Qualys joins Chainguard's Athena security coalition
Wed, 22nd Jul 2026 (Today)
Qualys has joined Chainguard's Athena coalition. The open source security group has now processed more than 40,000 vulnerability findings.
Qualys joins new members Akamai, Black Duck, Cycode, JFrog, Morgan Stanley, Upwind and Zafran, alongside existing participants including BNY, Cisco, Cloudflare, JPMorganChase and PwC.
Athena is a collective effort to coordinate the handling of open source software vulnerabilities across multiple companies. The coalition pools findings, removes duplicates, develops fixes under embargo, adds mitigations before patches are widely available, and then passes durable fixes upstream to maintainers.
The latest figures offer an early indication of the scale of issues the group is handling. According to Chainguard, 42% of the vulnerabilities submitted so far are rated critical or high severity, while 86% are network reachable.
About 7% of the flaws affect software packages more than five years old, suggesting some long-established dependencies still contain weaknesses that had not previously been identified.
Growing Membership
Qualys's addition reflects a broader push by security vendors, software suppliers and financial institutions to work together on open source risk. The coalition's model relies on members contributing at different stages, from identifying vulnerabilities to building mitigations and helping users understand whether they are exposed.
Cybersecurity companies form the largest partner group in Athena, Chainguard said. Those partners receive a pre-disclosure feed so they can prepare mitigations at the network, endpoint and traffic layers before a clean patch is available or before customers can deploy one.
The process is also intended to address so-called silent vulnerabilities, where an issue is fixed upstream but never assigned a Common Vulnerabilities and Exposures identifier. Such cases can be missed by standard scanning tools that depend on published identifiers and public disclosures.
Dan Lorenc, Chief Executive Officer and Co-founder of Chainguard, set out the company's view of the threat environment.
"Frontier models are finding zero-days in open source faster than anyone can respond. The time from discovery to exploitation is now measured in hours, and no one company is going to get ahead of that alone. Athena proves that orchestrated defense works," said Lorenc.
He added: "The volume and severity of what Athena is already finding make clear just how much depends on getting this right. The more of the ecosystem that joins, the less room attackers have to operate."
Role for Qualys
Qualys said its role in the coalition will centre on validating how exploitable vulnerabilities are. That is a significant distinction in open source security, where the existence of a flaw does not always mean it can be readily used in a real-world attack.
"As consistent contributors to open-source vulnerability research and disclosure, Qualys welcomes the invitation to participate in Chainguard's Athena coalition and secure open-source software by safely validating the exploitability of vulnerabilities with our technology," said Dilip Bachwani, Chief Technology Officer of Qualys.
He added: "We believe creating a safer digital future is a shared industry responsibility. This builds on our ongoing work to help customers, partners and stakeholders prepare for a future where vulnerability discovery and remediation pressure move faster than ever."
Other new members also described the coalition as a way to shorten the time between discovery and defensive action. Akamai said the arrangement allows participants to develop protections before vulnerabilities are publicly disclosed, while JFrog linked the initiative to the increasing speed with which AI systems can find and combine software flaws.
"Defending digital infrastructure in the age of AI requires a rapid, unified response," said Boaz Gelbord, Chief Security Officer of Akamai. "Athena allows us to protect customers with pre-embargo hardened software and platform-level mitigations before vulnerabilities can be exploited."
Gal Marder, Chief Strategy Officer of JFrog, described the shift in starker terms.
"Frontier AI models are not only discovering thousands of zero-days, but also chaining vulnerabilities together to exploit existing ones at machine speed, collapsing the gap between discovery and exploitation from weeks to hours. In this new reality, the era of 'scan and hope' is definitively over. Attackers are actively weaponising the trusted models and agentic tools driving today's development," said Marder.
He added: "By joining Athena's orchestrated defense coalition, JFrog is committed to helping organisations bridge the dangerous gap between an AI-discovered vulnerability and remediation in production. We provide a single source of truth for all software assets, enabling fully automated updates of patched components at scale and governance of the entire remediation process for every binary component, using any packaging technology in any environment."
Upstream Fixes
Chainguard has also joined Akrites, a Linux Foundation effort focused on remediating and disclosing open source vulnerabilities upstream. Under that arrangement, Athena can hand over findings once a fix has been developed and shielded, with Akrites then handling disclosure through a shared Security Incident Response Team and a standard process for maintainers.
The structure is meant to reduce duplicated reports reaching maintainers and to provide a fallback for critical packages that have no active maintainer. In practice, this points to one of the long-running challenges in open source security: many widely used components are maintained by small teams or individual developers despite their broad use in commercial systems.
For Chainguard and its partners, the central argument is that open source risk can no longer be handled through isolated disclosures and patch cycles alone. The coalition's current figures show that a large share of the issues it receives are both severe and reachable over networks, with more than 40,000 findings already processed.