IBM and Red Hat are investing $5BN in securing open-source software as they look to help enterprises confront the new generation of AI-driven cyber threats that could directly affect customer experience and trust.
The initiative, called Project Lightwell, comes in response to growing concern over Anthropic’s recent warnings about its Claude Mythos AI model, which the company says has identified nearly 3,900 high- or critical-severity vulnerabilities in open-source software.
Anthropic’s Project Glasswing initiative is exploring Mythos’s capabilities to autonomously identify and exploit software vulnerabilities and how advanced AI systems could transform offensive cybersecurity approaches, particularly through automated vulnerability discovery at scales previously impossible for human researchers. Anthropic’s findings have intensified warnings across the technology sector that enterprises are not prepared for how quickly frontier AI systems could accelerate vulnerability discovery and exploitation.
IBM and Red Hat’s initiative incorporates learnings from Project Glasswing as well as OpenAI’s Trust Access for Cyber.
AI’s Threat to Enterprise Infrastructure Based on Open-Source Software
Open-source software supports the digital infrastructure behind customer-facing banking apps, retail platforms, cloud services, AI assistants, contact centers and digital identity systems. More than 90 percent of Fortune 500 companies rely on open-source software according to IBM, making supply chain security increasingly intertwined with customer trust and business continuity.
A major vulnerability affecting widely used open-source components could quickly cascade into outages, fraud exposure, degraded customer journeys or large-scale trust failures.
IBM and Red Hat said Project Lightwell is designed to create a “trusted enterprise clearinghouse backed by new frontier AI capabilities” that helps organizations to identify, and fix vulnerabilities in open-source software before they disrupt enterprise operations and customer services. The announcement stated:
“The clearinghouse will serve as a security coordination layer, using advanced AI capabilities to validate and test fixes across an unprecedented volume of open source code.”
At a time when many technology firms are using AI to reduce their engineering headcount, the companies said they will deploy a team of more than 20,000 engineers, “positioning technical engineering capacity as a premium strategic asset and a source of market differentiation.”




