IBM and Red Hat fix 400 Java flaws with Lightwell security program
IBM and Red Hat have announced significant advancements in their Lightwell open-source security program, fixing over 400 previously unknown vulnerabilities in widely used Java libraries. The companies have also made the Lightwell Clearinghouse generally available, allowing enterprise customers to submit specific open-source dependencies for priority review and remediation.
The initiative addresses a growing risk as autonomous AI agents become more adept at combining lower-risk software weaknesses into serious attacks. Many businesses still rely on outdated library versions, requiring patches to be tailored to the exact release in production. Lightwell engineers have backported patches into widely deployed versions of each library, ensuring fixes are compatible with older software versions still in use.
The Lightwell Network serves as a general catalog for IT teams to integrate verified patches into their existing workflows. Fixes derived from Clearinghouse requests are specifically built to apply to older software versions that customers continue to operate. Gunnar Hellekson, vice president and general manager of Lightwell at Red Hat, emphasized the shifting threat landscape, stating that AI agents are targeting old dependencies at machine speed, making age and stability insufficient protections.
Lightwell's development involves collaboration between IBM and Red Hat engineers, utilizing AI-assisted workflows and Red Hat's secure software supply chain infrastructure. The program dates back to May, when IBM and Red Hat committed $5 billion and over 20,000 engineers to securing open-source software. The Lightwell Network went generally available in July with a catalog of more than 6,500 remediated dependencies, and the Clearinghouse Premier tier was introduced for financial services companies.