Athena spotlight: Black Duck on the importance of flagging zero-days at scale
View all articlesRoss Gordon
Staff Product Marketing Manager
Chainguard
Ross Gordon Staff Product Marketing Manager
Black Duck joined the Athena coalition in July. We sat down with their team to talk about what changes when AI can find vulnerabilities faster than anyone can fix them.
Frontier AI models are demonstrating that they are highly capable of finding and exploiting “zero-day” vulnerabilities in code at machine speed, including those that have gone undetected in widely used open source projects. Through the Athena coalition, we’ve validated thousands of these open source zero-days to date.
At that volume, protecting the ecosystem takes several defenses running at once: remediation, non-patch mitigations, and alerts telling organizations their apps are affected. Black Duck covers alerts, surfacing both known open source vulnerabilities and newly discovered zero-days in source code, binaries, and container images.
"Claude Mythos and Anthropic’s Project Glasswing changed the market in a fundamental way. It enables organizations to perform deep security analysis to detect vulnerabilities in open source missed by traditional AST," said Collin Hogue-Spears, Senior Director, Product Management at Black Duck. "But this leaves teams with a backlog of vulnerabilities to triage, prioritize, and remediate. This takes a lot of time and effort."
How Athena works
Here’s how the Athena coalition works: a member organization scans a running, sandboxed application with a frontier model and submits the finding anonymously. Chainguard triages, deduplicates, validates, and remediates it, then shares patched artifacts with members under a 30-day embargo, and publishes a private Open Source Vulnerabilities (OSV) feed to members and partners.
Where Black Duck fits
Black Duck takes that OSV feed and uses it as part of a responsible disclosure process to alert and provide mitigation and remediation guidance to customers using an open source component version containing one of these AI-discovered vulnerabilities.
"What the Athena project offers for our joint customers is the ability to not only find the vulnerabilities, but outsource the triage and the remediation to Chainguard, Black Duck, and others in the coalition, while improving the timeliness and actionability of our Black Duck Security Advisories (BDSAs) for all customers," said Collin.
It takes dozens of partners
When bringing together the Athena coalition, we knew that no single vendor could cover every layer of defense needed to prevent AI attacks. Taking a vulnerability through its full lifecycle and turning it into protection for everyone takes dozens of partners like Black Duck, each closing a gap the others can't.
"We started with Chainguard as customers, and we quickly moved into partnership, and now we're excited to further expand that partnership with the coalition," said Collin.
If you're finding vulnerabilities using frontier AI models, or you build detections and mitigations that could ride on a pre-disclosure feed, we would love to partner with you. Learn more about Athena here.
Share this article
Related articles
securityHow financial services companies can modernize their software supply chain
securityProven, not promised: Chainguard Containers achieves SLSA Build Level 3
securityThe keyv and cacheable npm Supply Chain Attack: Inside the Mini Shai-Hulud Campaign
securityWhy AI-assisted attacks made software supply chain security its own category
securityWhy zero CVEs matters in mobile airgapped deployments
securityMitigating WordPress attacks with containers