HomeMalware & ThreatsIBM Invests in Multi-Billion-Dollar Open-Source Patch Business

IBM Invests in Multi-Billion-Dollar Open-Source Patch Business

Published on

spot_img

Governance & Risk Management,
Patch Management

IBM Charges Enterprises $1M Annually for Validated Legacy Open-Source Patches

IBM Invests in Multi-Billion-Dollar Open-Source Patch Business
Image: Shutterstock

In a notable development for the world of cybersecurity, IBM has positioned itself to capitalize on the burgeoning multi-billion-dollar market of addressing flaws in open-source software. According to the company’s CEO, Arvind Krishna, reporting vulnerabilities and deploying patches for such software is a significant avenue for growth that IBM is keen to explore. This revelation was made during a recent investor meeting, highlighting IBM’s aggressive approach to monetize this critical aspect of technology.

In collaboration with its subsidiary Red Hat, IBM unveiled a $5 billion initiative named Lightwell, which is aimed at verifying, disclosing, and remediating vulnerabilities in open-source software packages. The initiative is structured to support various companies that utilize open-source components in their software solutions. The financial commitment to this initiative signals IBM’s long-term vision of leading the open-source patching services market, something that is gaining traction among enterprises that prioritize cybersecurity.

Furthermore, organizations wishing to access the remediated open-source packages are faced with an annual subscription fee of $1 million. This has already attracted a number of keen financial institutions, as CEO Krishna noted during his comments. “We looked at this historically, and we said that is the place that we want to go play,” he stated, underscoring the market’s potential.

Since its launch on May 28, Lightwell has reportedly provided patches for over 7,500 package versions. Krishna revealed that this accomplishment was made possible through the joint efforts of 20,000 engineers supported by cutting-edge AI technologies. These strides in technology have enabled a faster and more efficient means of identifying vulnerabilities, marking a significant shift in the industry landscape.

In addition to IBM and Red Hat, Palo Alto Networks is also collaborating on this initiative. The partnership seeks to enhance cybersecurity by offering virtual protections at the network layer that block attempted exploits, while Lightwell distributes the necessary software patches for organizations to test and implement. Red Hat emphasized this collaboration in a June press release, showcasing a unified effort in bolstering enterprise security.

Industry experts recognize a palpable need for robust cybersecurity solutions. Kara Sprague, CEO of the bug bounty platform HackerOne, noted that the demand for such services is truly substantial and extends beyond any single entity or product. Sprague also highlighted a significant change in the vulnerability discovery process, thanks to advancements in AI technology, which has facilitated faster and cheaper detection of flaws. This shift has essentially pushed the bottleneck down the chain to remediation; the pressing need for organizations to have access to tested patches is more critical than ever.

Krishna further iterated that systematic patching of open-source software lacked clear economic incentives in the past, primarily due to the labor-intensive requirements involved. However, the landscape has changed, and organizations are now incentivized to seek reliable solutions. IBM anticipates onboarding hundreds of clients in the initial phases of the Lightwell initiative, using this burgeoning client base as a key driver for identifying the necessary patches, thereby enhancing their services further.

He pointed out the sheer volume of open-source code now running in comparison to proprietary solutions, asserting that open-source software has surpassed its proprietary counterparts in volume. However, he acknowledged that the entities currently monetizing this vast resource remain limited, signaling a significant opportunity for IBM.

In the broader context, the Defense Advanced Research Projects Agency (DARPA) has been investing in cybersecurity ventures through initiatives like the Artificial Intelligence Cyber Challenge. This effort aims to nurture AI systems that can automatically detect and rectify software vulnerabilities. Emerging companies like Artiphishell, formed as a result of this initiative, resonate with IBM’s market assessment, indicating a collective acknowledgment of the urgent need for sophisticated open-source vulnerability solutions.

However, challenges persist within the open-source community, particularly regarding silent vulnerability fixes—bugs that developers unknowingly address without realizing their exploit potential. Because these fixes often go unreported, organizations running older software versions remain vulnerable without public awareness of potential risks. Additionally, updates to patches may not align with legacy software, necessitating specialized knowledge to maintain functionality while applying necessary fixes.

Artiphishell’s CEO, Wil Gibbs, commented on the hurdles that still lie ahead in ensuring proper and effective remediation of vulnerabilities. He acknowledged IBM’s proactive approach but emphasized that much work remains to secure open-source software adequately. The complexities involved highlight the intricate balance between commercial needs and community-driven open-source efforts, a challenge that will require engaged collaboration to navigate successfully.

Source link

Latest articles

FakeAgent Campaign Utilizes Malicious Claude Artifact to Distribute SectopRAT to 29 Organizations

Malvertising Campaign Exploits Anthropic's Claude.ai to Distribute SectopRAT Trojan Researchers at Huntress recently uncovered a...

Iranian Hackers Attack Siemens and Schneider Industrial Systems

Iranian Cyber Campaign Targets US Critical Infrastructure Recent reports highlight a concerning trend involving Iranian...

CISA Issues New Warning About Exposed PLCs

Internet-Exposed Programmable Logic Controllers Present an Easy Target for Hackers In a troubling revelation this...

Security Teams Transition from AI-Only to Hybrid Penetration Testing

Shift from Full AI Automation in Penetration Testing: A Return to Human Expertise In a...

More like this

FakeAgent Campaign Utilizes Malicious Claude Artifact to Distribute SectopRAT to 29 Organizations

Malvertising Campaign Exploits Anthropic's Claude.ai to Distribute SectopRAT Trojan Researchers at Huntress recently uncovered a...

Iranian Hackers Attack Siemens and Schneider Industrial Systems

Iranian Cyber Campaign Targets US Critical Infrastructure Recent reports highlight a concerning trend involving Iranian...

CISA Issues New Warning About Exposed PLCs

Internet-Exposed Programmable Logic Controllers Present an Easy Target for Hackers In a troubling revelation this...