Nvidia and Tech Giants Form AI Security Alliance

www.news4hackers.com-nvidia-and-tech-giants-form-ai-security-alliance-nvidia-and-tech-giants-form-ai-security-alliance

A coalition of tech firms launches the Open Secure AI Alliance to bolster AI security through open-source collaboration.

Introduction

Nvidia and a coalition of technology, cybersecurity, and enterprise software firms unveiled the Open Secure AI Alliance on Monday, an initiative focused on creating and sharing open source tools, models, and methodologies for securing artificial intelligence systems and agents. This effort expands upon prior work from the Linux Foundation’s Akrites project and the OpenSSF community.

Founding Members

Founding members of the alliance include Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, Microsoft, Naver, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, SK Telecom, ServiceNow, Siemens, Snowflake, SpaceXAI, Synopsys, Thinking Machines Lab, and TrendAI.

Key Contributions

Nvidia’s Involvement

Nvidia’s involvement includes releasing open models, data, and agent harness research, alongside a new open source project named NOOA. This tool aims to simplify the tracing, testing, and auditing of agent behavior.

HPE’s Contribution

HPE is contributing to SPIFFE/SPIRE, a zero-trust identity framework for verifying AI agents and services through cryptographic means.

Hugging Face’s Donation

Hugging Face is donating its Safetensors format for storing model weights to the PyTorch Foundation.

IBM and Red Hat’s Project

IBM and Red Hat are advancing open source supply chain security via the Lightwell project, which provides automated vulnerability remediation at scale.

Microsoft’s MDASH

Microsoft is offering MDASH, a multi-model agentic scanning harness that coordinates AI agents to identify, debate, and validate software vulnerabilities.

SpaceXAI’s Open-Sourcing

SpaceXAI is open-sourcing its Grok Build terminal-based AI coding agent, with plans to expand its use.

Alliance’s Stance on Openness

The alliance emphasizes that open models, harnesses, and security tools should be viewed as defensive assets rather than risks. It warns that restrictive policies on open frontier AI could undermine collective cybersecurity efforts. The group references a recent security incident involving OpenAI and Hugging Face, where closed AI tools failed to distinguish attackers from defenders, blocking forensic analysis. Hugging Face mitigated the breach by using its open-weight GLM 5.2 model to review over 17,000 actions.

Nvidia stated that the appropriate response is not to limit access to open systems but to combine openness with robust safeguards, clear rules against misuse, thorough evaluation, and swift remediation. It argued that cybersecurity requires both closed and open frontier models to allow defenders to select the most suitable tools while ensuring transparency, adaptability, and control.

Recent Security Incidents

Other developments highlighted include a data breach affecting 1.2 million individuals, patches for code execution flaws in Arena Simulation Software, a confirmed breach at Australian energy company Origin, and a credential stuffing attack on Chick-fil-A accounts. Additional reports cover a nuclear-sabotage malware impacting AI models, a $13 million fraud loss due to a data breach, a zero-day vulnerability exploited in the wild, and warnings about Iranian hackers targeting industrial control systems.

Industry Updates

New security measures for GitHub and PyPI aim to strengthen supply chain security, while MedusaHVNC malware uses hidden Windows desktops to evade detection. Coca-Cola confirmed a data breach following a Fairlife ransomware attack, and a hacker-trapping platform raised $3.4 million. Research from Lookout identifies potential risks in mobile apps, and Anthropic’s Opus 5 trails behind Mythos 5 in exploit detection. Industry updates include leadership changes at Datavault AI, Everfox, and Sectigo, alongside expert analyses on patching strategies, identity verification failures, OT security challenges, business-aligned risk management, and AI-driven software audit practices. A newsletter offers insights into cybersecurity trends and threats.


Blog Image

About Author

en_USEnglish