While the Lightwell Clearinghouse offers embargo protections for its enterprise participants, the broader tech community isn’t being left in the dark.
IBM and Red Hat have hit a major cybersecurity milestone, successfully uncovering and patching more than 400 previously unknown vulnerabilities hidden inside widely used, production-grade Java libraries.
The achievement highlights a critical shift in how the industry handles software supply chain security. Right now, most security tools are great at finding potential flaws, but detection alone doesn’t eliminate the risk.
And with the rise of autonomous AI agents capable of chaining together several low-risk weaknesses into a single devastating attack, simply knowing a bug exists isn’t enough. Organizations need actual, deployable fixes that integrate seamlessly with older software versions already running in production, without breaking business operations.
To tackle this, IBM and Red Hat have officially launched the Lightwell Clearinghouse.
Building on the broader Lightwell initiative, the newly available Clearinghouse allows enterprise customers to submit their specific open-source software dependencies for priority review and remediation.
How the Engine Works
Behind the scenes, Lightwell operates as a powerful remediation engine. It combines advanced AI-assisted engineering workflows with the deep open-source expertise of both IBM and Red Hat, all backed by Red Hat’s secure software supply chain infrastructure.
Instead of forcing companies to rip and replace their current security scanners or development pipelines, Lightwell delivers version-specific fixes directly through secured repositories via the Lightwell Network.
IT teams can grab verified patches and drop the remediated software right into their existing testing and deployment workflows.
An Open Source Win
While the Lightwell Clearinghouse offers embargo protections for its enterprise participants, the broader tech community isn’t being left in the dark.
True to Red Hat’s open-source roots, all applicable fixes developed through the Lightwell engine are ultimately contributed back to upstream open-source projects under responsible disclosure protocols.
Ultimately, the joint initiative proves that even the most mature, battle-tested codebases require continuous engineering attention as automated threats evolve and that moving from simply detecting vulnerabilities to actually fixing them is the new baseline for enterprise security.
Supporting Quotes
Gunnar Hellekson, vice president and general manager, Lightwell, Red Hat
“AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together. Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime. Finding and neutralizing 400+ novel vulnerabilities so quickly shows how fast Lightwell can move, and we are just getting started.”






