top of page

HeroDevs Joins Akrites to Tackle AI-Discovered Open Source Vulnerabilities

  • 3 hours ago
  • 2 min read

Artificial intelligence is making software vulnerabilities easier to find. Fixing them before attackers strike is becoming the harder problem.


HeroDevs, a company specializing in commercial support for end-of-life open source software, has joined Akrites, a Linux Foundation-backed initiative designed to coordinate the investigation, remediation, and responsible disclosure of open source security vulnerabilities.


Akrites addresses a growing complication in software security. AI models and automated research tools can now identify potential flaws across open source projects at a speed that maintainers may be unable to match. The resulting reports can include duplicate findings, false positives, and legitimate vulnerabilities that require urgent attention.


The initiative aims to consolidate those discoveries, validate their severity, coordinate disclosure under embargo, and connect affected projects with security engineers capable of producing patches. When a project is abandoned or its maintainers lack the resources to respond, Akrites can also designate a maintainer of last resort to oversee remediation.


HeroDevs will contribute engineering resources to Akrites’ security incident response team. Its engineers bring experience maintaining and patching unsupported open source libraries that remain embedded in enterprise applications long after their official support periods end.


“The exploit window has effectively gone negative: attacks are landing before a CVE is ever disclosed,” said Aaron Mitchell, CEO of HeroDevs. “Discovery isn't the bottleneck anymore. Getting a validated fix out before the rest of the world knows there's a problem is. Akrites gives us a seat at that table, and it lets us formally step in when a project's maintainer is gone and nobody else will.”


That shrinking response window is especially dangerous for organizations running end-of-life software. These systems may still support critical business operations, but vendors and community maintainers no longer routinely issue security updates. Replacing them can require months of engineering work, creating a gap between vulnerability discovery and migration.


HeroDevs markets its approach as “Secure in Place,” providing continued patches and compliance support while customers prepare upgrades on their own schedules. Its participation in Akrites extends that model into a broader open source security effort, where fixes may need to reach entire software ecosystems rather than a single customer.


As AI vulnerability discovery accelerates, Akrites is betting that coordinated human response, not detection alone, will determine whether newly discovered flaws become security improvements or ready-made opportunities for attackers.

bottom of page