{"id":5269,"date":"2026-10-08T20:42:59","date_gmt":"2026-10-08T20:42:59","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/10\/08\/ibm-and-red-hat-disclose-discovery-of-more-than-400-java-vulnerabilities\/"},"modified":"2026-10-08T20:42:59","modified_gmt":"2026-10-08T20:42:59","slug":"ibm-and-red-hat-disclose-discovery-of-more-than-400-java-vulnerabilities","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/10\/08\/ibm-and-red-hat-disclose-discovery-of-more-than-400-java-vulnerabilities\/","title":{"rendered":"IBM and Red Hat Disclose Discovery of More Than 400 Java Vulnerabilities"},"content":{"rendered":"<div><img data-opt-id=319188346  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/10\/ibm_red_hat_vulnerabilities_770x330.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=1537329914  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/10\/ibm_red_hat_vulnerabilities_770x330-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p><span>IBM and Red Hat this week reported they have <\/span><a href=\"https:\/\/www.redhat.com\/en\/about\/press-releases\/ibm-and-red-hat-remediate-more-400-previously-unknown-open-source-vulnerabilities\"><span>identified and remediated more than 400 previously unknown vulnerabilities in Java libraries<\/span><\/a><span> since launching a Lightwell initiative earlier this year.<\/span><\/p>\n<p><span>Additionally, Lightwell Clearinghouse, a program that enables IT organizations to submit specific open source software dependencies for priority review and remediation, is now generally available.<\/span><\/p>\n<p><span>Ben Bread, a senior principal product manager for Red Hat, said the 400 unknown vulnerabilities represent twice the number that was expected to be uncovered and there will undoubtedly be more to come as artificial intelligence (AI) tools are used to analyze more legacy code.<\/span><\/p>\n<p><span>Additionally, DevSecOps teams should expect a similar number of vulnerabilities to be discovered in libraries created using other programming languages, he added.<\/span><\/p>\n<p><span>While IT teams are contracting with IBM and Red Hat to fix vulnerable code in their IT environments, the code fixes developed are being contributed back to upstream open source projects under responsible disclosure protocols.<\/span><\/p>\n<p><span>IBM and Red Hat are not disclosing how many organizations are relying on them to help generate the code needed to remediate vulnerabilities in their legacy codebases, but they are delivered via secure repositories that connect to existing processes for building and deploying software. Via the Lightwell Network, IT teams can access verified patches, bring remediated software into their existing workflows and establish an ongoing process for addressing vulnerabilities. The more automated those processes are using best DevSecOps practices, the faster that remediation effort becomes, noted Bread.<\/span><\/p>\n<p><span>In fact, the ongoing discovery of so many vulnerabilities in legacy code will prove to be a tipping point that spurs adoption of scanners and test automation platforms as the building and applying of patches becomes a more standard element of software engineering workflows, he added. Organizations that today require three months to validate a code fix are not going to be able to keep pace with the vulnerability deluge, noted Bread.<\/span><\/p>\n<p><span>It\u2019s not clear at what rate vulnerabilities are being exploited in the age of AI, but the assumption is cybercriminals will increasingly use AI models to both discover and exploit vulnerabilities in hours. As such, rather than patching software once a month to fix vulnerabilities, DevSecOps teams now need to be continuously patching software as more issues are continuously surfaced, said Bread.<\/span><\/p>\n<p><span>Unfortunately, there are still many organizations that are not taking the threats AI poses to application security seriously enough, noted Bread. Many of those organizations will soon discover just how many vulnerabilities exist in codebases that many are assuming is more secure than it actually is. It\u2019s only when organizations are able to preview the vulnerabilities and exploits that AI models are able to discover and create that the real scope of the issue becomes apparent, added Bread.<\/span><\/p>\n<p><span>More challenging still, the cost of discovering a vulnerability is now as low as $30, so the economics of application security only continue to favor the attacker, he noted.<\/span><\/p>\n<p><span>Hopefully, it won\u2019t require some type of catastrophic event for more organizations to pay more attention to application security in the age of AI. The issue, of course, is that it\u2019s not so much a question of when a breach will occur but rather how serious it is given the nature of the vulnerability being exploited.<\/span><\/p>\n<p><a href=\"https:\/\/devops.com\/ibm-and-red-hat-disclose-discovery-of-more-than-400-java-vulnerabilities\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>IBM and Red Hat this week reported they have identified and remediated more than 400 previously unknown vulnerabilities in Java [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5270,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-5269","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5269","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=5269"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5269\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/5270"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=5269"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=5269"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=5269"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}