“After Fable 5 ban, Anthropic and 19 organizations launch open source security body” (The New Stack)
Paul Sawers (The New Stack, June 2026) reports the launch of Akrites — the Linux Foundation‘s coordinated body for open-source vulnerability discovery, remediation, and disclosure, built to counter AI-accelerated exploitation. The framing the headline draws out is the one that puts this in this wiki: Akrites arrives in the wake of the Fable 5 / Mythos 5 ban, and Anthropic is a founding member.
What it reports
- The body. ~20 founders (AWS, Anthropic, Google, Microsoft/GitHub, OpenAI, Cisco, Red Hat, NVIDIA, Chainguard, Sonatype, Ericsson, Vodafone, Citi, JPMorganChase); a shared SIRT consolidating findings, validating exploitable ones, and running one coordinated fix/disclosure under CVE/CVSS; three membership tiers; Alpha-Omega (OpenSSF) seed funding (>$7M/yr).
- The trigger context. Recaps the Fable 5/Mythos 5 suspension: Project Glasswing → trusted-partner cyber-defense access (April), then GA Mythos-class models with guardrails (early June), then the three-days-later US government suspension after researchers weaponized them for cyberattacks.
- On-record quotes. Jason Clinton (Anthropic deputy CISO), Varun Badhwar (Endor Labs CEO), Mark Russinovich (Microsoft Azure CTO) — each arguing the coordinated-disclosure model has been outpaced by AI-speed discovery.
Tier (T3)
Reputable trade press reporting a launch, with a primary backstop (the Linux Foundation press release + akrites.org) and on-record executive quotes — the launch is well-grounded. One stat is explicitly unverified (Endor Labs’ “thousands of AI-found OSS vulns, <5% patched,” from the firm’s own data). Aspirational claims about the SIRT’s effectiveness are not yet evidenced; this is day-one reporting on intent, not outcomes.
Related
akrites · linux-foundation · anthropic-export-ban-2026 · ai-governance · synthesis