Skip to Content

Aikido acquires Root to bolster open-source security efforts

Aikido acquires Root to bolster open-source security efforts

Aikido acquires Root to bolster open-source security efforts

GHENT, Belgium—Aikido Security has acquired Root, a cybersecurity company focused on automated vulnerability remediation, in a move aimed at helping organizations address growing software supply chain risks and secure open-source code without requiring disruptive software upgrades. 

The acquisition brings Root's automated patching technology into Aikido's platform. The companies said the combined offering will help organizations remediate vulnerabilities in open-source software while avoiding compatibility issues that can arise when upgrading to newer software versions. 

Aikido Security"Open source needs patching, and it needs it fast," said Willem Delbare, co-founder and CEO of Aikido Security. "With Root, we fix what teams are actually running, generating hundreds of verified patches a day: no upgrades, no migrations, no breaking changes." 

The deal comes as software supply chain security remains a growing concern for organizations. Open-source software serves as a foundational component of modern applications, but attackers increasingly exploit vulnerabilities and compromise software packages to gain access to target environments. 

Aikido said organizations face a dual challenge: malicious actors embedding malware in open-source packages and known vulnerabilities remaining unpatched in production environments for extended periods. The company pointed to the continued presence of the Log4Shell vulnerability in systems years after its discovery as evidence of the industry's patching challenges. 

As part of the acquisition, Aikido is launching what it describes as an industry-first initiative to provide backported fixes for critical, actively exploited open-source vulnerabilities to the broader community across supported software ecosystems. The company said the approach is intended to help organizations apply security fixes without forcing major software migrations or upgrades. 

The technology will be offered through Aikido Libraries, a platform powered by Root's patching capabilities. According to the companies, the technology enables organizations to apply fixes directly to vulnerable software components while minimizing the risk of breaking existing applications. 

"The industry is still stuck on triage, taking a giant list of CVEs and arguing over which ones to fix first," said Ian Riopel, co-founder and CEO of Root. "We built Root to skip the argument and just fix the problem in place." 

The acquisition marks Aikido's latest expansion move. The company previously acquired AI code-review startup Trag and autonomous penetration-testing firms Allseek and Haicker in 2025.  

Financial terms of the transaction were not disclosed. 

Comments

To comment on this post, please log in to your account or set up an account now.