đ° Full Story
IBM and its Red Hat unit on May 28 unveiled Project Lightwell, a $5 billion initiative that combines AI tools and a global force of roughly 20,000 engineers to identify, validate and deploy fixes for vulnerabilities in open-source software used by enterprises.
Described as an âenterprise clearinghouse,â the service will let firms confidentially report security flaws, receive tested patches backported to exact dependency versions and integrate those fixes into existing software supply chains.
IBM said it piloted the model with major financial institutions including Bank of America, JPMorgan Chase, Goldman Sachs, Visa and Mastercard and expects to launch Project Lightwell as a commercial subscription within about 30 days.
Initial technical focus will include Java/Maven with plans to expand to PyPI, npm and Go.
IBM positions the effort as a response to acceleration in AI-driven vulnerability discovery â citing recent projects that surfaced thousands of highâseverity flaws â and says the clearinghouse will also coordinate upstream disclosure so fixes reach open-source communities.







đŹ Commentary