AI agents are getting better at finding and exploiting weaknesses in software, but IBM and Red Hat are trying to make sure some of those holes disappear before attackers can take advantage of them.
The companies say their Lightwell initiative has remediated more than 400 previously unknown vulnerabilities across foundational Java libraries. Rather than simply identifying the problems, IBM and Red Hat developed fixes and backported them for software already running in production.
This matters because autonomous AI agents could potentially combine seemingly minor weaknesses into much more serious attack chains. IBM and Red Hat specifically warn about AI-driven exploits targeting critical enterprise applications, including older dependencies that organizations may have relied on for years.
Lightwell is designed to work alongside existing scanners, repositories, CI/CD pipelines, and validation processes. Organizations can receive version-specific patches through secured repositories rather than having to overhaul the security infrastructure they already use.
IBM and Red Hat are also making Lightwell Clearinghouse generally available. Enterprise customers can submit specific open source dependencies for priority triage, remediation, and backporting.
I’m genuinely impressed by what IBM and Red Hat are doing here. Finding vulnerabilities is useful, of course, but actually doing the engineering work to fix them and get those fixes into software that companies are already running is far more interesting to me.
Better yet, applicable fixes developed through Lightwell are expected to be contributed back to upstream open source projects under responsible disclosure procedures. That means the work can ultimately benefit the wider open source community rather than staying locked behind an enterprise service.
“AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together. Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime. Finding and neutralizing 400+ novel vulnerabilities so quickly shows how fast Lightwell can move, and we are just getting started,” said Gunnar Hellekson, vice president and general manager of Lightwell at Red Hat.
Of course, finding more than 400 previously unknown problems in mature, production-grade software also highlights how much potentially vulnerable code sits underneath modern enterprise applications. There will always be more bugs to find.
Still, Lightwell offers an encouraging answer to one of the scarier questions surrounding autonomous AI. If attackers can use AI to move faster, perhaps defenders can use it to find and fix vulnerabilities faster too.
Support independent tech journalism
NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.
Support NERDS.xyz


