Mark RadarMARK RADAR
About
EN
Sign in

IBM, Red Hat Launch AI-Powered Open-Source Software Security Service

1 reports · First detected 2026-07-14 · Last active 2026-07-14

Open-source software has become a cornerstone of system development as companies accelerate their digital transformation, but vulnerabilities in its supply chain have also created fertile ground for hackers. IBM and open-source software leader Red Hat are joining forces to help companies worldwide guard against supply-chain security risks when using third-party packages, particularly in highly regulated industries such as financial services. The initiative aims to ensure the stability and compliance of core operations.

IBM and Red Hat formally launched Lightwell, an enterprise open-source software supply-chain security service, in July 2026. Its initial catalog includes more than 6,500 dependencies that have been patched and verified. Lightwell also uses a generative AI-powered vulnerability remediation engine that can backport security fixes to long-term enterprise versions. The companies are initially prioritizing a dedicated offering for the financial services industry to accelerate the reduction of cybersecurity risks.

All Coverage

1 original reports

The Backstory

The history behind this event
IBM, Red Hat Launch Project Lightwell to Use AI to Secure Open-Source Software Supply Chains and Patch Vulnerabilities2026-06-29 · 2 reports · similarity 0.89

Open-source packages underpin enterprise applications and AI systems, but upgrading vulnerable third-party dependencies can create compatibility and operational problems. IBM and Red Hat developed Project Lightwell to use AI to analyze, validate and backport patches, reducing software supply-chain risks.

IBM and Red Hat announced on May 28, 2026, that they would invest $5 billion and mobilize more than 20,000 engineers, initially focusing on Java. Eleven financial institutions, including Bank of America and Visa, were the first adopters. Palo Alto Networks joined on June 24, integrating Virtual Patching to block attacks at the network layer before permanent fixes are completed.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)