IBM and Red Hat patch 400-plus unknown Java flaws, open Clearinghouse for fix requests
IBM Corp. and its Red Hat unit said today that their Lightwell open-source security program has found and fixed more than 400 previously unknown vulnerabilities in widely used Java libraries. The companies also made Lightwell Clearinghouse generally available. Enterprise customers can use it to submit specific open-source dependencies to IBM and Red Hat for priority […] The post IBM and Red Hat…
IBM and Red Hat recently discovered and resolved over 400 previously unknown vulnerabilities in widely used Java libraries through their Lightwell open-source security program. The companies have also made the Lightwell Clearinghouse generally available, allowing enterprise customers to submit specific open-source dependencies for priority review and remediation.
This development comes as autonomous artificial intelligence agents become more adept at chaining multiple software weaknesses into serious attacks. Since many businesses still utilize outdated library versions, each patch must be tailored to the exact production release. For the majority of the identified flaws, Lightwell engineers backported patches to widely deployed library versions.
Any fix applicable upstream is returned to the open-source project using responsible disclosure protocols, while Clearinghouse participants maintain their embargo protections. Engineers from both IBM and Red Hat collaborate with AI-assisted development workflows, and builds run on Red Hat’s secure software supply chain infrastructure.
Customers access patched packages through secured repositories that integrate with their existing IT processes, eliminating the need to replace security scanners or development pipelines. These patched packages are provided via the Lightwell Network, a general catalog that IT teams use to incorporate verified patches into their workflows.
Gunnar Hellekson, vice president and general manager of Lightwell at Red Hat, highlighted that AI agents have dramatically altered the threat landscape by targeting old dependencies at machine speed. While finding bugs is crucial, the real challenge lies in backporting fixes to existing production systems, ensuring customers do not have to choose between security and uptime.
Lightwell began in May, with IBM and Red Hat investing $5 billion and deploying over 20,000 engineers to bolster open-source software security. The Lightwell Network went generally available in July, featuring more than 6,500 remediated dependencies. In August, the companies expanded Lightwell to universities, non-governmental organizations, and think tanks at no cost.
Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.