
Work Here?
Work Here?
Work Here?
The Linux Foundation provides a neutral home and shared infrastructure to support open source projects, handling governance, legal, marketing, and organizational tasks so developers can focus on coding. It hosts and supports thousands of projects—such as Kubernetes, Hyperledger, and RISC-V—by offering governance, developer enablement, training and certification, and ecosystem development, along with events and research. It differentiates itself by acting as a non-profit, member-funded hub that does not compete with projects for licensing or development work, instead coordinating collaboration among developers, users, and industry partners. Its goal is to speed up open technology development and its commercial adoption through coordinated collaboration and shared investments in open standards and ecosystems.
Industries
Data & Analytics
Consulting
Enterprise Software
Education
Company Size
1,001-5,000
Company Stage
Grant
Total Funding
$12.5M
Headquarters
San Francisco, California
Founded
2007
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$12.5M
Above
Industry Average
Funded Over
1 Rounds
Health Insurance
Unlimited Paid Time Off
Remote Work Options
401(k) Company Match
CertiK partners with Linux Foundation's Decentralized Trust on blockchain security. * C. Monasterio * Published: September 24, 2026 * 6:01 pm * Updated: September 24, 2026 * 6:01 pm Table of Contents Web3 cybersecurity and audit firm CertiK joins LF Decentralized Trust (LFDT), the Linux Foundation's open-source initiative focused on decentralized ecosystems. Ronghui Gu, CEO and co-founder of CertiK, and Daniela Barbosa, executive director of LFDT, stated that the company will contribute technical research, formal verification, and audit expertise directly to the institutional-grade decentralized projects and infrastructure managed by the foundation. This collaboration reflects a tightening global regulatory landscape where anti-money laundering (AML) controls and smart contract audits have become essential requirements for operating with digital assets. By integrating into LFDT's working groups - which encompass initiatives like the Ethereum Besu client and collaborate alongside traditional financial and tech institutions - CertiK shifts vulnerability prevention from early design stages straight into the core architecture of enterprise decentralized technology. Through this strategic addition, they aim to ensure that finance, banking networks, and supply chains run on fully audited code that remains resilient against cyber threats. Disclaimer: Crypto Economy Flash News stories are prepared from official and public sources verified by its editorial team. Their purpose is to provide prompt reporting on relevant developments across the crypto and blockchain ecosystem. This information does not constitute financial advice or investment recommendations. Crypto Economy recommend always verifying each project's official channels before making related decisions.
OpenSearch Software Foundation and Linux Foundation Research report finds organizations seek neutral Data Infrastructure as global AI implementation peaks. Sep 22, 2026, 12:00 ET 83% of organizations run AI workloads, driving demand for interoperable, cost-efficient data platforms * The OpenSearch Software Foundation and Linux Foundation Research released The 2026 Open Data Infrastructure Report, examining how organizations scale AI implementation while navigating data governance, vendor independence and infrastructure costs. * Key findings show that 83% of organizations run or plan to run AI workloads, with 71% prioritizing vendor neutral infrastructure. * Research found 77% of organizations see OpenSearch as core or significant in their AI processes. SAN JOSE, Calif., Sept. 22, 2026 /PRNewswire/ - The OpenSearch Software Foundation, the neutral home for the OpenSearch Project, today released The 2026 Open Data Infrastructure Report: AI, Governance, and OpenSearch Adoption Trends, created in partnership with Linux Foundation Research. Key findings show that AI workloads, now ubiquitous across global organizations, require a neutral, interoperable, unified data platform to ensure data control, cost efficiency, and operational security. This shift helped drive a nearly 2x increase in OpenSearch adoption as it evolved into a foundational data layer for AI infrastructure. "This research confirms what we're hearing directly from the community," said Bianca Lewis, executive director of the OpenSearch Software Foundation. "As organizations expand AI efforts, they are worried about the risk of proprietary lock-in, and they need a neutral, open platform they can control. "That's why enterprises are shifting to an open model - enabling cost predictability, data sovereignty, and long-term stability." AI Workloads Drive Widespread Infrastructure Demand The adoption of AI is pervasive, and the underlying data platforms that search, index, retrieve, and monitor information have become just as central to success as the models and algorithms themselves. As organizations rapidly scale these systems, recent benchmark data highlights the operational shift required to support full-scale enterprise deployment. The report found: * 83% of organizations run or plan to run AI workloads, reaching more than 90% among large enterprises. * Generative AI and LLM-powered applications are the leading data infrastructure use case (82%). * Hybrid search - combining keyword and semantic search - is the preferred retrieval approach for 68% of organizations to enable AI relevance. Infrastructure Adoption Relies on Cost Overhead and Vendor Independence Research confirms that data infrastructure - the search, analytics, observability, and related platforms and tools organizations rely on to collect, store, manage, process, and extract value from their data - is a strategic priority for leaders. Selecting a data platform to run AI requires a major investment of time and resources, which can impact business success for years to come. Vendor independence, data ownership, interoperability, and cost are critical factors in IT leaders' decision making. The report found: * 78% of organizations say cross-vendor, cross-tool interoperability is critical when evaluating data infrastructure, enabling flexibility as the ecosystem evolves. * 71% of organizations agree that deploying infrastructure independently of a specific vendor or cloud provider is a strategic priority. * Total cost of ownership (80%) and security and compliance (79%) top the list of needs for a data infrastructure platform. * 80% of organizations would consolidate to fewer platforms if it meaningfully reduced costs, and 44% prefer one core platform with specialized tools. Beyond Search: OpenSearch as Core AI Infrastructure OpenSearch has evolved, and the community is taking notice. At the five-year anniversary of the project, search and retrieval is the number one use case (91%), but research demonstrated the breadth and depth of platform use, with use cases like log analytics and observability reaching 83% and real-time analytics at 70%. The increasing importance of unified observability and search capabilities is driving expanded adoption and awareness of the platform. The report found: * OpenSearch awareness jumped to 89% in 2026, up from 68% in 2024. * 77% of organizations see OpenSearch as a core or supporting component of their AI infrastructure. * 62% of respondents already use OpenSearch in AI workloads. OpenSearch provides the infrastructure layer that grounds AI applications in an organization's own data and the observability layer that keeps AI-powered systems running reliably in production. Explore all findings in The 2026 Open Data Infrastructure Report: AI, Governance, and OpenSearch Adoption Trends here. Insights from OpenSearch in Production "Our use of data infrastructure technology dates back over ten years to early versions of our primary data platform. When licensing changes disrupted that ecosystem, we transitioned first to an intermediate distribution and eventually moved directly to OpenSearch. Today, we use the technology very heavily across multiple major areas, including global anti-money laundering, public security, and anti-fraud solutions." - Terry Quigley, Principal Software Developer, SAS "Handling highly sensitive data under a consent framework requires extreme customizability to maintain strict privacy promises. While commercial solutions often violate those privacy bounds, OpenSearch provides a customizable framework that allows organizations to maintain aggregate data layers while upholding user trust." - Art Abal, Managing Director, Vana Foundation About Linux Foundation Research Founded in 2021, Linux Foundation Research explores the growing scale of open source collaboration, providing insight into emerging technology trends, best practices, and the global impact of open source projects. By leveraging project databases and networks and committing to best practices in quantitative and qualitative methodologies, Linux Foundation Research is creating the go-to library for open source insights for the benefit of organizations worldwide. About the OpenSearch Software Foundation The OpenSearch Software Foundation is a vendor-neutral community for search, analytics, observability, and vector database software. Hosted by the Linux Foundation and supported by premier members such as AWS, IBM, SAP and Uber, the OpenSearch Software Foundation works with community maintainers, developers, and member organizations to drive the continued growth of the OpenSearch project. With more than 2 billion software downloads since its inception and participation from thousands of contributors, the OpenSearch project and its community are transforming how information is managed and discovered. To learn more, please visit https://opensearch.org/foundation. The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see its trademark usage page: www.linuxfoundation.org/trademark-usage. Linux is a registered trademark of Linus Torvalds. SOURCE OpenSearch Software Foundation
Xbox's digital ownership and AI verification in healthcare. Published By: Antonio Robles Robles.AI Build AI That Earns Trust. AI Assistant: Sophia Pulse Healing with data-driven compassion. September 17, 2026 at 08:00 AM PDT technology artificial intelligence gaming Table of contents. Xbox's journey to digital ownership. Microsoft recently introduced a disc-to-digital feature for Xbox, a concept that has been in development for 15 years. This feature allows users to convert their physical Xbox One discs into digital copies, utilizing unique serial numbers embedded in the discs since 2013. This move aligns with Microsoft's long-standing goal of game preservation and digital ownership. As Sony plans to phase out PlayStation discs by 2028, Microsoft's foresight positions it well in the digital era. The technical foundation of this feature lies in the unique identification of discs, a method conceived in 2011. This identification enables the digital conversion, showcasing Microsoft's commitment to digital game sharing and preservation, evident in their Project Helix initiative. Project Helix aims to ensure compatibility with all Xbox games, furthering the digital era's reach. This initiative has significant implications for the gaming industry. With the growing trend towards digital purchases, evidenced by Sony and Microsoft's digital-only consoles, disc-to-digital is a strategic move. Microsoft's focus on game preservation and backward compatibility strengthens its market position, catering to both digital and nostalgic gamers. From my perspective, this shift towards digital ownership reflects broader technological trends. As physical media becomes obsolete across various sectors, Microsoft's approach could set a precedent for digital preservation, a crucial aspect as gaming evolves into an entirely digital landscape. Advanced AI Society's open verification ecosystem. The Advanced AI Society has launched an open verification ecosystem in collaboration with the Linux Foundation, responding to legislative demands for verifiable AI agent controls. This initiative introduces the Proof-of-Control v1.0 draft, allowing third-party verification of AI agents' actions. The goal is to address the verifiability gap as AI agents operate faster than human oversight can handle. Technically, the Proof-of-Control standard relies on production-proven verifiable AI technologies, ensuring agent actions are auditable across their lifecycle. This standard requires agents to define their authority pre-execution and produce evidence of compliance, thus enabling open verification without reliance on operator claims. The implications for the AI industry are profound. As AI becomes more autonomous, ensuring transparency and accountability is paramount. This standard could become a benchmark, fostering trust in AI applications across various sectors, from healthcare to financial services. In my view, this move towards open verification signifies a shift in AI governance. By decentralizing trust and making AI actions auditable, the industry can address public concerns about AI's unchecked capabilities. This initiative could lead to more robust AI integration in critical sectors, ensuring safety and accountability. The rise of Autonomous Racing. Autonomous racing is gaining traction globally, with recent events showcasing driverless cars on renowned tracks. The Indy Autonomous Challenge and Abu Dhabi Autonomous Racing League have highlighted the technological advancements in AI-driven racing. These races test the AI's ability to manage speed and make real-time decisions, a significant leap from previous solo time trials. The technology behind autonomous racing involves AI algorithms capable of real-time decision-making, steering, and braking at high speeds. Teams like Purdue AI Racing and Team Kinetiz utilize identical hardware, focusing on software development to gain a competitive edge. The races demonstrate AI's capability to handle complex scenarios, such as sudden speed changes and collisions. The implications for the racing industry are notable. While fans traditionally connect with drivers, autonomous racing shifts focus to the engineering teams behind the AI. This could attract a new audience interested in the technological prowess rather than individual drivers. Personally, I see autonomous racing as a testbed for broader AI applications. The challenges faced in racing, such as rapid decision-making and handling unpredictability, mirror those in other sectors like autonomous vehicles on public roads. The advancements here could accelerate AI's integration into everyday life, enhancing safety and efficiency. Meta's ai-driven marketing revolution. Meta is reshaping digital marketing with its AI-driven tools, enhancing ad placements and creative generation. The recent changes include removing manual placement exclusions, pushing advertisers towards Advantage+ Placements, which optimize delivery using Meta's algorithms. The Andromeda algorithm, part of this evolution, emphasizes high-quality content, rewarding ads with positive engagement. Meta's AI tools, including the RAG plugin, allow real-time data retrieval and creative generation, creating a more effective advertising strategy. The AI-enhanced pixel further supports this by automatically gathering product data for better audience targeting, streamlining the ad experience for consumers. These advancements have significant implications for marketers. By leveraging AI, advertisers can achieve more precise targeting and improved ROI, particularly in competitive sectors like e-commerce. Meta's approach could redefine digital marketing strategies, setting a new standard for AI integration in advertising. In my opinion, Meta's focus on AI-driven marketing reflects a broader trend towards automation in advertising. As AI continues to evolve, the ability to deliver personalized and effective marketing campaigns will become increasingly crucial, offering businesses a competitive edge in the digital landscape. Thermo Fisher's ai-driven growth. Thermo Fisher Scientific is experiencing robust growth, driven by increased demand in pharma and biotech sectors. In 2026, the company reported a 5% organic growth in the second quarter, with adjusted earnings per share rising by 13%. CEO Marc Casper highlighted AI's role in enhancing drug development returns, contributing to the company's optimistic outlook. The company's growth is supported by its focus on bioproduction and personalized mRNA cancer vaccines, areas bolstered by AI technologies. Thermo Fisher's strategic acquisitions, like Clario, enhance its clinical trial capabilities, integrating AI to streamline processes and improve outcomes. The implications for the healthcare industry are significant. Thermo Fisher's growth highlights the increasing reliance on AI to drive innovation and efficiency in drug development and clinical research. As AI becomes more integrated into healthcare, companies like Thermo Fisher are well-positioned to lead the industry's transformation. From my perspective, Thermo Fisher's success underscores the potential of AI in healthcare. By leveraging AI to enhance research and development, the company sets a precedent for others in the industry, highlighting the transformative power of technology in improving healthcare outcomes and operational efficiency. Where Robles.AI fits. At Robles.AI, Robles.AI is closely aligned with the advancements in AI verification and digital ownership as highlighted in these developments. Its expertise in AI transparency and accountability complements the initiatives by the Advanced AI Society, ensuring that its solutions meet the highest standards of verifiability and trust. In the realm of healthcare, its AI-driven analytics and decision support tools are designed to enhance clinical outcomes, aligning with the innovations seen in Thermo Fisher's AI applications. By integrating advanced algorithms, Robles.AI aim to streamline healthcare processes and improve patient care. As digital transformation accelerates, Robles.AI remains committed to providing cutting-edge solutions that empower businesses and industries to harness the full potential of AI technologies, ensuring a future where AI-driven insights lead to meaningful and sustainable advancements. #Xbox #AIverification #autonomousracing #digitalownership #healthcareAI Sources. Tokens used: Prompt 13646, Completion 4038, Total 17684
How to study for the MCPA security and governance domain. Security and governance is 24% of the new Model Context Protocol Associate exam. Here is what each competency actually covers in the 2026-07-28 spec, and the distinctions candidates get wrong. Maria Paktiti September 16, 2026 Explore with AI The Agentic AI Foundation and Linux Foundation Education launched the Model Context Protocol Associate (MCPA) on September 14, 2026. It is the first official certification for MCP, it is vendor neutral, and it is built against the 2026-07-28 specification. Look at how the exam is weighted and one thing stands out: | Domain | Weight | | Interactions and execution | 26% | | Security and governance | 24% | | Use cases and ecosystem | 20% | | MCP fundamentals | 16% | | Architecture and components | 14% | Security and governance is the second heaviest domain. Almost a quarter of a foundational protocol exam is about trust boundaries, permissions, consent, and audit, and the listed prerequisites include OAuth 2.1 and token handling. That is a fair signal about where the difficulty in production MCP actually lives. The official blueprint breaks the domain into four competencies. Here is what each one covers, plus the distinction that trips people up. Trust boundaries. A trust boundary is any point where data or instructions cross from one party's control into another's. In MCP there are more of these than people expect: between the user and the host application, between the host and the client, between the client and the server, and between the server and whatever upstream API it wraps. The rule that matters most is that a token issued for one boundary is not valid at the next one. Access tokens are audience bound to a single MCP server, the server validates that a token was issued for it, and the server must not forward the token it received to an upstream API. Forwarding is catalogued in the spec as an anti pattern, not a shortcut, because it launders the audience and destroys any ability to say which party actually acted. When the server needs to call an upstream API, it exchanges for a new credential of its own rather than replaying the client's. Commonly missed: candidates treat "the token is valid" as the security question. The exam cares whether the token was issued for this server. A structurally valid token with the wrong audience must be rejected. Permissions and consent. The thing to internalize is that consent and authorization happen at different times, and the gap between them is the whole problem. A user approves a scope set once, at connection time, on a consent screen, for a category of actions. The agent then discovers tools dynamically and decides which to call, possibly hours later, possibly ones the user never pictured when they clicked approve. So "access to the MCP server" is not a useful permission. Scopes have to be per tool, and the permission check has to run at invocation, not just at connection. Two related ideas worth knowing cold: * Least privilege for agents. An agent's effective permissions should be the intersection of its own grant and the authority of whoever delegated to it. An agent should not inherit an admin's full rights just because an admin installed it. * Delegation is explicit. On behalf of flows name both parties, the human subject and the acting agent, so the delegation chain survives every hop. Commonly missed: scope step up and authentication step up are different operations. Asking for more scope is not the same as re-verifying who the user is, and conflating them is a real vulnerability rather than a wording quibble. Risk and safety controls. This competency covers what constrains an agent once it is already authorized: human in the loop approval, time limits, and the difference between advice and enforcement. The single most important distinction here is that tool annotations are hints, not security controls. Annotations describe intent, whether a tool is read only, destructive, or idempotent, so a host can decide how to present it. They are declared by the server and are not verified by anything. A client that skips a confirmation because a tool claimed to be read only has trusted an unenforced assertion. Annotations belong in the user experience layer; enforcement belongs in the authorization layer. Session scoped authorization is the other pattern to know: access that is time boxed to a task, that ends when the task ends, and that the agent cannot renew on its own. Commonly missed: the STDIO carve out. Implementations using a STDIO transport should not follow the authorization specification at all, and should instead take credentials from the environment. The OAuth machinery is for remote servers over HTTP. Expect at least one question that hinges on knowing authorization requirements are transport dependent. Auditability and observability. The 2026-07-28 revision made the protocol core stateless. There is no initialize handshake and no protocol level session, so a remote MCP server is an ordinary HTTP workload that can sit behind a round robin load balancer. That is good for scaling, and it means identity has to travel with every request rather than being established once and remembered. For audit, the question to be able to answer is simple: after an agent acts, who appears in the destination system's log? If it is the human whose token got borrowed, the deployment has an attribution problem no amount of logging volume will fix. If it is the agent, with the authorizing human recorded alongside it, the chain is intact. Commonly missed: logging that an action happened is not auditability. Auditability is being able to reconstruct which agent acted, under whose authority, with what scope, and whether a human approved it. Do not skip the OAuth prerequisite. The prerequisites list "basic literacy in security concepts (API keys, OAuth 2.1 and token handling, authentication headers)," which undersells it. The authorization model in 2026-07-28 leans on a specific stack: OAuth 2.1 with PKCE, protected resource metadata for discovery, and resource indicators for audience binding. One change worth knowing because it is recent: Dynamic Client Registration is now formally deprecated in favor of Client ID Metadata Documents. DCR still works for backward compatibility and will be removed in a future revision. A question written against the current spec may well present DCR as the outdated option. Exam logistics. | Format | Online, proctored, multiple choice | | Duration | 90 minutes | | Price | $250, exam only | | Level | Beginner, no prerequisites required | | Validity | 2 years | | Included | 12 month exam eligibility, one retake | | Spec version | 2026-07-28 | Attendees of AGNTCon and MCPCon events can enroll at a 20% discount. What to read. Read the 2026-07-28 specification directly, and the authorization section twice. It is the exam's stated source of truth, and it is short enough to work through in an afternoon. For the security domain specifically, the concepts above map onto patterns you can read about in more depth: MCP authorization in five OAuth specs for the standards stack, per-tool scopes, consent, and least privilege for the permissions model, scope step up versus authentication step up for the distinction above, and the security risks specific to MCP servers for the threat model. Passing the exam and shipping a server that survives an audit are different achievements. If you are doing the second one, AuthKit handles MCP authorization with CIMD registration, audience bound tokens, and on behalf of exchange, so the parts the exam spends 24% of its questions on are configuration rather than code you maintain.
Linux Foundation introduces TRACE standard for AI runtime evidence. 2026-08-26 11:08 This new open standard offers hardware-attested runtime and compliance evidence for AI agents Read the original article: The Linux Foundation announced the contribution of TRACE (Trust, Runtime Attestation and Compliance Evidence), from OPAQUE. Collaboratively developed by... Hacking & Cracking August 26, 2026 TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. August 25, 2026 4 posts published in the last hour06:02Production data in testing is still common, and Tricentis' CISO wants it gone 06:02Hackers Hide Malware Inside Plain English Words to Infect Windows Users With Amatera Stealer 06:02Linux Foundation takes on TRACE, a hardware-backed runtime evidence specification for AI agents 06:00IT Security News Hourly... August 26, 2026 In "hourly summary"
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Consulting
Enterprise Software
Education
Company Size
1,001-5,000
Company Stage
Grant
Total Funding
$12.5M
Headquarters
San Francisco, California
Founded
2007
Find jobs on Simplify and start your career today