AI’s About to Cause Security Teams a Right Lovely Headache This Summer

AI’s Causing Security Teams to Work Overtime: The Chainguard Challenge

This summer is set to be quite the challenge for those in security, particularly as they navigate the open source code that supports their enterprises. Dan Lorenc, the CEO and co-founder of Chainguard, believes this season will be rather chaotic. Chainguard, a company focused on software supply-chain security, is leading Athena, a newly established coalition comprising around twenty firms that aim to simplify the process of identifying and resolving open source bugs.

Athena’s Forces: The Key Players in the Coalition

The participants have committed to utilizing AI to protect open source software from intrusions. In addition to Chainguard, other foundational members include BNY, Cisco, Cloudflare, Corridor, DepthFirst, Docker, JPMorganChase, Kyndryl, LTM, and PwC. Many of these organizations also collaborate with Anthropic’s Project Glasswing and OpenAI Daybreak, allowing them to experiment with innovative bug-fixing models.

Summer of Exposures: The Bug Search

Athena has already examined more than 20,000 findings and created over 2,000 patches across 500 open source projects. Lorenc states, “This summer is going to be messy for all involved.” He is convinced that the data from cutting-edge models, such as Anthropic’s Mythos and OpenAI’s GPT‑5.5‑Cyber, is genuinely alarming. “The numbers we’re encountering are frightening – vulnerabilities keep appearing,” he remarked.

Chainguard’s Approach: Unraveling the Glasswing Dilemma

Even though not directly part of Glasswing or Daybreak, Chainguard’s partners are deeply engaged. “Picture being a developer with access to Glasswing,” Lorenc elaborated. “You have this astonishing model that uncovers vulnerabilities everywhere, which you have overlooked for ages with your previous tools. Run it on your code, and suddenly, you discover numerous issues in your own crafted code, and then you have to address them all.”

Open Source Code: An Unmanageable Nightmare?

After you’ve addressed your own code, how about applications? Contemporary applications are a mixed bag of code sourced from various places, predominantly third-party. Lorenc mentions that 95% of codebases are open source. “Deploy these models at the application level, and you uncover a wealth of vulnerabilities in open source code, but fixing them isn’t as straightforward as your own code,” Lorenc explained. “Then you find yourself pondering what to do next.”

The Bug Report Dilemma

By this point, everyone knows they must report issues to open source project maintainers. However, when you’re overwhelmed by thousands of bugs you never knew were there, and you can’t find the responsible parties, it leaves you perplexed. The only clear fact is that attackers are not wasting time, and the interval from public disclosure to exploitation is rapidly decreasing.

The Clearinghouse: Chainguard’s Role in Bug Resolution

Your application might be exposed even before a patch is available. “Then you’re taking a risk – and you were already in danger before you ran these scans, but no one else was aware,” Lorenc stated. “In an unexpected turn, AI has placed everyone in quite a predicament.” In May, Anthropic utilized Mythos Preview on over 1,000 open-source projects, uncovering a staggering 6,202 critical or high-severity vulnerabilities.

Submissions and Solutions: Athena’s Approach

Members of the Athena coalition submit their newly found vulnerabilities using various frontier models. Occasionally they identify bugs while scanning their applications, while at other times it’s after targeting Mythos or GPT‑5.5‑Cyber at a well-utilized library. Chainguard compiles these reports, refining and addressing findings across entire libraries, strengthening them against entire categories of vulnerabilities.

Akrites: The Linux Foundation Enters the Battle

On Thursday, the Linux Foundation joined the initiative, unveiling Akrites, a coalition aimed at defending open source software from AI-induced threats. Akrites offers a shared Security Incident Response Team (SIRT) and a standardized Coordinated Vulnerability Disclosure (CVD) process, facilitating easier management of the influx of vulnerability reports for maintainers.

SIRT to the Rescue: A Support System for Maintainers

With AI uncovering an increasing number of vulnerabilities daily, the urgency to patch them is escalating. Without adequate coordination, fixes could evolve into a chaotic mess. Lorenc expresses, “Akrites provides an organized method to rectify flaws before wrongdoers can exploit them. Having a dedicated SIRT means maintainers have a single partner to collaborate with on remediation rather than sifting through multiple uncoordinated reports.”

Summary: The AI Summer Challenge

This summer is set to be quite a rollercoaster for security teams and anyone involved with open source. With AI spotlighting a multitude of vulnerabilities, it’s going to be a continuous chase. But remember, every silver lining comes with its challenges, right? So let’s stay vigilant, and perhaps keep our code afloat. Until next time, stay secure!