IBM and Red Hat have fixed more than 400 previously unknown security weaknesses in widely used Java libraries through their Lightwell initiative. The fixes cover older software versions still running in business applications, allowing companies to address the weaknesses without moving to a newer version.
Java libraries are collections of ready-made code that developers use to build applications. A security flaw in one of these shared components can affect the applications that rely on it, making the libraries an important part of keeping business systems secure.
“AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed,” said Gunnar Hellekson, vice president and general manager, Lightwell, Red Hat. They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together.”
The companies also announced the general availability of Lightwell Clearinghouse. The service allows enterprise customers to submit specific open source software components they depend on for priority security review and fixes.
Open source software makes its source code available for people to inspect, use, and modify. Companies often rely on these components rather than building every part of an application themselves.
IBM and Red Hat said autonomous AI agents, or software that can carry out tasks with limited human direction, can combine several smaller weaknesses into a more serious attack. This puts pressure on businesses to fix problems in the software they already use.
Security scanners can flag possible weaknesses, but companies still need a working fix. Applying one can be difficult when an application depends on an older software version and an upgrade could disrupt daily operations.
Lightwell develops fixes for specific versions, including older releases. This process, called backporting, brings a security fix to an earlier version so businesses can address the problem without upgrading the entire application.
The initiative combines IBM and Red Hat’s open source engineering expertise, Red Hat’s relationships with open source communities, AI-assisted engineering workflows, and infrastructure for building and delivering software securely.
Fixes are delivered through secured software repositories, where companies obtain and manage their software components. IBM and Red Hat said these repositories connect with customers’ existing development, testing, and IT processes.
Through Lightwell Network, IT teams can access verified patches and bring the repaired software into their usual workflows. Customers can continue using their existing security scanners and software management tools.
Applicable fixes are also contributed back to the original open source projects through responsible disclosure. This allows the wider community to benefit while protecting details that must remain confidential until the fixes can be released safely.