IBM launches Project Lightwell with $5 billion investment to fix open source vulnerabilities
2026-06-04 10:03
Favorite

en.Wedoany.com Reported - IBM announced on Thursday a $5 billion investment to launch Project Lightwell, aimed at discovering and fixing vulnerabilities in open source software packages widely used in the business world. Through this project, IBM will create a trusted enterprise-grade information exchange hub, combining a global team of engineers to identify and fix vulnerabilities at scale, and using artificial intelligence to verify and test patches before deployment. Enterprises can subscribe to the patch program for automated deployment of fixes.

Photo shows IBM headquarters in downtown San Francisco on August 21, 2019.

IBM CEO Arvind Krishna stated that open source is the backbone of the digital economy, and the project aims to enhance trust in systems that support businesses, governments, and society. IBM has already tested the program with major financial institutions including Bank of America, Goldman Sachs, JPMorgan Chase, Mastercard, and Visa. The experience gained from these tests will guide how to identify, verify, and fix vulnerabilities at scale within complex software supply chains.

The information exchange hub of Project Lightwell will provide enterprises with a secure environment to discuss security issues related to open source code. This mechanism aims to accelerate the time it takes for open source maintainers to understand issues while preventing threat actors from exploiting vulnerabilities. As open source software becomes increasingly critical to global technology stacks, hackers are targeting it more frequently. These exploitation activities highlight weaknesses in the open source ecosystem, where most volunteer developers struggle to keep up with vulnerability reports, and AI-driven vulnerability discovery further exacerbates the problem.

As one of the world's largest users of open source code, IBM's launch of this project comes four years after tech giants agreed to develop multi-year plans to increase investment in open source security. Three months ago, major AI companies announced $12.5 million in funding to help alleviate the challenges their products pose to open source maintainers.

This article is compiled by Wedoany. All AI citations must indicate the source as "Wedoany". If there is any infringement or other issues, please notify us promptly, and we will modify or delete it accordingly. Email: news@wedoany.com