CYBERSECURITY OPEN SOURCE SECURITY

Lightwell: IBM and Red Hat Launch AI Platform to Secure Open Source at Scale

TM
Techmediaglobal
| 4 min read
90%
OF CODEBASES OPEN SOURCE
581
AVG. VULNERABILITIES PER CODEBASE
US$5bn
OPEN SOURCE SECURITY COMMITMENT
6,500+
REMEDIATED DEPENDENCIES

IBM and Red Hat have unveiled Lightwell, an AI-powered platform built to secure open source software and simplify vulnerability remediation at scale. With open source code making up as much as 90% of enterprise codebases, and AI now accelerating the discovery of hidden exploits, the companies argue traditional patch management can no longer keep pace.

A Response to an Escalating Vulnerability Crisis

An average codebase today contains 581 vulnerabilities, according to IBM and Red Hat. To combat this, the pair launched Lightwell, a platform designed to address the challenge through automated remediation and AI-powered dependency management.

The move builds on a US$5 billion commitment to open source security announced in May 2026, backed by more than 20,000 engineers focused on scaling AI-powered remediation.

Automation Meets Engineering Expertise

Lightwell introduces two offerings targeting enterprise software development teams: Lightwell Network and Lightwell Clearinghouse Premier. Both combine AI-driven automation with human engineering expertise to identify, validate and remediate vulnerabilities in open source dependencies.

The platform uses a generative AI-powered remediation engine that combines frontier AI and open AI models with human expertise to analyse software dependencies, delivering validated fixes for production environments without requiring organisations to upgrade entire software stacks. The technology backports critical fixes directly into long-lived production versions, an approach designed to reduce disruption and minimise regression risks.

"Lightwell represents a fundamental structural shift in how we secure all enterprise software. By pairing automated remediation with our deep engineering heritage, we aim to deliver the trusted infrastructure required to consume open source reliably, sustainably and at AI speeds."

— Matt Hicks, President and CEO, Red Hat

Network Offering Targets Development Pipelines

Lightwell Network is now generally available with more than 6,500 remediated, digitally signed and certified application dependencies across ecosystems including Java and Python. Members receive updated binaries, source code, Software Bills of Materials and compliance documentation that integrate directly into existing development pipelines.

The platform follows Red Hat's upstream-first development model, contributing fixes back to the open source community while maintaining enterprise-grade security protections. Development teams can pull certified fixes directly into systems they already run with no retooling required.

"IBM and Red Hat are giving enterprises certified fixes they can pull straight into the systems they already run, with no retooling or disruption, backed by a growing network of technology and delivery partners."

— Rob Thomas, Senior Vice President, Software & Chief Commercial Officer, IBM

Financial Services Clearinghouse in Limited Release

Lightwell Clearinghouse Premier has entered limited availability with an initial focus on the financial services sector. It enables organisations to collaborate on vulnerability disclosure, coordinated threat response and patch embargoes before vulnerabilities become public.

IBM and Red Hat plan to expand the service to government, healthcare and telecommunications sectors, reflecting the need for coordinated vulnerability management across regulated industries.

A Growing Ecosystem of Partners

IBM and Red Hat are positioning Lightwell as an ecosystem backed by an elite roster of technology and consulting partners, including Amazon Web Services, AMD, F5, GitLab, Intel, JFrog, Microsoft, NVIDIA, Palo Alto Networks and ServiceNow, collaborating to integrate security fixes across cloud environments, developer tools and enterprise infrastructure.

Deployment support will come from IBM Consulting, Red Hat Consulting, Accenture, Atos, Cognizant, Deloitte, EY, HCLTech, Infosys, Kyndryl, NTT DATA, Tata Consultancy Services and Tech Mahindra, helping customers map SBOMs, manage software dependencies and integrate Lightwell into existing pipelines.

The challenge could intensify as AI accelerates both software development velocity and the speed at which vulnerabilities emerge — with AI-generated exploits reportedly available for as little as US$50, traditional patch cycles may no longer offer adequate protection.

Key Takeaways

  • IBM and Red Hat launched Lightwell to automate remediation of open source vulnerabilities at enterprise scale.
  • The average enterprise codebase carries 581 vulnerabilities, with open source making up 90% of code.
  • Lightwell Network is generally available with 6,500+ certified, remediated dependencies across Java and Python.
  • Lightwell Clearinghouse Premier launches first for financial services, with government, healthcare and telecoms to follow.
  • The launch builds on a US$5bn open source security commitment backed by 20,000+ engineers.
  • A broad ecosystem of cloud, tooling and consulting partners is supporting adoption across industries.
Tags: Lightwell Cybersecurity Open Source Security AI Automatic Remediation Enterprise IT Vulnerability Management