OWASP Launches OASIS to Fight AI-Powered Attacks With AI-Generated Security Fixes

OWASP has launched the Open Automated Security Initiative for Software (OASIS), a global program aimed at closing the gap between identifying vulnerabilities in open-source code and delivering usable fixes.

Announced August 26, 2026, in San Francisco, OASIS combines AI-generated patch candidates with validation by application security professionals.

The initiative is designed to give maintainers credible remediation starting points, rather than simply producing queues of scanner alerts, CVE notices, and machine-generated code.

OWASP Launches OASIS to Fight AI-Powered Attacks

OASIS recognizes automation can accelerate security work, but expert review must determine whether a proposed patch is correct, safe, maintainable, and appropriate for the affected project.

Open source components appear in roughly 98% of commercial codebases, according to the Black Duck 2026 Open Source Security and Risk Analysis Report.

However, maintainers routinely face a reality: scanning tools can identify flaws faster than small project teams can reproduce, prioritize, patch, test, and release corrections.

OASIS addresses that remediation bottleneck through a three-stage process. First, automated tooling scans widely used repositories and produces candidate code changes when vulnerabilities are identified.

The system is intended to propose a fix quickly, allowing reviewers to focus on verification, context, and risk rather than starting remediation efforts from scratch.

Second, a community of application security practitioners, supported by agents, reviews every candidate for correctness and security impact.

Validators can examine vulnerable and patched code, test behavior, identify remediation options, and reject changes that introduce regressions or conceal risk.

This human-in-the-loop stage is central to OASIS because a syntactically valid AI patch is not necessarily safe. Following review, vetted patches are submitted upstream to project maintainers.

Maintainers retain authority over acceptance and release decisions, but receive an implementation they can adapt to conventions, versions, constraints, and testing requirements. The approach aims to reduce cycles to minutes.

The initiative arrives as attackers apply generative AI to reconnaissance, analysis, vulnerability discovery, and exploit development.

OWASP stated that AI-enabled activity, called vibe hacking, can shorten the time between identifying a weakness and attempting to exploit it. Defenders need not only detection but also faster, reliable remediation.

James Wickett, executive officer of DryRun Security, said generative AI can accelerate defense when validation and community expertise are applied.

Chris Holt, Strategic Engagement and Community Architect at Intigriti, said open source vulnerabilities represent a systemic risk because the ecosystem underpins much of the information economy.

OASIS provides a framework for AppSec practitioners and maintainers to respond. OASIS complements enterprise projects, including OpenAI’s Patch the Planet, the Linux Foundation’s Akrites, and Anthropic’s Project Glasswing.

Those efforts focus expertise on infrastructure such as operating systems and browsers. OASIS instead seeks to scale through volunteer AppSec participation, reaching the long tail of libraries and applications that organizations actually deploy.

David Kosorok, Director of Product Security at ACV Auctions, described validated upstream remediation as high-leverage work because one accepted fix can protect thousands of downstream users.

Early sign-ups have drawn hundreds of security professionals. Participation is open to vulnerability validators, repository community managers, maintainer liaisons, and automation operators.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories