惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 【当耐特】
阮一峰的网络日志
阮一峰的网络日志
博客园 - 三生石上(FineUI控件)
Engineering at Meta
Engineering at Meta
S
Security Archives - TechRepublic
S
Schneier on Security
I
Intezer
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
D
Docker
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
U
Unit 42
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
L
LINUX DO - 热门话题
小众软件
小众软件
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
AWS News Blog
AWS News Blog
Know Your Adversary
Know Your Adversary
C
CERT Recently Published Vulnerability Notes
T
The Blog of Author Tim Ferriss
The Hacker News
The Hacker News
Simon Willison's Weblog
Simon Willison's Weblog
Microsoft Azure Blog
Microsoft Azure Blog
P
Privacy International News Feed
V
V2EX
博客园 - Franky
博客园 - 聂微东
MyScale Blog
MyScale Blog
H
Help Net Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
Tenable Blog
T
Tailwind CSS Blog
L
Lohrmann on Cybersecurity
量子位
The Cloudflare Blog
D
DataBreaches.Net
NISL@THU
NISL@THU
D
Darknet – Hacking Tools, Hacker News & Cyber Security
B
Blog RSS Feed
V
Vulnerabilities – Threatpost
V
Visual Studio Blog
Cyberwarzone
Cyberwarzone
P
Proofpoint News Feed
T
Threat Research - Cisco Blogs
Cisco Talos Blog
Cisco Talos Blog
A
Arctic Wolf
P
Privacy & Cybersecurity Law Blog
Recorded Future
Recorded Future
Scott Helme
Scott Helme
罗磊的独立博客

The Stack

OpenAI acquires German startup to spin up cloud dev environments for better agent control STACKUP: The Stack's weekly tech startups and funding wrap Microsoft CEO warns over concentrated AI model dependency Internet pillar cURL takes a summer holiday from security Anthropic knee-capped by abrupt export controls Months after losing its CEO, now Adobe's CFO gets poached Oracle zero-day exploited for nearly two weeks by Shiny Hunters HM Treasury needs a new CTO, the salary is below average AMD joins UK's Sovereign AI train with Cambridge "AI lab" Oracle PeopleSoft vulnerability exploited: 100s reported hit Oracle reports a $638 billion backlog The UK wants to record court hearings - but not an actual plan Bank of England restarts stalled £24m data collection refresh Anthropic warns LLMs can crank out N-day exploits cheap and fast Defender under Attack: June's Patch Tuesday in the spotlight The CISO needs to get focused on business resilience LibreOffice denounces Euro-Office as Microsoft Trojan Horse Apple's revamped Siri AI leans on Google models and cloud AI could be driving IT hiring in Europe, new report finds UK calls for “device-based” nude controls Cult browser project Ladybird cuts off code community UK gets $1.5bn AI Hardware Plan, and a big-coalition sovereign model plan too STACKUP: The Stack's weekly tech startups and funding wrap Fake IT support staff are walking in to US law firms to steal data Apple found a way to sharply cut token use Apache Livy graduates to Top-level project for Spark support Supabase raises $500m, looks to horizontal Postgres scaling GitLab Field CTO on unlikely customers pulling ahead with AI Killing the card? The UK’s banks eye a payments revolution MPs call on UK government to drop £330m Palantir-NHS deal The Tokenomics Foundation is coming for AI Finops Microsoft's new models give it a better moat The EU dropped its latest tech sovereignty package – what to know HMRC digital transformation: new customer service platform Tokenmaxxing is dead. Finops for AI is emerging slowly. This database company wants to take on Palantir ChatGPT 5.5 and Codex now on Bedrock for easy AWS access Multicloud gets sweeter with a 500 Mbps free private link Alphabet raising $80bn to keep up with ballooning AI CapEx How to get visibility and isolation for AI in Kubernetes Red Hat packages injected with worm in supply chain attack STACKUP: The Stack's weekly tech startups and funding wrap Dell COO says “pain” of price hikes will continue NVIDIA, MS tease tighter agent-native security primitives in Windows Sumedh Thakar: CISOs need to think Shock, WoW, and "AWE" Microsoft turns down temperature amid Nightmare Eclypse row IBM to put $5bn and 20,000 engineers into OSS security fight MongoDB eyes more federal work, snaps up partner Clarity Chinese cyber victims overlapping with industrial strategy - ESET Microsoft stirs a hornets nest over “criminal” zero day disclosure threats Snowflake's AI coding tool is "flywheel" for data platform “Headless” Salesforce hits 1 trillion API calls MySQL gets a foundation with no Oracle, but Alibaba presense GCHQ teases “blueprint” for national AI cyber defense BNP Paribas moves to “zero copy” data model Snowflake joins US federal discount scheme Can Dropbox's new CEO save it from stagnation? Zscaler CEO drools over Mythos tailwind, but Jason's and Joe's departures spook markets Google chases a Kubernetes moment for AI agents UKHSA sticks with Oracle after outsourcing payroll Lenovo eyes “personal AI super agents” in $100 billion drive US eyes physics-based safeguards for water cyber threats Accenture beats IBM in Post Office's latest bid to ditch Horizon
Red Hat's $5 billion answer to Mythos: fix all the code
Phillip de Wet · 2026-06-16 · via The Stack

In late May, Red Hat and its parent IBM announced they would allocate $5 billion and 20,000 engineers to Project Ligthwell, "to help enterprises secure open source software" alongside a group of big-target financial services companies.

The project, which the companies describe as "a trusted enterprise clearinghouse" for open source code, is exactly what Red Hat has always done: backporting security patches and upstreaming them, securing customers first and improving the entire ecosystem over time.

Even the mechanism is similar. Project customers point their build tools to the Red Hat registry and Red Hat takes care of scanning, backports, and patching, plus managing the upstream contributions. 

See also: IBM muscles into OSS security space with $5 billion “Lightwell” project

But the project's plans to address the broader application landscape, including "independent libraries, language toolchains, AI frameworks, and data streaming platforms", is were it diverges from securing a discrete set of packages.

And that complicates matters – starting with who gets to decide what is covered.

When it expands beyond the early adopters, Red Hat chief product officer Ashesh Badani told The Stack Lightwell will likely have two contract tiers. Those who only need the patches will be able to choose a "read-only mode", with a premium option for those who want to be involved in determining which packages Lightwell will include.

Get the full story: Subscribe for free

Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.

Subscribe now