STOCK TITAN

IBM and Red Hat Offer Lightwell at No Charge to Universities, NGOs and Think Tanks

(Neutral)
(Neutral)
Tags

IBM (NYSE: IBM) and Red Hat announced a program to provide Lightwell, their AI-driven open source vulnerability remediation service, at no charge to over 185 leading U.S. research universities and 100 major NGOs and think tanks. Eligible institutions gain access to a library of remediated, digitally signed and validated open source dependencies tailored to the software versions they already run, without sharing proprietary code, data or research.

Launched in May 2026 with a $5 billion commitment and more than 20,000 engineers, Lightwell has expanded from 6,500 to over 8,000 validated and remediated package versions, including fixes for 64 previously undisclosed vulnerabilities. IBM and Red Hat plan to begin onboarding eligible institutions in August 2026, building on collaborations with major global banks and technology partners.

Loading...
Loading translation...

Positive

  • $5 billion Lightwell commitment backed by over 20,000 engineers
  • Validated remediated packages grew from 6,500 to over 8,000 versions
  • Lightwell includes fixes for 64 previously undisclosed vulnerabilities
  • Program extends no-charge Lightwell access to over 285 U.S. institutions

Negative

  • None.

News Explained

The announced package adds source code and compliance documentation, while remediation fixes are routed to originating communities for review.

The announcement says eligible institutions will receive source code and compliance documentation alongside Lightwell’s remediated dependencies, adding concrete integration materials to the announced program.

Under Red Hat’s “upstream-always” model, fixes are submitted to the originating open source communities for review and acceptance.

Thus, the stated delivery process includes both materials for participating institutions and a route for contributing fixes back to the projects that produced the software.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

Access to Lightwell will help strengthen the open source software supporting research, education and mission-critical work

Key Facts

  • IBM and Red Hat will offer Lightwell at no charge to over 185 leading research universities and 100 major nongovernmental organizations (NGOs) and think tanks in the United States.
  • Lightwell combines AI-driven automation with human engineering expertise to identify, validate and remediate open source software vulnerabilities.
  • Participating institutions can access validated fixes for the software versions they currently run, helping reduce the need for disruptive upgrades.
  • Lightwell operates within an institution's existing environment and does not require access to its proprietary source code, data or research.

ARMONK, N.Y. and RALEIGH, N.C., Aug. 4, 2026 /PRNewswire/ -- IBM (NYSE: IBM) and Red Hat today announced a new program providing Lightwell at no charge to over 185 leading research universities and 100 major nongovernmental organizations (NGOs) and think tanks. Eligible institutions can access Lightwell's library of validated fixes for open source software vulnerabilities, helping them secure the software and focus resources supporting research, education, humanitarian programs and other public-interest work.

IBM Corporation logo.

Open source software underpins university research environments, teaching platforms and campus operations, as well as the systems NGOs and think tanks use to conduct policy research and serve communities around the world. Yet many of these institutions lack the resources and specialized engineering capacity required to keep pace as AI accelerates the discovery and potential for exploitation of software vulnerabilities.

Through this initiative, eligible institutions will receive access to Lightwell including a growing library of remediated, digitally signed and validated open source dependencies that can be integrated into existing software pipelines. Lightwell is designed to deliver validated fixes for the specific software versions organizations already run, helping them address vulnerabilities without forcing disruptive upgrades or requiring access to their proprietary code, data or research.

"Lightwell combines automated remediation with deep open source engineering expertise and contributes fixes back upstream," said Matt Hicks, President and Chief Executive Officer, Red Hat. "Expanding access will help strengthen both participating institutions and the open source communities on which they depend."

How Lightwell Helps Secure Open Source Software

IBM and Red Hat launched Lightwell in May 2026 with a $5 billion commitment and a global force of more than 20,000 engineers to help secure the open source software supply chain. In July, the companies introduced Lightwell and Lightwell Clearinghouse Premier, extending automated vulnerability remediation to the open source packages organizations use in active production. Since its introduction, Lightwell has expanded the scale of validated open source remediation available to participating organizations, from 6,500 to more than 8,000 validated and remediated package versions, including fixes for 64 previously undisclosed vulnerabilities.

Lightwell combines a generative AI-powered remediation engine with human engineering expertise to identify, validate and remediate vulnerabilities across critical software dependencies. For participating universities, NGOs and think tanks, the initiative is intended to help:

  • Reduce the time and specialized engineering effort required to address open source vulnerabilities;
  • Apply validated fixes to current and long-lived software versions, reducing the need for disruptive upgrades;
  • Receive digitally signed binaries, source code and compliance artifacts, including Software Bills of Materials (SBOMs); and
  • Strengthen the broader open source ecosystem through Red Hat's upstream-always model, under which fixes are submitted to originating communities for review and acceptance.

Lightwell works within an institution's existing environment and does not require IBM or Red Hat to access its proprietary source code, data or research. Participating institutions will receive information and support to help them assess their open source environments and integrate applicable remediated packages into existing workflows.

Building on a Growing Global Network

The expanded access program builds on Lightwell's work with leading financial institutions, including Bank of America, BNY, Citi, Goldman Sachs, JPMorganChase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa and Wells Fargo.

A growing technology ecosystem—including Amazon Web Services (AWS), AMD, F5, GitLab, Intel, JFrog, Microsoft, NVIDIA, Palo Alto Networks and ServiceNow—is also collaborating with IBM and Red Hat on Lightwell. Together, these organizations are working to help security fixes move across development tools, cloud environments, deployment pipelines and network controls.

IBM and Red Hat will begin onboarding for eligible institutions in August 2026. To learn more about Lightwell, visit ibm.com/products/lightwell and redhat.com/en/lightwell.

Frequently Asked Questions

What is Lightwell?
Lightwell is an IBM and Red Hat initiative that combines AI-driven automation with human engineering expertise to identify, validate and remediate vulnerabilities in open source software.

Who is eligible for no-charge Lightwell access?
The program is being made available to over 185 leading research universities and 100 major NGOs and think tanks in the U.S.

What will participating institutions receive?
Eligible institutions will receive access to Lightwell and its growing library of remediated, digitally signed and certified open source dependencies, along with source code and compliance documentation.

Does Lightwell require access to an institution's proprietary code or data?
No. Lightwell works within an institution's existing environment and does not require IBM or Red Hat to access its proprietary source code, data or research.

About IBM
IBM is a leading provider of global hybrid cloud and AI, and consulting expertise. We help clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs and gain the competitive edge in their industries. Thousands of governments and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM's hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently and securely. IBM's breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and consulting deliver open and flexible options to our clients. All of this is backed by IBM's long-standing commitment to trust, transparency, responsibility, inclusivity and service. Visit www.ibm.com for more information.

About Red Hat
Red Hat is the open hybrid cloud technology leader, delivering a trusted, consistent and comprehensive foundation for transformative IT innovation and AI applications. Its portfolio of cloud, developer, AI, Linux, automation and application platform technologies enables any application, anywhere—from the datacenter to the edge. As the world's leading provider of enterprise open source software solutions, Red Hat invests in open ecosystems and communities to solve tomorrow's IT challenges. Collaborating with partners and customers, Red Hat helps them build, connect, automate, secure and manage their IT environments, supported by consulting services and award-winning training and certification offerings.

Media contact: 

Michele Brancati
IBM
mbrancati@ibm.com 

John Terrill
Red Hat
terrill@redhat.com 

 

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/ibm-and-red-hat-offer-lightwell-at-no-charge-to-universities-ngos-and-think-tanks-302842466.html

SOURCE IBM

FAQ

What is IBM's Lightwell and how does it secure open source software?

Lightwell is an IBM and Red Hat initiative that uses AI-driven automation and human engineering to remediate open source vulnerabilities. According to IBM, it delivers validated, digitally signed fixes for specific dependency versions, helping organizations address security issues without disruptive upgrades or exposing proprietary code and data.

Who can access IBM Lightwell at no charge under the August 4, 2026 program (IBM)?

IBM and Red Hat are offering Lightwell at no charge to over 185 leading U.S. research universities and 100 major NGOs and think tanks. According to IBM, these institutions can use Lightwell’s validated remediation library to secure open source software used in research, education and mission-focused operations.

What do participating universities and NGOs receive from IBM's Lightwell program (IBM)?

Participating institutions receive access to Lightwell and its growing library of remediated, digitally signed and validated open source dependencies. According to IBM, they also obtain source code and compliance artifacts, including Software Bills of Materials (SBOMs), to integrate security fixes into existing software pipelines and workflows.

Does IBM's Lightwell require access to an institution's proprietary code or data (IBM)?

Lightwell does not require IBM or Red Hat to access an institution’s proprietary source code, data or research. According to IBM, Lightwell operates within the existing environment, supplying remediated open source packages that organizations can integrate without exposing confidential intellectual property or sensitive information.

How large is IBM's investment and engineering commitment to Lightwell (IBM)?

IBM and Red Hat launched Lightwell with a $5 billion commitment and more than 20,000 engineers. According to IBM, this global engineering force supports identifying, validating and remediating vulnerabilities across critical open source dependencies, scaling the availability of digitally signed fixes for participating organizations worldwide.

How has IBM Lightwell's remediation library grown since launch (IBM)?

Lightwell’s validated remediation library has expanded from 6,500 to more than 8,000 remediated package versions. According to IBM, this includes fixes for 64 previously undisclosed vulnerabilities, increasing the breadth of open source components that participating organizations can secure without undertaking disruptive version upgrades.