Asia Tech Times — Technology, science and culture across Asia

Technology, science and culture across Asia

Tech

Chainguard Named a CVE Numbering Authority

The authorization covers qualifying open source vulnerabilities processed through the company's Athena coalition.

Chainguard Named a CVE Numbering Authority

Chainguard has been authorized by the CVE Program as a CVE Numbering Authority, the company said. As a CNA, Chainguard can assign CVE identifiers and publish CVE Records for qualifying vulnerabilities. The authorization is limited to open source vulnerabilities processed through the Athena coalition, in cases where upstream maintainers have already fixed a flaw without an identifier, no maintainer remains to assign one, or no more specific CNA covers the project. The CVE Program exists to identify, define and catalog publicly disclosed cybersecurity vulnerabilities, according to Chainguard.

Quincy Castro, Chainguard's chief information security officer, said AI-driven zero-day discovery is pushing traditional approaches to vulnerability handling and disclosure to the breaking point. He said Athena is working to get fixes as quickly as possible into as many hands as possible, and that becoming a CNA lets the company communicate about vulnerability fixes in a "language" familiar to many organizations and open source maintainers.

The designation strengthens Athena, which Chainguard describes as an industry coalition for the orchestrated defense of open source software, by supplying precise affected and fixed version ranges and technical details that help organizations assess their exposure, reduce false positives and take action. Chainguard said its CVE Records defer to maintainers and project-specific CNAs wherever those exist. Coalition members and mitigation partners named by the company include Akamai, BNY, Cisco, Cloudflare, JPMorganChase, Kyndryl, Morgan Stanley and Upwind, which help validate AI-discovered vulnerabilities and develop fixes; Athena then works with Akrites to carry vulnerabilities through disclosure and toward durable upstream remediation.

Chainguard said frontier AI models are surfacing latent vulnerabilities in widely used open source software that traditional security tools and years of expert review failed to detect. As AI compresses the time between discovery and exploitation, flaws without CVE identifiers may remain invisible to the scanners, databases and compliance systems organizations rely on to identify and prioritize risk, the company said.