Red Hat and IBM used 'Lightwell' to fix 400+ undisclosed Java library vulnerabilities and launch 'Lightwell Clearinghouse' (report)
What happened
Red Hat and IBM used Lightwell to find and fix more than 400 previously unknown vulnerabilities in Java libraries. They also made 'Lightwell Clearinghouse' generally available. The service lets enterprise customers ask for specific open-source dependencies to be reviewed and fixed first. The two companies said the move is a response to the threat of autonomous AI agents chaining several low-risk vulnerabilities into more serious attacks.
Why it matters
As AI automates attacks, large-scale advance patching of the open-source supply chain is now offered as a commercial service.
Confidence medium · official source pending
Sources
- Press 레드햇·IBM, 기존에 알려지지 않은 오픈소스 취약점 400건 이상 수정 조치 AI News Korea