
TL;DR
Open source software often requires users to upgrade to newer versions to receive security fixes, which can be disruptive. Aikido Security has acquired Root to integrate its patching technology into a new product called Aikido Libraries, allowing for backporting of critical fixes directly into existing versions.
✦ Why It Matters
Engineers can now maintain their current software versions while receiving critical security updates seamlessly.
Key Takeaways
Full Summary
Aikido Security, a developer-focused cybersecurity platform, has acquired Root, a company specializing in patching known vulnerabilities in open source software without requiring users to upgrade to newer versions. The $70 million acquisition integrates Root's technology into Aikido Libraries, which will offer free backporting of fixes for critical vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalog.
This commitment addresses urgent flaws that are actively exploited, while Aikido's existing paid products will cover a broader range of vulnerabilities. Aikido, which achieved unicorn status in January 2023, aims to streamline the process of finding and fixing vulnerabilities in the software supply chain.
The acquisition comes at a time when AI is rapidly changing the landscape of cybersecurity, making it easier to identify and exploit weaknesses in open source code. Aikido emphasizes that the same technology used for patching will be human-verified before deployment to ensure security.
Related