Red Hat and IBM Expand Open Source Security Initiative with Lightwell
IBM and Red Hat have announced that they will be expanding their AI-powered open source security initiative by providing Lightwell, a platform for vulnerability remediation, to over 285 research and public-interest organisations. This includes more than 185 leading U.S. research universities and 100 major NGOs and think tanks.
The programme aims to secure research, education, and public-interest infrastructure while strengthening the broader open source ecosystem. Lightwell combines generative AI-driven automation with human engineering expertise to identify, validate, and remediate vulnerabilities.
Under Red Hat's upstream-always development model, validated fixes are contributed back to the originating open source communities, extending the benefits beyond participating organisations. The platform delivers validated fixes for software versions institutions already run, reducing the need for disruptive upgrades.
Lightwell was launched in May 2026 with a US$5 billion commitment and more than 20,000 engineers. It has expanded from 6,500 to over 8,000 validated and remediated package versions, including fixes for 64 previously undisclosed vulnerabilities.