IBM and Red Hat announced today they have identified and remediated more than 400 previously unknown vulnerabilities across popular Java libraries.

Red Hat’s Lightwell open-source software supply chain initiative that relies on specialized AI agents was able to accelerate the discovery of 400+ vulnerabilities affecting popular Java code. They announced this feat today as part of their promoting Lightwell Clearinghouse to GA, which is an enterprise service for their customers to submit open-source software dependencies for priority review and remediation.

From today’s announcement:

"The milestone addresses a growing business risk. As autonomous AI agents become capable of combining several lower-risk software weaknesses into a more serious attack, companies need to do more than identify vulnerabilities. They need a practical way to develop, test and deploy fixes in the software that supports critical applications."

Details are light on all the specific vulnerabilities uncovered. They appear to be ramping up fast in their Lightwell efforts as in the embargoed press release days ago was at 300+ vulnerabilities and then increased to 400+ vulnerabilities. Their AI laden press release announcing these 400+ vulnerabilities can be found on the IBM Newsroom.

  • stravanasu@lemmy.ca
    link
    fedilink
    arrow-up
    3
    ·
    25 minutes ago

    I wonder how many new vulnerabilities the fixes (likely LLM-generated) to these vulnerabilities will introduce.

  • SocialistVibes01@lemmy.mlOP
    link
    fedilink
    arrow-up
    8
    ·
    edit-2
    1 hour ago

    I wish the PR was clearer about what kind of bugs were discovered and whether they’re could ever be triggered.