IBM and Red Hat are expanding access to their AI-driven remediation platform, helping enterprises secure existing software without disrupting production.

Yesterday, IBM and Red Hat announced that AI-driven Lightwell has identified and remediated more than 400 previously unknown vulnerabilities in popular Java libraries.
Launched in July, Lightwell is a platform for delivering automated vulnerability remediation at scale. The Java revelation was leading into an announcement that Clearinghouse — a part of the platform that allows users to submit specific open source software dependencies for review and remediation — has reached general availability. Previously, its use had been restricted to the financial services industry.
The other side of the platform, Network, which has been GA since the platform’s launch, offers a set of secure repositories of open‑source packages that Red Hat rebuilds, signs, and maintains for enterprise customers.
Basically, the platform is designed to deal with a threefold security threat that’s largely been brought about by the advent of AI:
- The speed at which AI can work is resulting in the discovery of security vulnerabilities at an ever increasing rate.
- Once these vulnerabilities are found, it’s imperative that they be remedied at once, because black hats are using AI too.
- This includes fixing vulnerabilities that previously might not have been considered serious, because AI makes it easier for bad actors to string together several small and possibly inconsequential vulnerabilities in a way that enables an intrusion.
If you need proof for the first bullet point, all you need do is look at the history of Red Hat’s announcement for this release. On Friday, when we were first handed the press release under embargo, the number of Java vulnerabilities that Lightwell had found and fixed was listed as 300. When we received the final copy Monday morning, that number had risen to 400.
“AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed,” longtime Red Hatter Gunnar Hellekson, VP and GM of Lightwell, said in a statement. “They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together.
“Finding those bugs is only half the battle,” he added. “The real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime. Finding and neutralizing 400+ novel vulnerabilities so quickly shows how fast Lightwell can move, and we are just getting started.”
Hellekson’s statement pretty much echoes Red Hat’s pitch, which paints the platform as developing version-specific fixes for open source application dependencies in production systems.
“This allows organizations to address difficult or previously unknown vulnerabilities without replacing their current security scanners, software repositories, development pipelines or testing processes,” the company explained in the latest release. IT teams using the platform have access to a repository that allows them to bring remediated software into their existing workflows and establish a system for addressing vulnerabilities as part of their workflow.
In some ways, Clearinghouse will now act as a mediator for a type of indirect security partnership with other users of the same software. This starts with customers submitting open source vulnerabilities to IBM and Red Hat for “review, remediation, and fixes” that can be applied to the software the customers are running.
“In alignment with Red Hat’s open source leadership, applicable fixes developed through Lightwell are contributed back to upstream open source projects under responsible disclosure protocols,” Red Hat said. “This helps the broader open source ecosystem benefit from Lightwell’s scale while maintaining embargo protections for Clearinghouse participants.”
More information about Lightwell can be found on a sales and marketing oriented page on Red Hat’s website.
Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux






Be First to Comment