International Business MachinesIBM's Lightwell initiative with Red Hat identified and remediated 400+ unknown Java vulnerabilities and launched the Lightwell Clearinghouse product.

IBM and Red Hat announced that their Lightwell initiative has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries, and that Lightwell Clearinghouse is now generally available. The Clearinghouse gives enterprise customers a direct path to submit specific open source software dependencies for priority review and remediation. Through Lightwell, the two companies uncovered, remediated and backported fixes for the more than 400 previously unknown bugs in widely deployed, production-grade software, delivering version-specific patches through secured repositories that connect with customers' existing IT processes without replacing their current security scanners, software repositories, development pipelines or testing processes. Applicable fixes are contributed back to upstream open source projects under responsible disclosure protocols, with embargo protections maintained for Clearinghouse participants. Gunnar Hellekson, vice president and general manager of Lightwell at Red Hat, said AI agents have shifted the threat landscape by exploiting old dependencies at machine speed, and that finding and neutralizing 400-plus novel vulnerabilities so quickly shows how fast Lightwell can move.
International Business MachinesIBM's Lightwell initiative with Red Hat identified and remediated 400+ unknown Java vulnerabilities and launched the Lightwell Clearinghouse product.
Red Hat co-developed Lightwell, remediated 400+ novel Java vulnerabilities, and launched the generally available Lightwell Clearinghouse.