OpenAI launches new initiative to help find and patch open source bugs | TechCrunch
The first StrictlyVC of 2026 hits SF on April 30. Tickets are going fast. [Register now.]($1)[Founder Summit]($1) ticket savings of up to $190 end June 26. Join 1,000+ founders and VCs for all-day boo...
The first StrictlyVC of 2026 hits SF on April 30. Tickets are going fast. Register now.Founder Summit ticket savings of up to $190 end June 26. Join 1,000+ founders and VCs for all-day bootcamp. **REGISTER NOW.**OpenAI announced a new initiative on Monday designed to help the open source community improve its cybersecurity game and ward off bugs.“Patch the Planet” (which is a not-so-subtle allusion to “Hack the Planet,” the iconic catchphrase from the 1995 movie “Hackers”) will see OpenAI team up with the security company Trail of Bits to help open source maintainers secure their projects.OpenAI said security staff from Trail of Bits will work directly with open source maintainers to review potential code issues. OpenAI’s security tools — like Codex Security — will be used to assist in the process.“Many maintainers are already being asked to sort through more reports, more quickly, with the same limited time and resources,” OpenAI said Monday. “Patch the Planet is built to reduce that burden, not add to it: security engineers review findings before they reach maintainers, work with projects to develop patches and tests, and build reusable workflows that help teams continue improving security after the first fixes land.” In other words, Trail of Bits engineers will function more or less like code EMTs — there to help open source project maintainers identify and triage potential issues, all supported by OpenAI’s software. It sounds like an ambitious project, and it’s somewhat unclear how it will function in the long term, or how it plans to scale up (if at all).Open source projects are the digital bedrock upon which the commercial software industry rests, but, unfortunately, due to the decentralized and poorly monitored structure of that ecosystem, much of the software is insecure. Bugs in open source projects can turn into major problems for commercial codebases. The log4j debacle from several years ago — when a bad vulnerability was discovered in a widely used open source utility — is a good example.Much of the concern surrounding tools like Mythos (Anthropic’s highly publicized security tool) seems to stem from the fact that AI can now automatically identify existing bugs within codebases and set about creating exploits for them. While the automation of cybercrime is not new, these tools undoubtedly have the potential to make it significantly more convenient for bad actors.OpenAI is turning that formula on its head by using AI to help the open source community better protect itself. It’s hard not to read it as a competitive swipe at Anthropic, while also recognizing that it’s something the open source community desperately needs.TopicsWhen you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence. Senior Writer, TechCrunch
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.
Savings end June 26, 11:59 p.m. PT. WhatsApp gets new chief as Meta taps India’s CRED founder Kunal Shah and invests $900M in startup]($1)
Every new iOS 27 feature that’s worth knowing about]($1)
Aura’s impressive e-ink photo frame doesn’t even look digital]($1)
The CEO of Allbirds’ new AI biz has a plan. Now she needs a “brand-new team”]($1)
The US says ASML’s top chip tool may be in China, but how?]($1)
The 11 standout startups from YC’s Demo Day, according to VCs]($1)
NASA picks Eric Schmidt’s rocket company for Mars mission, setting up a race with SpaceX]($1)
Related Articles
iOS 27 beta 2 is out now, here's what's new - Engadget
- [Big Tech]($1) - [Apple]($1) # iOS 27 beta 2 is out now, here's what's new Spoiler: It’s more Siri stuff. By [Anna Washenko]($1) June 22, 2026 4:16 pm EST ...
Meta is 'pausing' employee tracking program after it let the whole company see sensitive data - Engadget
- [Big Tech]($1) - [Meta]($1) # Meta is 'pausing' employee tracking program after it let the whole company see sensitive data This won’t make the already-controversial AI training endeavor ...
OpenAI's new Daybreak initiative will help open-source projects fend off bugs - Engadget
- [Cybersecurity]($1) # OpenAI's new Daybreak initiative will help open-source projects fend off bugs Patch the Planet will pair security researchers with open-source projects. ...
