CompaniesInvestorsPeople
Home
Loading

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

Get in Touch

  • Contact

  • Request a Demo

  • Request Data Updates

  • Add a Company

Research

  • Companies

  • Investors

  • People

aVenture

  • Download App

  • Pricing

Download the aVenture Research beta for iOS and iPadOSDownload aVenture Research on the Mac App Store

Resources

  • Documentation

  • Use Cases

  • CLI

  • MCP

  • Feature Requests

  • Sitemap

Member

Backed by

© aVenture Investment Company, 2026. All rights reserved.

San Francisco, CA, USA

Privacy Policy · Terms of Service · Privacy FAQ

aVenture Investment Company ("aVenture") is an independent research platform providing detailed analysis and data on startups, venture capital investments, and key industry individuals. It is not a registered investment adviser, broker-dealer, or investment advisor and does not provide investment advice or recommendations. The data provided by aVenture does not constitute recommendations or advice, whether by methodology, analysis, AI-generated content, or a statement written by a staff member of aVenture.

aVenture is not affiliated with any of the people, companies, organizations, government agencies, regulatory bodies, or investment funds we provide coverage for on this site unless explicitly stated otherwise. Users assume full responsibility for decisions made based on information obtained from this platform. Links to external websites do not imply endorsement or affiliation with aVenture. Any links that provide the ability to invest in a primary or secondary transaction in a company are for convenience only and do not constitute solicitations or offers to buy or sell an investment. Investors should exercise heightened precaution and due diligence when investing in private companies, especially those not independently audited.

While we strive to provide valuable insights with objectivity and professional diligence, we cannot guarantee the accuracy of the information provided on our platform. Before making any investment decisions, you should verify the accuracy of all pertinent details for your decision. To the fullest extent permitted by law, aVenture shall not be liable for any direct, indirect, incidental, consequential, or financial damages arising from use of this site, whether by consumers of its contents directly or by persons or organizations covered by our research, even if we are advised of the possibility. Our best-efforts processes and correction request forms do not create a warranty or duty of care.

Profiles on this platform may include content generated in part by large language models (LLMs, artificial intelligence) that aggregate publicly available sources (e.g., SEC EDGAR, public filings, press releases). Source attribution is provided where known; always verify statements and claims here against original sources before relying on any data. Content on our site may contain inaccuracies, omissions, or what are commonly called 'hallucinations' if generated in part or in full by AI / LLMs. The risk can also exist even when content is written by a human, as internal and third-party sources may also have inaccuracies for the same or different reasons. While we randomly audit a proportion of content, this is not exhaustive.

We recommend that an independent auditor be hired to verify the accuracy of the information before relying on it for any sensitive decisions. By accessing this platform, you agree not to rely solely on any information generated by AI, aggregated, or sourced or written otherwise on this site, for investment, financial, or other decisions. aVenture assumes no responsibility for inaccuracies, omissions, or hallucinations. You must independently verify all data from primary sources. Use of this platform constitutes your waiver of claims for reliance-based damages, including negligent misrepresentation. To report an error, request a correction, or dispute information about a company or individual, contact us via our request data updates form.

Loading
Loading
Home
News
IBM and Red Hat patch 400-plus unknown Java flaws, open Clearinghouse for fix requests

From SiliconANGLE

By Duncan Riley

October 6, 2026

IBM and Red Hat patch 400-plus unknown Java flaws, open Clearinghouse for fix requests

IBM and Red Hat patch 400-plus unknown Java flaws, open Clearinghouse for fix requests

IBM Corp. and its Red Hat unit said today that their Lightwell open-source security program has found and fixed more than 400 previously unknown vulnerabilities in widely used Java libraries.

The companies also made Lightwell Clearinghouse generally available. Enterprise customers can use it to submit specific open-source dependencies to IBM and Red Hat for priority review and remediation.

The milestone is pitched at a risk the two companies say is growing as autonomous artificial intelligence agents get better at chaining several lower-risk software weaknesses into one serious attack. Because many businesses still run library versions that are years old, any patch has to be built for the exact release sitting in production.

For the more than 400 flaws, Lightwell engineers backported patches into the widely deployed versions of each library. Any fix that also applies upstream goes back to the open-source project under responsible disclosure protocols while Clearinghouse participants keep their embargo protections. Neither company has named the affected libraries.

Behind the fixes, engineers from both companies work alongside AI-assisted development workflows, and the builds run on Red Hat’s secure software supply chain infrastructure. Customers pull the patched packages from secured repositories that connect to their existing information technology processes, so nobody has to swap out security scanners or development pipelines to use them.

Those patched packages come through Lightwell Network, the general catalog IT teams draw on to fold verified patches into the workflows they already have. Fixes that come back from a Clearinghouse request are built to apply to older software versions a customer still runs.

Gunnar Hellekson, vice president and general manager of Lightwell at Red Hat, said AI agents “shifted the threat landscape overnight” by going after old dependencies at machine speed. Age and stability do not protect a codebase, he argued. Finding the bugs is “only half the battle,” Hellekson said, and the real work is backporting fixes into applications already in production so customers “do not have to pick between security and uptime.”

Lightwell dates backk to May, when IBM and Red Hat committed $5 billion and more than 20,000 engineers to securing open-source software. Lightwell Network went generally available in July with a launch catalog of more than 6,500 remediated dependencies, and a tier called Clearinghouse Premier opened to financial services companies on a limited basis at the same time. IBM and Red Hat extended Lightwell to universities, nongovernmental organizations and think tanks at no cost in August.

View original article on siliconangle.com

Most Recent

BattleBots builders turn to AI simulation to win fights before entering the box

AI networking and GPU simulation let BattleBots builders test weapons and materials before a fight, says Rob Bahr of BattleBots Inc. on theCUBE.

Oct 6, 2026

NetApp aims to make legacy data AI-ready without a rebuild

NetApp aims to make legacy data AI-ready without a rebuild - SiliconANGLE NetApp aims to turn legacy enterprise data into AI-ready data without moving it, using unified storage, built-in protection and a single console.

Oct 6, 2026

Seattle startup Chiplytics lands $4.5M to catch fake and flawed chips before they hit the market

Seattle startup Chiplytics today announced $4.5 million in funding to support the deployment of its microelectronics verification technology and the opening of an inspection facility in Bellport, N.Y. The company provides authentication and quality screening of semiconductor chips and other critical

Oct 6, 2026

Tanium expands Security Operations with Atlas-powered detection, response and hunting

Endpoint management and security company Tanium Inc. today expanded its Security Operations portfolio with new detection, response and threat-hunting tools built on its Tanium Atlas agentic artificial intelligence platform. The release is Tanium’s attempt to move customers closer to what it calls a

Oct 6, 2026

Similar Posts

Socket lands a fresh $40M to scan software for security flaws

The software supply chain, which comprises the components and processes used to develop software, has become precarious. According to one recent survey, 88% of companies believe poor software supply chain security presents an “enterprise-wide risk” to their organizations. Open source supply chain components are especially fraught, thanks to the logistical hurdles in keeping each component well-maintained. Security firm Synopsys found in its 2023 report that 89% of businesses’ codebases containe

Oct 22, 2024

IBM and Red Hat Commit $5 Billion to Redefine the Future of Open Source in the AI Era

IBM and Red Hat announced Project Lightwell, a $5 billion commitment backed by new frontier AI capabilities to strengthen open source software security in the AI era.

May 27, 2026

Vulnerability-free container image startup Echo acquires Minimus

Echo Software Ltd., a startup that’s using artificial intelligence agents to secure container images, today announced it’s acquiring the assets of Minimus Inc. following the company’s wind-down. The core proposition of Echo is that it uses AI agents to replace vulnerable upstream open-source compone

Aug 27, 2026

Visa ships a security AI that patches production code before any human reviews it

Visa's open-source security harness now finds the vulnerability, writes the fix, and turns an adversarial panel on its own patch before any human reviews it. The whole loop ships on by default. A plain scan of the Visa Vulnerability Agentic Harness runs all 11 stages and edits source files in the ta

Aug 27, 2026