IBM and Red Hat Disclose Discovery of More Than 400 Java Vulnerabilities
IBM and Red Hat this week reported they have identified and remediated more than 400 previously unknown vulnerabilities in Java libraries since launching a Lightwell initiative earlier this year. Additionally, Lightwell Clearinghouse, a program that enables IT organizations to submit specific open source software dependencies for priority review and remediation, is now generally available. Ben […]
IBM and Red Hat have recently disclosed the discovery of more than 400 previously unknown vulnerabilities in Java libraries since starting a Lightwell initiative. This number is twice the amount initially expected to be found. The Lightwell Clearinghouse, a program that allows IT organizations to submit specific open-source software dependencies for priority review and remediation, is now widely available.
Ben Bread, a senior principal product manager for Red Hat, stated that this revelation of vulnerabilities is expected to increase as AI tools analyze more legacy code. DevSecOps teams should anticipate a similar number of vulnerabilities in libraries created using other programming languages. These code fixes are being contributed back to upstream open-source projects under responsible disclosure protocols.
IBM and Red Hat are not revealing how many organizations are relying on their services for code remediation, but these fixes are made available via secure repositories that connect to existing software building and deployment processes. The Lightwell Network enables IT teams to access verified patches, integrate remediated software into their workflows, and establish ongoing vulnerability management processes.
This continuous discovery of vulnerabilities is expected to drive adoption of scanners and test automation platforms, making code patching a standard part of software engineering workflows. With cybercriminals potentially leveraging AI to exploit vulnerabilities within hours, organizations need to shift from patching software once a month to continuously patching as more issues arise.
Despite the low cost of discovering vulnerabilities, currently as low as $30, the economics of application security continue to favor attackers. Organizations must take AI's threat to application security seriously and prepare for the inevitable breaches, which could be catastrophic if the vulnerabilities exploited are severe.
Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.