TL;DR — Key Takeaways
-
IBM and Red Hat Remediate 400+ Vulnerabilities: The companies have identified and fixed more than 400 previously unknown vulnerabilities in Java libraries through their Lightwell initiative.
-
Lightwell Clearinghouse Now Generally Available: Organizations can submit open-source dependencies for priority security review and remediation, with verified patches integrated into existing development workflows.
-
AI Accelerates Vulnerability Discovery: AI-powered analysis is uncovering security flaws in legacy code faster, potentially increasing pressure on DevSecOps teams to address vulnerabilities.
IBM and Red Hat this week reported they have identified and remediated more than 400 previously unknown vulnerabilities in Java libraries since launching a Lightwell initiative earlier this year.
Additionally, Lightwell Clearinghouse, a program that enables IT organizations to submit specific open source software dependencies for priority review and remediation, is now generally available.
Ben Bread, a senior principal product manager for Red Hat, said the 400 unknown vulnerabilities represent twice the number that was expected to be uncovered and there will undoubtedly be more to come as artificial intelligence (AI) tools are used to analyze more legacy code.
Additionally, DevSecOps teams should expect a similar number of vulnerabilities to be discovered in libraries created using other programming languages, he added.
While IT teams are contracting with IBM and Red Hat to fix vulnerable code in their IT environments, the code fixes developed are being contributed back to upstream open source projects under responsible disclosure protocols.
IBM and Red Hat are not disclosing how many organizations are relying on them to help generate the code needed to remediate vulnerabilities in their legacy codebases, but they are delivered via secure repositories that connect to existing processes for building and deploying software. Via the Lightwell Network, IT teams can access verified patches, bring remediated software into their existing workflows and establish an ongoing process for addressing vulnerabilities. The more automated those processes are using best DevSecOps practices, the faster that remediation effort becomes, noted Bread.
In fact, the ongoing discovery of so many vulnerabilities in legacy code will prove to be a tipping point that spurs adoption of scanners and test automation platforms as the building and applying of patches becomes a more standard element of software engineering workflows, he added. Organizations that today require three months to validate a code fix are not going to be able to keep pace with the vulnerability deluge, noted Bread.
It’s not clear at what rate vulnerabilities are being exploited in the age of AI, but the assumption is cybercriminals will increasingly use AI models to both discover and exploit vulnerabilities in hours. As such, rather than patching software once a month to fix vulnerabilities, DevSecOps teams now need to be continuously patching software as more issues are continuously surfaced, said Bread.
Unfortunately, there are still many organizations that are not taking the threats AI poses to application security seriously enough, noted Bread. Many of those organizations will soon discover just how many vulnerabilities exist in codebases that many are assuming is more secure than it actually is. It’s only when organizations are able to preview the vulnerabilities and exploits that AI models are able to discover and create that the real scope of the issue becomes apparent, added Bread.
More challenging still, the cost of discovering a vulnerability is now as low as $30, so the economics of application security only continue to favor the attacker, he noted.
Hopefully, it won’t require some type of catastrophic event for more organizations to pay more attention to application security in the age of AI. The issue, of course, is that it’s not so much a question of when a breach will occur but rather how serious it is given the nature of the vulnerability being exploited.
Frequently Asked Questions
What is IBM and Red Hat's Lightwell initiative?
Lightwell is an initiative designed to identify and remediate previously unknown vulnerabilities in open-source software dependencies. Since launching earlier this year, IBM and Red Hat have fixed more than 400 vulnerabilities in Java libraries.
What is Lightwell Clearinghouse?
Lightwell Clearinghouse is a generally available program that enables organizations to submit specific open-source dependencies for priority security review and remediation. Verified patches can be accessed through secure repositories and incorporated into existing software development workflows.

