Securing the software supply chain requires more than just patching code; it requires visibility into where that code actually resides within complex enterprise environments. Manifest Cyber is joining Athena, the Chainguard-led industry coalition for orchestrated open-source defense, to provide this visibility. By integrating its illumination capabilities, Manifest aims to help coalition members—including JPMorganChase, Morgan Stanley, and Cisco—rapidly identify the "blast radius" of new vulnerabilities across internal systems, third-party products, and binaries.
Manifest Integrates Supply Chain Illumination into Athena
Manifest is positioning its technology to bridge a critical gap in vulnerability management: identifying risk within software where source code is unavailable. While the Athena coalition focuses on gathering vulnerability findings and building hardened fixes under embargo, Manifest provides the diagnostic layer. The company intends to use binary analysis to inspect shipped commercial software, identifying open-source components and third-party dependencies even when no source code is provided.
This capability is designed to support Athena’s workflow, which reported processing over 40,000 findings in its first three weeks, with 42% categorized as critical or high severity. Manifest will also provide "reachability" analysis, determining if an application actually calls vulnerable code. This allows members to prioritize real exposure during embargo periods. Additionally, Manifest will offer continuous monitoring of third-party software and flag risks related to foreign ownership, control, and influence among open-source contributors.
Addressing Vulnerabilities in Critical Infrastructure
The strategic value of this partnership lies in protecting hardware and systems that cannot be easily rebuilt or patched. In sectors like healthcare or utilities, vulnerabilities often reside in medical devices or industrial controllers that lack a software bill of materials (SBOM). For these assets, traditional rebuilding is impossible, necessitating isolation or compensating controls.
Manifest’s involvement aims to facilitate these responses by identifying exactly which products carry a specific vulnerable component. By providing continuous rechecks of supplier software as new findings emerge, the platform moves beyond the static, point-in-time reviews common in many third-party risk programs. This approach seeks to provide a layer of defense for critical technologies, including network hardware and automotive systems, where the software supply chain is often opaque and difficult to manage through standard developer workflows.
Key Takeaways
- Manifest joins the Athena coalition, which includes members such as Cloudflare, Akamai, and PwC.
- The Athena coalition processed more than 40,000 findings in its first three weeks, 42% of which were critical or high severity.
- Manifest will provide binary analysis to identify dependencies in commercial software lacking available source code.
TechInsyte's Take
In our view, Manifest’s entry into the Athena coalition signals a shift from reactive patching to proactive supply chain mapping. While Chainguard and its partners focus on the "fix," Manifest is addressing the "where." This is a vital distinction for enterprise leaders managing legacy infrastructure or proprietary third-party hardware. By focusing on reachability and binary analysis, Manifest is attempting to solve the "noise" problem in vulnerability management, ensuring security teams do not waste resources on non-exploitable code. This orchestrated approach—combining rapid discovery, hardened fixes, and deep visibility—is a necessary evolution to counter the speed of AI-powered software attacks.
Questions & Answers
How does Manifest address vulnerabilities in software without source code?
Manifest utilizes binary analysis to inspect shipped commercial software. This allows the platform to report the open-source components and third-party dependencies contained within a product, even when the original source code is unavailable to the user.
What is the primary goal of the Athena coalition's orchestrated defense?
Athena aims to coordinate the defense of open-source software by gathering vulnerability findings, building hardened fixes under embargo, and driving durable fixes upstream to ensure the entire ecosystem is protected.
How does Manifest help prioritize vulnerability response for enterprise members?
Manifest provides "reachability" reporting, which identifies whether an application actually calls the vulnerable code. This helps organizations focus their efforts on actual exposure rather than treating every new vulnerability record as an immediate priority.
What specific risk does Manifest flag regarding open-source contributors?
Manifest flags exposure related to foreign ownership, control, and influence (FOCI) across both open-source contributors and software suppliers, providing an additional layer of geopolitical risk assessment to the supply chain.
Source: Manifest