Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    A New Device Eases One of the Most Annoying Parts of Routine Physicals

    August 5, 2026

    NASA’s new dark energy space telescope can also detect killer asteroids

    August 5, 2026

    The AI Notetaker Has Been Invited to All the Meetings

    August 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • A New Device Eases One of the Most Annoying Parts of Routine Physicals
    • NASA’s new dark energy space telescope can also detect killer asteroids
    • The AI Notetaker Has Been Invited to All the Meetings
    • OK, Well, Rogue AI Agents Are Hacking Again
    • Heat Is an Orbital Data Center’s Greatest Foe. These Tiles Dump It at the Source.
    • The White House Is Keeping Its AI Cybersecurity Framework Secret
    • How One Startup Built a (Mostly) China-Free Robot
    • The 2026 R&D Benchmark Report: Waste, AI and the Race to Market
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Open-source security is a mess – IBM and Red Hat bet $5 billion and 20,000 engineers can fix it
    Cybersecurity

    Open-source security is a mess – IBM and Red Hat bet $5 billion and 20,000 engineers can fix it

    kirklandc008@gmail.comBy kirklandc008@gmail.comMay 29, 2026No Comments6 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Open-source security is a mess - IBM and Red Hat bet $5 billion and 20,000 engineers can fix it
    Share
    Facebook Twitter LinkedIn Pinterest Email

    PeterPhoto123 via Shutterstock

    Follow ZDNET: Add us as a preferred source on Google.

    ZDNET’s key takeaways

    • Lightwell is a huge effort to safeguard open-source software.
    • IBM and Red Hat are investing in this massive security initiative. 
    • We don’t yet know how this subscription-based service will work. 

    AI is a mixed blessing for open-source software. On the one hand, AI can help developers program faster and find bugs more quickly. On the other hand, maintainers are being overwhelmed by the sheer volume of potentially serious bug reports. 

    As Daniel Steinberg, founder and maintainer of the popular open-source data transfer program cURL, recently said, “The rate of incoming security reports is four to five times higher than it was in 2024 and double the speed of 2025.” For the first time, he confessed, “I work more than I’ve done before, but the flood keeps coming.” Steinberg is on the verge of burning out. So, he asked for more companies “to fund us” so they could then pay more developers to distribute the workload.” Now, IBM and its subsidiary Red Hat have heard the call.

    Also: Europe’s open-source alternative to Microsoft Office and Google Docs launches June 9

    Their answer is Project Lightwell, an AI‑powered initiative they described as a “first‑of‑its‑kind force” to find and fix vulnerabilities in open-source software at an industrial scale. Lightwell aims to become a de facto clearinghouse for securing the open-source components that underpin modern enterprise IT.

    However, the initiative will not pay upstream developers. Instead, Lightwell provides IBM and Red Hat engineers with AI tools to work on important, business-critical open-source projects and make them as secure as possible. Since Anthropic’s Mythos Preview model has already identified nearly 3,900 serious security vulnerabilities in open-source software in just a few weeks, the urgent need for faster fixes is crystal clear.

    To take this step, the two companies will invest $5 billion over the following years to roll out frontier‑scale AI models, tooling, and a global engineering organization dedicated to open-source security. This move isn’t just an AI play. The companies will also dedicate 20,000 engineers to treating open-source risk as a first‑order supply chain problem, not a background maintenance chore.

    Also: Rust will save Linux from AI, says Greg Kroah-Hartman

    After all, as ZDNET’s own David Gerwitz recently pointed out, “traditional application security is no longer enough.” It’s not even close to being enough. 

    Boosting open-source code security

    At the heart of Project Lightwell is a new operational model that bridges the gap between enterprises and the upstream communities that build the software they rely on. Rather than launching yet another bug bounty program or code‑scanning service, IBM and Red Hat are pitching Lightwell as a trusted intermediary. That is, businesses will feed the initiative information about the open-source software they run. Then, Lightwell engineers will use AI to hunt for flaws and propose fixes. After that, its engineers will work with upstream maintainers to get patches merged and shipped.

    The companies said this clearinghouse will combine several functions that today are fragmented across internal security teams, third‑party scanners, and community maintainers. Those functions include large‑scale vulnerability discovery, triage and prioritization, patch development, backporting, and long‑term lifecycle support for the specific versions enterprises actually deploy. If all goes well, this approach will transform the trickle of manual fixes into a high‑throughput remediation pipeline that still respects project governance and open development norms.

    As Arvind Krishna, IBM’s Chairman and CEO, said in a statement, “With Project Lightwell, IBM and Red Hat are helping define a new industry model, one that brings together AI, engineering expertise, and trusted collaboration, to secure open source software at its source and across the entire supply chain.”

    Also: Nearly half of cybersecurity pros want to quit – here’s why

    Lightwell will start with the Maven/Java ecosystem, which witnessed enormous abuse even before AI appeared on the scene. The project will then be expanded across PyPI, npm, Go, and other important open-source codebases. 

    IBM’s latest AI models will power Lightwell. These systems will be trained to scan massive codebases, dependency graphs, and configuration archives for potential vulnerabilities, then generate candidate patches that human engineers validate before anything goes upstream or into customer environments.

    Also: 10 ways AI can inflict unprecedented damage in 2026

    The companies argued that this human‑in‑the‑loop approach is essential if AI is to be trusted with security‑critical code. Models can surface patterns and issues that human reviewers would never have time to cover, IBM said. However, final decisions about what constitutes a safe and acceptable fix will remain with experienced engineers and project maintainers. In practice, Lightwell is meant to appear to communities as a particularly large and well‑organized contributor, not as an opaque automation layer dropping unsolicited pull requests.

    Working with, not around, upstream

    For Red Hat, Project Lightwell extends a playbook honed for decades. The initiative will take upstream open source, harden and support it for enterprises, and push improvements back to the community. The difference is scope. While Red Hat’s traditional model has centered on platforms such as its own products, including Red Hat Enterprise Linux (RHEL), OpenShift, and Ansible, Lightwell will target the sprawling long tail of libraries, frameworks, and tools that quietly underpin everything from banking systems to AI pipelines.

    Also: Red Hat Desktop vs. Fedora Hummingbird: Which AI development Linux path is right for you?

    The companies said Lightwell engineers will file issues, propose patches, and co‑maintain critical components alongside existing project leaders rather than forking or replacing them. When upstream maintainers disagree with a fix or decline to support an older branch, Lightwell will still be able to carry hardened backports for its customers. But IBM and Red Hat insisted that the default path is upstream‑first, with the clearinghouse acting as a bridge between enterprise production demands and community release cadences.

    Supply chain risk as an opportunity

    At the same time, IBM and Red Hat explicitly said, “These capabilities will be offered through commercial subscriptions, allowing enterprises to integrate secure patches directly into their existing software supply chains with enterprise-grade validation and lifecycle management.” 

    These subscriptions are positioned as an overlay on existing software supply chains, not a new distro: Lightwell plugs into Continuous Integration and Continuous Deployment (CI/CD), registries, and Software Bill of Materials (SBOM) processes companies already use, delivering vetted fixes and policy decisions via APIs, catalogs, and integrations.

    Also: Why business architects are poised to lead the corporate AI revolution

    IBM’s senior VP of software, ‌Rob ⁠Thomas, told Reuters, “The service will launch as a commercial offering in the next 30 days.” This subscription, which will probably be priced according to the number of packages used, will provide clients with a “stamp of approval from the clearinghouse that their open source is safe to use in production.”

    That service is all well and good, and certainly the two powerhouse companies will be investing a ton of money and deserve to make a profit, but how do the upstream open-source developers and their businesses fit into this new approach? Will this proposed trusted enterprise clearinghouse become a de facto gatekeeper for big companies? If the patches are all placed in upstream repositories, what, exactly, will customers be paying for?

    Those are all good questions, and right now there are no good answers. Stay tuned. 

    Bet billion engineers fix HAT IBM mess opensource Red Security
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • A New Device Eases One of the Most Annoying Parts of Routine Physicals
    • NASA’s new dark energy space telescope can also detect killer asteroids
    • The AI Notetaker Has Been Invited to All the Meetings
    • OK, Well, Rogue AI Agents Are Hacking Again
    • Heat Is an Orbital Data Center’s Greatest Foe. These Tiles Dump It at the Source.

    A New Device Eases One of the Most Annoying Parts of Routine Physicals

    August 5, 2026

    NASA’s new dark energy space telescope can also detect killer asteroids

    August 5, 2026

    The AI Notetaker Has Been Invited to All the Meetings

    August 5, 2026

    OK, Well, Rogue AI Agents Are Hacking Again

    August 5, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.