Cyber Security News

OWASP Launches OASIS AI Initiative to Fix Open Source Vulnerabilities at Scale

OWASP has launched the Open Automated Security Initiative for Software (OASIS), a global community effort designed to close the gap between finding vulnerabilities in open source code and actually fixing them.

Announced on August 26, 2026, in San Francisco, the initiative pairs AI-generated fix candidates with human validation from application security professionals, aiming to deliver credible, ready-to-use patches to open source maintainers instead of just longer vulnerability lists.

Open source software underlies roughly 98% of commercial codebases, according to the Black Duck 2026 Open Source Security and Risk Analysis Report, yet maintainers are routinely overwhelmed by scanning tools that flag issues without offering usable remediation paths. OASIS addresses that bottleneck through a three-stage process.

Automated tooling first scans widely used repositories and generates candidate fixes as vulnerabilities surface. A community of AppSec practitioners and agents then reviews each candidate for correctness and safety, cutting validation time down to minutes.

Finally, vetted patches are submitted upstream, giving maintainers a trustworthy starting point they can adapt to their own codebase rather than a raw AI suggestion, complementing modern open-source vulnerability scanner workflows.

Since opening early sign-ups, OASIS has drawn hundreds of application security professionals across industries, backed by founding sponsors AppSecAI, Intigriti, and DryRun Security.

As detailed in the OWASP OASIS announcement, Chris Holt, Strategic Engagement and Community Architect at Intigriti, said open source underpins the majority of the information economy, making unremediated vulnerabilities a systemic risk, and that OASIS lets the AppSec and open source communities cooperatively deliver secure software together.

The timing reflects a shifting threat landscape. Attackers are increasingly using “vibe hacking,” AI-assisted vulnerability discovery and exploitation that outpaces manual defense.

James Wickett, CEO of DryRun Security, noted that the same generative AI accelerating attacks can accelerate defense when paired with independent validation and community expertise.

Michael Cartsonis of AppSecAI added that OASIS finally gives security professionals with code-review experience a fast, low-friction way to contribute.

Stage / ComponentProcess & Operational ModelStrategic Impact
Automated Scanning & GenerationAI-driven tooling scans repos and crafts patch candidatesAccelerates initial remediation proposals for newly found CVEs
AppSec Community ValidationHuman-in-the-loop expert review and agent validationCuts review cycles to minutes and eliminates false-positive fixes
Upstream SubmissionDelivery of vetted, ready-to-merge patches to maintainersReduces maintainer burden with production-grade remediation
Ecosystem CollaborationVendor-neutral backing (OWASP, Intigriti, DryRun Security)Secures long-tail open source dependencies across commercial stacks

OASIS is positioned as a complement to enterprise-led efforts such as OpenAI’s Patch the Planet, the Linux Foundation’s Akrites, and Anthropic’s Project Glasswing, which focus elite research teams on high-priority infrastructure like operating systems and browsers.

OASIS instead scales through volunteer AppSec crowds to cover the long tail of libraries and applications enterprises actually run, an approach David Kosorok, Director of Product Security at ACV Auctions, called the highest-leverage work in application security, since one validated upstream fix can secure thousands of downstream applications simultaneously, bolstering defense against offensive vulnerability discovery tool automation.

Participation is open through several roles, including vulnerability validators, repo community managers, maintainer liaisons, and automation operators, making OASIS a vendor-neutral entry point for security practitioners wanting to help fix, not just find, the vulnerabilities threatening the open source software that powers modern infrastructure.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago