Aikido Acquires Root to Combat Supply Chain Vulnerabilities
Article Content
- •Aikido Security acquired Root to enhance supply chain security for open-source software.
- •AI agents will automate the generation of patches for vulnerabilities without requiring upgrades.
- •Nearly a third of known vulnerabilities are exploited on or before their disclosure date.
On June 30, 2026, Aikido Security announced its acquisition of Root, a startup specializing in automated vulnerability remediation for open-source software. This acquisition aims to enhance supply chain security as open-source components have become primary targets for attackers. The integration will leverage AI agents to generate patches for known vulnerabilities without requiring teams to upgrade their existing systems. Aikido's new offerings, Aikido Libraries and Aikido Images, will provide drop-in replacements that patch software without breaking changes. The urgency of this acquisition is underscored by the fact that nearly a third of known vulnerabilities are exploited on or before their disclosure date. The Log4Shell vulnerability, discovered in 2021, remains prevalent in many production systems. Aikido and Root's collaboration aims to backport critical fixes to the community, addressing the overwhelming security workload faced by open-source maintainers. This initiative is positioned as a significant step towards securing the software supply chain against increasingly sophisticated AI-driven attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Continue Reading
New CVE Exploits Affect DedeCMS with Remote Code Execution Vulnerability A newly discovered vulnerability in DedeCMS (CVE-2026-XXXX) allows for remote code execution through the 'dede/update_guide.php' script. The vulnerability has a CVSS score of 7.2/8.8 and was disclosed on September 25, 2026. The affected version is DedeCMS V5.7.118, and the advisory includes non-weaponized…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…