Updated
Updated · InfoWorld · Oct 9
Lightwell Finds 400+ Java Flaws, Opens Code Review Service as AI Exploits Old Dependencies
Updated
Updated · InfoWorld · Oct 9

Lightwell Finds 400+ Java Flaws, Opens Code Review Service as AI Exploits Old Dependencies

2 articles · Updated · InfoWorld · Oct 9

Summary

  • More than 400 previously undiscovered vulnerabilities have been found by Lightwell in widely used Java libraries, and IBM and Red Hat are now asking customers to submit code dependencies to its new Lightwell Clearinghouse for review.
  • AI agents exploiting old dependencies at machine speed drove the push, with Lightwell saying the harder task is backporting fixes into live production applications without forcing customers to trade security for uptime.
  • A critical example is Thymeleaf’s sandbox-bypass flaw, discovered in April and rated 9.1 on the CVSS scale, which illustrates the kind of high-severity bug the service aims to catch and remediate.
  • IBM and Red Hat said in May they would commit 20,000 engineers and $5 billion to Lightwell, positioning the effort as both a vulnerability-finding and remediation project in a growing market that also includes Azul.

Insights

Can AI-driven backports save legacy Java apps from autonomous hackers, or are we just creating a massive shadow ecosystem of patched code?
If upgrading breaks your application but staying puts you at risk, can Lightwell's new clearinghouse truly offer a frictionless escape route?
When autonomous AI exploits legacy vulnerabilities at machine speed, is IBM's five-billion-dollar gamble enough to outpace the next generation of cyber threats?