Deliver Your News to the World

IBM and Red Hat Remediate More Than 400 Previously Unknown Open Source Vulnerabilities


RALEIGH, N.C. – WEBWIRE –
  • Fixes across widely-used Java libraries help address security gaps that AI agents could combine into attacks
  • Lightwell Clearinghouse is now generally available, giving businesses a direct path to request priority review and remediations for open source software

IBM (NYSE: IBM) and Red Hat today announced that Lightwell has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries. The companies also announced the general availability of Lightwell Clearinghouse, which allows enterprise customers to submit specific open source software dependencies for priority review and remediation.

The milestone addresses a growing business risk. As autonomous AI agents become capable of combining several lower-risk software weaknesses into a more serious attack, companies need to do more than identify vulnerabilities. They need a practical way to develop, test and deploy fixes in the software that supports critical applications.

Moving from finding vulnerabilities to remediating them

Many security tools can identify potential problems, but detection alone does not remove the risk. Organizations also need fixes that work with the software versions already running in production and can be introduced without disrupting business operations.

Through Lightwell, Red Hat and IBM have uncovered, remediated, and backported fixes for more than 400 previously unknown bugs in widely deployed, production-grade software. The work shows that even mature codebases require continued attention as threats evolve. Red Hat and IBM are focusing engineering resources on this foundational software to help reduce risk across enterprise systems.

How Lightwell works

Lightwell builds on IBM and Red Hat’s commitment to secure open source software for the AI era. The initiative combines several key capabilities:

  • Open source engineering expertise from Red Hat and IBM;
  • Red Hat’s deep open source community relationships;
  • Advanced AI-assisted engineering workflows; and
  • Red Hat’s secure software supply chain capabilities and build infrastructure.

This powerful engine rapidly develops version-specific fixes for open source application dependencies in production systems. The remediations are delivered through secured repositories that connect with customers’ existing IT processes. This allows organizations to address difficult or previously unknown vulnerabilities without replacing their current security scanners, software repositories, development pipelines or testing processes.

Through Lightwell Network, IT teams can access verified patches, bring remediated software into their existing workflows and establish an ongoing process for addressing vulnerabilities. With the general availability of Lightwell Clearinghouse, customers can submit specific open source vulnerabilities to IBM and Red Hat for priority review, remediation and fixes that can be applied to older software versions still in use.

In alignment with Red Hat’s open source leadership, applicable fixes developed through Lightwell are contributed back to upstream open source projects under responsible disclosure protocols. This helps the broader open source ecosystem benefit from Lightwell’s scale while maintaining embargo protections for Clearinghouse participants.

Supporting Quotes

Gunnar Hellekson, vice president and general manager, Lightwell, Red Hat

“AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together. Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime. Finding and neutralizing 400+ novel vulnerabilities so quickly shows how fast Lightwell can move, and we are just getting started.”

IBM and the IBM logo are trademarks or registered trademarks of International Business Machines Corporation in the US and other countries.Red Hat and the Red Hat logo are trademarks or registered trademarks of Red Hat, LLC. or its subsidiaries in the U.S. and other countries. Java and all Java-based trademarks and logos are trademarks or registered trademarks of Oracle and/or its affiliates.


ABOUT RED HAT
Red Hat is the open hybrid cloud technology leader, delivering a trusted, consistent and comprehensive foundation for transformative IT innovation and AI applications. Its portfolio of cloud, developer, AI, Linux, automation and application platform technologies enables any application, anywhere—from the datacenter to the edge. As the world’s leading provider of enterprise open source software solutions, Red Hat invests in open ecosystems and communities to solve tomorrow’s IT challenges. Collaborating with partners and customers, Red Hat helps them build, connect, automate, secure and manage their IT environments, supported by consulting services and award-winning training and certification offerings.

ABOUT IBM
IBM is a leading provider of global hybrid cloud and AI, and consulting expertise. We help clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs and gain the competitive edge in their industries. Thousands of governments and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM’s hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently and securely. IBM’s breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and consulting deliver open and flexible options to our clients. All of this is backed by IBM’s long-standing commitment to trust, transparency, responsibility, inclusivity and service. Visit www.ibm.com for more information.

FORWARD-LOOKING STATEMENTS
Except for the historical information and discussions contained herein, statements contained in this press release may constitute forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. Forward-looking statements are based on the company’s current assumptions regarding future business and financial performance. These statements involve a number of risks, uncertainties and other factors that could cause actual results to differ materially. Any forward-looking statement in this press release speaks only as of the date on which it is made. Except as required by law, the company assumes no obligation to update or revise any forward-looking statements.


( Press Release Image: https://photos.webwire.com/prmedia/6/361475/361475-1.png )


WebWireID361475





This news content was configured by WebWire editorial staff. Linking is permitted.

News Release Distribution and Press Release Distribution Services Provided by WebWire.