
Project Lightwell is a $5 billion initiative by IBM and Red Hat to help enterprises secure open source software. The effort applies lessons from frontier AI models and large engineering resources. Exploit timelines are shrinking as powerful models reduce the window between vulnerability detection and patching from weeks to days or hours. Security and IT vendors are developing AI-powered protections and processes to keep pace with faster attacker activity. Open source environments are especially challenging because open source software underpins much of the internet and infrastructure. In related work, Mythos Preview scanned more than 1,000 open source projects and identified 23,019 security flaws, including 6,202 high- or critical-severity issues. The main bottleneck is human capacity to triage, report, design, and deploy patches, even as finding vulnerabilities becomes easier.
"IBM and Red Hat are bringing together what they've learned from frontier AI models and 20,000 engineers to launch Project Lightwell, a $5 billion initiative aimed at helping enterprises better secure their open source software, work that has become more challenging in the age of such models as Anthropic's Claude Mythos Preview."
"Mythos and similarly powerful frontier models are quickly collapsing the exploit window for organizations, reducing from weeks to days or hours the time between vulnerability detection and patching. IT and security vendors are scrambling to develop AI-powered protections and processes to match the machine speed at which bad actors can now operate."
"They wrote that they used Mythos to scan more than 1,000 open source projects, with the model finding 23,019 security flaws, including 6,202 deemed high- or critical-severity. The researchers noted the importance of open source software - "which collectively underpin much of the internet - and much of our own infrastructure" - and the challenges that frontier AI models present."
""The bottleneck in fixing bugs like these is the human capacity to triage, report, and design and deploy patches for them," they wrote. "Finding them in the first place has become vastly more straightforward with Mythos Preview.""
Read at DevOps.com
Unable to calculate read time
Collection
[
|
...
]