the real reason it exists out loud.

The gap that triggered this is specific and measurable, not theoretical. A single model surfaced 1,596 verified vulnerabilities across hundreds of open source projects. Most had no visible fix attached, according to Tuskira’s analysis, reported by Help Net Security. Discovery is outrunning remediation everywhere, not only inside the handful of companies with the balance sheet to fund a Linux Foundation initiative about it.

Here is the part that belongs on your desk and not only your CISO’s. You did not get a vote on whether your organization joined Akrites. You are covered by what it finds whether you contributed to its formation or not, in the same way every company benefits from a standard it did not help write. That is not a complaint. It is a description of where the accountability actually sits now. The industry just built the discovery function. The decision about what your organization does with what that function surfaces still belongs to exactly one desk inside your walls, and right now that desk is empty.

Open source software has never shown up on a balance sheet. There is no purchase order, no procurement trigger, no line item that forces a review before it enters production. It accumulates the way every liability accumulates when nobody is required to log it, continuously and invisibly, until a regulator or an acquirer asks to see the record.

Two clocks are already running underneath this. SEC disclosure rules put personal accountability on the executive who signs off on a security posture with no documentation behind it. The EU Cyber Resilience Act adds a second one. Manufacturers must send an early warning on an actively exploited vulnerability to ENISA within 24 hours of becoming aware of it, starting September 11, 2026, for products already on the market. Neither clock is waiting for Akrites to finish its first year.



None of this requires your organization to solve AI driven vulnerability discovery on its own. Funding a shared body was the whole point of not solving it alone. The technology problem, discovery outrunning remediation, just got an industry scale answer. What no coordination effort can do on your behalf is make the one decision that was always going to sit inside your organization: how much of the exposure that body surfaces is acceptable to carry, who weighed that call, and on what evidence.

That decision has to leave a mark somewhere, or it does not count. Not a scan result. Not a line in a risk register with no name attached to it. A documented call: this exposure was identified, this person or committee weighed it against the alternative, and this was the decision, made on this date, with this evidence on the table. That is the artifact a regulator, an auditor, or a plaintiff’s attorney asks for after something goes wrong. Most organizations only find out they never created one at the exact moment they need it most.

A CFO and a CISO are asking a version of the same question in different vocabulary. Not whether open source vulnerabilities exist. Every company has them, and now an industry body exists to confirm the scale. The question is whether anyone inside your organization can produce, today, the name attached to the decision about how much of that exposure you chose to carry.

Most cannot answer that yet. That is not evidence the security team is behind. It is evidence the decision was never assigned to a person in the first place, and that gap is far cheaper to close before an incident than to explain after one.


Comments

Popular posts from this blog

Open Source Compliance Now Has a Deadline. Accountability Now Has a Name.

Open Source Compliance Now Has a Deadline. Accountability Now Has a Name. The US federal safety net that followed Log4j has thinned in the same window the EU Cyber Resilience Act wrote obligations for commercial users of open source software into law, with reporting requirements beginning September 2026. The accountability for what enters your products is moving toward the organizations that consume it, on someone else's timeline. Two things happened to open source software security in the same window, and together they change who is on the hook. The US federal effort that grew after the 2021 Log4j crisis has largely lapsed, with key personnel gone and the initiatives quiet. At the same time, the EU Cyber Resilience Act turned obligations for commercial users of open source software into law, with vulnerability and incident reporting requirements applying from September 2026. One backstop thinned. The other became a requirement with a date attached to it. If the plan was to wai...

The SBOM Just Became a Liability With a Date on It

The SBOM Just Became a Liability With a Date on It When a best practice becomes a product requirement, it stops being a security artifact and starts being a financial one. The question now is whether the document you are obligated to produce is true. The EU Cyber Resilience Act is moving the software bill of materials from a best practice to a product security requirement, with the law’s full application arriving in December 2027 . If your company ships software into the EU, the character of one of your obligations just changed. The software bill of materials you used to produce because it was responsible is becoming one you are legally required to produce because a regulator says so. That is not a procedural change. It moves the bill of materials off the security team’s task list and onto the company’s books, and most organizations have not adjusted to what that means. A best practice and a requirement are not the same liability Every CFO understands that an unmanaged liability is a ...