AI News Feed
Market watch
Cybersecurity

IBM and Red Hat Patch 400-Plus Unknown Java Flaws, Open Lightwell Clearinghouse

IBM and Red Hat say their Lightwell open-source security program has fixed more than 400 previously unknown Java library vulnerabilities and made the Clearinghouse remediation service generally available to enterprise customers.

The companies pitch the milestone against a risk they say is growing as autonomous artificial intelligence agents become better at chaining several lower-risk software weaknesses into one serious attack, according to SiliconANGLE. Because many businesses still run library versions that are years old, a patch has to be built for the exact release sitting in production rather than only for the current upstream code.

For the more than 400 flaws, Lightwell engineers backported patches into the widely deployed versions of each affected library. Any fix that also applies upstream goes back to the open-source project under responsible disclosure protocols, while Clearinghouse participants keep their embargo protections. Neither company has named the libraries involved.

The work combines engineers from both companies with AI-assisted development workflows, and the builds run on Red Hat's secure software supply chain infrastructure. Customers pull the patched packages from secured repositories that connect to their existing information technology processes, so no one has to swap out security scanners or development pipelines to use them.

Those patched packages come through Lightwell Network, the general catalog IT teams draw on to fold verified patches into the workflows they already have. Fixes that come back from a Clearinghouse request are built to apply to older software versions that a customer still runs.

Gunnar Hellekson, vice president and general manager of Lightwell at Red Hat, said AI agents "shifted the threat landscape overnight" by going after old dependencies at machine speed. Age and stability do not protect a codebase, he argued. Finding the bugs is "only half the battle," Hellekson said, and the real work is backporting fixes into applications already in production so customers "do not have to pick between security and uptime."

Lightwell dates back to May, when IBM and Red Hat committed $5 billion and more than 20,000 engineers to securing open-source software. Lightwell Network became generally available in July with a launch catalog of more than 6,500 remediated dependencies, and a tier called Clearinghouse Premier opened to financial services companies on a limited basis at the same time. In August, IBM and Red Hat extended Lightwell to universities, nongovernmental organizations and think tanks at no cost.