IBM, Red Hat, and Palo Alto Networks Join Forces on Project Lightwell to Combat Software Vulnerabilities
IBM, Red Hat, and Palo Alto Networks have unveiled an expanded partnership aimed at enabling organizations to detect and neutralize software vulnerabilities across multiple environments—from open-source applications and commercial software to operational technology systems and healthcare platforms.
The initiative integrates Palo Alto Networks' Virtual Patching technology with Project Lightwell, IBM and Red Hat's comprehensive open-source security program, creating a layered defense strategy. This approach pairs immediate network-level threat blocking with longer-term software remediation capabilities, allowing enterprises to manage emerging security risks more effectively.
The acceleration of vulnerability discovery through artificial intelligence has fundamentally altered the security landscape. Machine learning algorithms can now identify flaws across vast codebases far more rapidly than security teams can deploy fixes, creating significant supply-chain exposure for organizations worldwide.
Nikesh Arora, Chief Executive and Chairman of Palo Alto Networks, emphasized the urgency: "The window between when a flaw is discovered and when attackers exploit it has contracted from weeks to mere minutes. Conventional patching approaches cannot match this pace. Our collaboration with IBM and Red Hat restores the defensive advantage by enabling rapid threat neutralization at the network level while maintaining business continuity."
Arvind Krishna, Chairman and Chief Executive of IBM, noted that Project Lightwell was conceived to fortify the open-source software ecosystem that underpins modern enterprise operations. "By partnering with Palo Alto Networks, we extend protection from the source code itself through to network defenses. This integrated approach delivers what organizations need to operate securely in an AI-driven threat environment: swift, automated resilience combined with the careful validation necessary for safe system updates."
The partnership leverages IBM and Red Hat's $5 billion investment in open-source security infrastructure alongside Palo Alto Networks' security capabilities. The resulting framework operates through a coordinated "shield-and-fix" model: Palo Alto Networks deploys a virtual patch at the network layer to stop exploitation attempts, while Project Lightwell provides remediation software for open-source components that organizations can test and deploy within their own infrastructure.
The collaboration delivers several key protective measures. Coverage spans open-source software, proprietary applications, operational technology environments, and connected devices. Organizations gain access to virtual patch protection before formal software updates become available, reducing risk during the remediation window. Network-level defenses can be activated within a single day of vulnerability discovery, with the partners targeting further reductions in the time between validated identification and deployed protection.
The three companies intend to establish secure channels for sharing vulnerability intelligence among software vendors, technology providers, and security teams. This framework is expected to facilitate coordinated vulnerability disclosure, expedite the development of protective measures, and generate anonymized data regarding real-world exploitation patterns.
IBM Security Services will complement these technical capabilities by offering advisory and implementation support. These services help organizations assess which vulnerabilities pose the greatest business risk and chart the most effective remediation course. Working in concert with Palo Alto Networks' virtual patching and Project Lightwell's software remediation, IBM Security Services assists customers in prioritizing, implementing, and validating protections across complex technology environments.
Compare options


