THEMETASEC

Cybersecurity News, Aggregated

Lightwell project filters out 400 Java library vulnerabilities

CSO Online · 52 minutes ago Vuln

Lightwell, the open-source security initiative set up by IBM and Red Hat, has identified more than 400 previously undiscovered vulnerabilities in widely used Java libraries — and now the companies are inviting customers to submit their own code dependencies to a new service, Lightwell Clearinghouse, for review. They’ll be looking for bugs such as the critical sandbox bypass in Java template engine Thymeleaf, with a CVSS score of 9.1, discovered in April. “AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime. Finding and neutralizing 400+ novel vulnerabilities so quickly shows how fast Lightwell can move,” said Gunnar Hellekson, vice president and general manager of Lightwell. IBM and Red Hat announced in May that they would commit 20,000 engineers and $5 billion to the Lightwell project, combining their open-source engineering expertise, Red Hat’s community relationships, and AI-assisted engineering workflows. Their goal is not just to identify security issues, but also to introduce remediation software to address them. Lightwell is not the only player in town when it comes to identifying and fixing Java vulnerabilities. Azul has introduced free vulnerability risk assessment for Java Virtual Machines.  The company said it can address the blind spots that autonomous AI-powered exploitation tools, like Mythos, are able to find. This article first appeared on InfoWorld.

Read full story at CSO Online →