OpenAI launches program to fix vulnerabilities in open-source software

OpenAI announced the launch of the Patch the Planet program in collaboration with cybersecurity firm Trail of Bits, a leader in the field, as reported by Zamin.uz.
The main goal of this initiative is to identify and fix vulnerabilities in open-source software. Open-source components are now used in nearly all digital products.
Even a single small error can therefore threaten the security of millions of devices and thousands of companies worldwide. According to OpenAI data, the system has already successfully detected hundreds of security issues, with fixes implemented for dozens of projects.
As part of the Patch the Planet program, analysts are currently focusing on the Python and Go programming languages, network tools such as cURL and NATS Server, cryptographic libraries like Sigstore and pyca/cryptography, and server technologies including aiohttp and freenginx. These components perform critical tasks such as encrypting data, verifying software integrity, and ensuring network connectivity.
OpenAI specialists are using the Codex Security tool and advanced AI models to analyze code. Trail of Bits engineers then verify the errors identified by AI, filtering out false positives.
Cybersecurity experts emphasize that AI’s main advantage lies in its speed. Whereas discovering and patching vulnerabilities previously took weeks, the process can now be completed in just a few days.
However, human expertise remains essential. Specialists must assess the real risk level of detected flaws and confirm that fixes are secure.
In recent years, incidents such as Log4Shell and XZ Utils have demonstrated how damaging weaknesses in the software supply chain can be. Open-source projects are often maintained by volunteers, making technological support from large corporations like OpenAI especially valuable.
The new initiative aims not only to find bugs but also to transform the approach to cybersecurity. Companies are now expected to shift from periodic audits to continuous, real-time threat assessment systems.
The Patch the Planet project is considered an important step toward strengthening the resilience of the global digital ecosystem.





