Surf AI Joins Chainguard’s Athena Coalition

Prasad Raman|

AI is changing the economics for attackers. Frontier models can now find zero-days in widely used software and weaponize them far faster than defenders are used to, and the window between discovery and exploitation keeps shrinking.

This era requires enterprises to put more of their focus on basic security hygiene. Many security teams have ignored a large portion of their backlog, betting that no adversary would spend the time and money discovering and exploiting an obscure flaw. Security by obscurity worked for a long time, but it doesn't hold up when an AI model can do the digging for an attacker. The organizations that stay secure will be the ones that proactively improve their security hygiene and continuously minimize their attack surface.

Today we're announcing that Chainguard has invited Surf AI to join Athena, the industry coalition defending open source software against AI-driven attacks. Our role is to help member enterprises put Athena's work into practice: identifying who owns each affected asset, understanding what a change will touch, and moving the fix through to completion inside real environments.

What is Athena

Athena is a coalition that brings pre-disclosure vulnerability findings from across the industry into a shared clearinghouse. The findings come from frontier AI models, and many are zero-days in open source software that enterprises rely on every day.

Chainguard rebuilds the affected code as a private, hardened version ahead of disclosure, reconciles each fix against upstream throughout the embargo, and layers independent network, platform, and vendor mitigations around it so members stay covered even where a patch can't be deployed right away.

The coalition is already operating at real scale: more than 21,175 validated zero days with more than two dozen members across banking, cloud, networking, and software supply chain security. Each member brings something the others don't, and that's what makes the model work.

Why Surf AI joined

Athena gives members something rare: validated findings and hardened fixes before a flaw is public. The next step happens inside each organization's own environment, and that's where Surf comes in.

In a large enterprise, applying a fix means answering a string of practical questions. Which team owns the affected component? Where else does it run? Does changing it touch a compliance boundary? Who is on call to do the work, and does it need to go through a change board? When those answers live across a dozen systems and have to be pieced together by hand.

AI-driven threats make this harder in two ways. Serious findings arrive faster than teams can triage them by hand, and many of these flaws are fixed upstream without ever getting a CVE, so they don't show up in workflows built around CVE and NVD data.

Surf was built for exactly this. Our Context Graph, a continuously updated map of every entity, relationship, ownership assignment, and policy in an environment, gives teams the context they need to act on a fix as soon as it's available. Joining Athena lets us help enterprises put the coalition's work into practice: identifying who owns each affected asset, understanding what a change will touch, and seeing the fix through to completion.

What customers get

For enterprises running Surf, every Athena finding comes with the context to act on it: who owns it, what it touches, and how it gets approved. Surf then carries the fix through to closed using the workflows teams already have.

That adds up to:

  • A head start. For coalition members, the groundwork can happen while a flaw is still under embargo, so disclosure day starts with the fix already in motion.
  • Visibility into silent fixes. Upstream fixes that never receive a CVE get handled like any other finding.
  • Fixes that don't break things. Teams know what a change will affect before it goes in.
  • A cleaner backlog. Findings move all the way to closed, even as the volume grows.

Want to see how Surf AI turns Athena findings into closed remediation inside your environment? Talk to us.

Prasad Raman is Head of Technology Partnerships at Surf AI, with a decade of experience building alliance and partnership programs across the security industry.

Logo

Ready to operationalize your security?