6 Sources
[1]
Open-source security is a mess - IBM and Red Hat bet $5 billion and 20,000 engineers can fix it
Follow ZDNET: Add us as a preferred source on Google. ZDNET's key takeaways * Lightwell is a huge effort to safeguard open-source software. * IBM and Red Hat are investing in this massive security initiative. * We don't yet know how this subscription-based service will work. AI is a mixed
[2]
IBM and Red Hat want to become the 'security clearinghouse' for open source applications in the enterprise
IBM and Red Hat are betting that a new initiative, Project Lightwell, can help accelerate this process. Announced today, the project will commit $5 billion and 20,000 IBM and Red Hat engineers to build a new 'enterprise clearinghouse' to accelerate discovery and remediation of vulnerabilities in
[3]
Exclusive: IBM launches $5 billion AI push to combat cyber threats
Why it matters: AI is supercharging cyberattacks, pushing companies to adopt the same technology to defend against threats. Driving the news: "Project Lightwell" -- the new initiative by IBM and Red Hat, its open source software subsidiary -- uses frontier AI capabilities to establish a
[4]
IBM, Red Hat launch $5B Project Lightwell to boost open-source security
IBM, Red Hat launch $5B Project Lightwell to boost open-source security IBM Corp. and its Red Hat subsidiary today launched an initiative called Project Lightwell to improve the security of open-source projects. Project Lightwell is backed by a $5 billion commitment. In addition, IBM and Red Hat
[5]
IBM commits $5 billion to secure open-source software
The initiative, called Project Lightwell, seeks to create a "clearinghouse" for open source security, establishing a model for managing risks across the software supply chain. IBM said on Thursday it has committed $5 billion to an initiative that will deploy engineers and AI tools to help
[6]
IBM, Red Hat Pledge $5 Billion for AI-Driven Open Source Security Initiative
International Business Machines and Red Hat have committed $5 billion to establish a new model for open-source software, aiming to secure software supply chains for enterprises. Under the new project, dubbed Project Lightwell, the companies said Thursday they will deploy a global force of 20,000
Share
Copy Link
IBM and Red Hat unveiled Project Lightwell, committing $5 billion and 20,000 engineers to create an AI-powered clearinghouse for open-source security. The initiative addresses the surge in vulnerabilities discovered by AI tools, with early adopters including Bank of America, JPMorgan Chase, and Visa. The subscription-based service launches commercially within 30 days.
IBM and Red Hat announced Project Lightwell, a $5 billion investment to transform how enterprises handle open-source security vulnerabilities. The initiative deploys 20,000 engineers—all current IBM employees working full-time—to create what the companies call an AI-powered security clearinghouse for securing open-source software
1
3
. This represents a fundamental shift in how the industry approaches software supply chain security, treating open-source risk as a first-order supply chain problem rather than a background maintenance task.
Source: ET
The timing reflects an urgent crisis in open-source maintenance. Daniel Steinberg, founder of the popular cURL data transfer program, reported that security reports now arrive at four to five times the rate of 2024, pushing maintainers toward burnout
1
. Meanwhile, Anthropic's Mythos Preview model recently identified nearly 3,900 serious vulnerabilities in open-source software within weeks of launch, demonstrating how AI accelerates both threat discovery and the need for faster remediation of software vulnerabilities1
2
.
Source: Axios
Project Lightwell operates as a trusted intermediary between enterprises and upstream open-source communities. Businesses feed information about the open-source software they run into the system, then Lightwell engineers use AI to identify and patch vulnerabilities before working with upstream maintainers to merge fixes
1
. The initiative combines large-scale vulnerability discovery, triage, patch development, backporting patches, and long-term lifecycle support for specific versions enterprises actually deploy.This approach addresses a critical pain point: companies often don't use the latest version of open-source components, and cybersecurity patches aren't immediately available for legacy versions
4
. By backporting patches to specific versions, Project Lightwell removes the need for companies to upgrade components to the latest release, which can require significant code changes.The system employs a human-in-the-loop approach where IBM's latest AI models scan massive codebases, dependency graphs, and configuration archives, then generate candidate patches that experienced engineers validate before deployment
1
. "The advancement in AI tools has broken the patching map, which is the ability to discover vulnerabilities in software without losing the speed of remediation," explained Ashesh Badani, Red Hat SVP and CPO2
.Bank of America, JPMorgan Chase, Visa, Mastercard, Wells Fargo, and Morgan Stanley are piloting the initiative to refine how the system identifies and fixes vulnerabilities across complex enterprise software
3
5
. The service will launch as a commercial subscription within 30 days, likely priced by the number of packages used, providing clients with a "stamp of approval from the clearinghouse that their open source is safe to use in production," according to IBM's senior vice president of software, Rob Thomas5
.Project Lightwell will start with the Maven/Java ecosystem, which has witnessed enormous abuse even before AI appeared, then expand across PyPI, npm, Go, and other critical open-source codebases
1
. The initiative extends Red Hat's protections beyond its own platforms to cover AI frameworks, coding libraries, and data streaming platforms such as Apache Kafka3
.
Source: InfoWorld
Related Stories
Arvind Krishna, IBM's Chairman and CEO, expects significant government interest in combating cyber threats through this model. "Over the last few weeks, ever since Mythos came out, there have been a lot of conversations with very senior levels of the government," Krishna said, noting that Project Lightwell could serve as a potential response to AI-driven security challenges
3
. This comes as the White House recently pulled an AI executive order following internal disagreements over cybersecurity approaches.The initiative positions IBM and Red Hat to compete directly with software supply chain security startups like Chainguard Inc., which raised $280 million last year providing hardened versions of open-source projects, and Socket Inc., which sells tools for installing open-source patches
4
. With more than 90% of Fortune 500 companies relying on open-source software, Krishna expects the project to expand beyond the financial sector within days or weeks3
.The clearinghouse model includes vulnerability disclosure protocols where IBM and Red Hat will share discovered vulnerabilities with maintainers of affected open-source projects through a "trusted intermediary framework"
4
. This approach aims to transform the current trickle of manual fixes into a high-throughput remediation pipeline while respecting project governance and open development norms.Summarized by
Navi
[1]
[2]
23 Jun 2026•Technology

17 Mar 2026•Technology
27 Jun 2026•Technology

1
Science and Research

2
Technology
3
Policy and Regulation
