
As OpenAI's latest AI model reportedly breached human control and launched an external cyberattack on its own, the global cybersecurity industry is shifting from isolated responses to collaborative defense against AI-driven threats. Security vendors are joining vulnerability research projects led by frontier AI companies while expanding partnerships to improve response speed and strengthen market competitiveness.
According to industry sources on July 23, Athena, an open-source collective defense initiative launched by U.S. security company ChainGuard on June 15, has expanded rapidly, adding eight new members this month after launching with about 20 organizations.
Athena includes security companies such as Qualys, Upwind and Zafran; networking and infrastructure providers including Cisco, Cloudflare and Akamai; software supply chain companies such as Docker and JFrog; and financial and professional services firms including BNY Mellon, JPMorgan Chase, Morgan Stanley and PwC.
While Anthropic's Project Glasswing and OpenAI's Daybreak primarily focused on sharing vulnerability information, Athena covers the entire vulnerability response process, from discovery and pre-disclosure protection to deployment in customer environments and final fixes to upstream open-source projects. Member organizations share newly discovered vulnerabilities identified through initiatives such as Project Glasswing and Daybreak while coordinating responses across their respective business areas.

Network and platform providers block malicious traffic at the network edge, security companies develop detection rules and virtual patches before official fixes become available, and ChainGuard distributes pre-patched private versions to alliance members. Professional services firms then help customers deploy those updates in production environments.
As of July 7, Athena had processed more than 40,000 vulnerabilities, producing more than 2,000 patches that have been applied to over 500 open-source projects.
The collaborative approach is spreading across major U.S. cybersecurity companies. CrowdStrike launched Project Quiltworks in April, expanding cooperation with OpenAI and Anthropic to include consulting, system integration and cybersecurity firms such as Accenture, EY, IBM and Kroll.
CrowdStrike evaluates the likelihood that newly discovered vulnerabilities will be exploited and their potential business impact to determine response priorities. Partner companies then help customers identify exposed vulnerabilities and remediate the most critical issues in their production environments.

Trend Micro is strengthening AI-era cybersecurity through the Zero Day Initiative (ZDI), a global bug bounty and vulnerability disclosure program with more than 19,000 researchers worldwide. The company invests tens of billions of won annually to identify third-party vulnerabilities proactively and provides virtual patches through network-based protections more than 90 days before official patches become available.
South Korea's government and industry have recently begun organizing a Korean version of Project Glasswing, but progress has been relatively slow. Industry officials say faster collaboration will be necessary to respond effectively to AI-driven cyber threats.
An industry official said the volume and speed of vulnerabilities identified by AI have surpassed the response capabilities of individual companies, adding that the ability to share information across a broad partner network and rapidly turn that intelligence into defensive actions will become a key factor in both corporate and national cybersecurity competitiveness.