IBM and Red Hat said their Lightwell open-source security program has identified and corrected more than 400 vulnerabilities in widely used Java libraries that were previously unknown. The two companies also announced that Lightwell Clearinghouse is now generally available, allowing enterprise customers to submit specific open-source dependencies for priority review and remediation.
The announcement addresses what IBM and Red Hat describe as a growing risk: autonomous artificial intelligence agents are becoming more capable of combining several lower-risk software weaknesses into a single serious attack. Many businesses continue to run library versions that are years old, according to the companies, meaning any patch must be built for the exact release running in production.
For the more than 400 flaws, Lightwell engineers backported patches into the widely deployed versions of each affected library. Fixes that also apply upstream return to the open-source project under responsible disclosure protocols, while participants in Clearinghouse retain their embargo protections. Neither company has named the libraries involved.
Engineers from both companies work alongside AI-assisted development workflows, and the builds run on Red Hat's secure software supply chain infrastructure. Customers obtain the patched packages from secured repositories that connect to their existing information technology processes, so they do not need to replace security scanners or development pipelines.
The patched packages are delivered through Lightwell Network, the general catalog IT teams use to incorporate verified patches into their current workflows. Fixes produced through a Clearinghouse request are built to apply to older software versions that a customer still runs.
Gunnar Hellekson, vice president and general manager of Lightwell at Red Hat, said AI agents changed the threat landscape overnight by targeting old dependencies at machine speed. He said age and stability do not protect a codebase, and that finding bugs is only part of the problem. The harder work, he said, is backporting fixes into applications already in production so customers do not have to choose between security and uptime.
Lightwell began in May, when IBM and Red Hat committed $5 billion and more than 20,000 engineers to securing open-source software. Lightwell Network became generally available in July with a launch catalog of more than 6,500 remediated dependencies, and a tier called Clearinghouse Premier opened to financial services companies on a limited basis at the same time. In August, IBM and Red Hat extended Lightwell to universities, nongovernmental organizations and think tanks at no cost.
More cybersecurity news from TechManNews.





