All articles

Athena spotlight: Black Duck on the importance of flagging zero-days at scale

Ross Gordon Staff Product Marketing Manager

Black Duck joined the Athena coalition in July. We sat down with their team to talk about what changes when AI can find vulnerabilities faster than anyone can fix them.

Frontier AI models are demonstrating that they are highly capable of finding and exploiting “zero-day” vulnerabilities in code at machine speed, including those that have gone undetected in widely used open source projects. Through the Athena coalition, we’ve validated thousands of these open source zero-days to date. 

At that volume, protecting the ecosystem takes several defenses running at once: remediation, non-patch mitigations, and alerts telling organizations their apps are affected. Black Duck covers alerts, surfacing both known open source vulnerabilities and newly discovered zero-days in source code, binaries, and container images.

"Claude Mythos and Anthropic’s Project Glasswing changed the market in a fundamental way. It enables organizations to perform deep security analysis to detect vulnerabilities in open source missed by traditional AST," said Collin Hogue-Spears, Senior Director, Product Management at Black Duck. "But this leaves teams with a backlog of vulnerabilities to triage, prioritize, and remediate. This takes a lot of time and effort."

How Athena works

Here’s how the Athena coalition works: a member organization scans a running, sandboxed application with a frontier model and submits the finding anonymously. Chainguard triages, deduplicates, validates, and remediates it, then shares patched artifacts with members under a 30-day embargo, and publishes a private Open Source Vulnerabilities (OSV) feed to members and partners.

Where Black Duck fits

Black Duck takes that OSV feed and uses it as part of a responsible disclosure process to alert and provide mitigation and remediation guidance to customers using an open source component version containing one of these AI-discovered vulnerabilities.

"What the Athena project offers for our joint customers is the ability to not only find the vulnerabilities, but outsource the triage and the remediation to Chainguard, Black Duck, and others in the coalition, while improving the timeliness and actionability of our Black Duck Security Advisories (BDSAs) for all customers," said Collin.

It takes dozens of partners

When bringing together the Athena coalition, we knew that no single vendor could cover every layer of defense needed to prevent AI attacks. Taking a vulnerability through its full lifecycle and turning it into protection for everyone takes dozens of partners like Black Duck, each closing a gap the others can't.

"We started with Chainguard as customers, and we quickly moved into partnership, and now we're excited to further expand that partnership with the coalition," said Collin.

If you're finding vulnerabilities using frontier AI models, or you build detections and mitigations that could ride on a pre-disclosure feed, we would love to partner with you. Learn more about Athena here.

Share this article

Want to learn more about Chainguard?

Contact us