Anthropic AI Finds 3,900 Open Source Bugs; IBM Commits $5B
TL;DR. Anthropic's Mythos Preview AI model identified nearly 3,900 critical open-source vulnerabilities, prompting IBM and Red Hat's $5 billion Project Lightwell. - Project Lightwell aims to fix open-source security issues before attackers exploit them, impacting 40,000 CVEs projected for 2024. - The initiative includes a security clearinghouse where enterprises can report vulnerabilities to IBM for discreet remediation. - IBM will backport fixes to specific dependency versions companies use, strengthening upstream open-source communities. - The effort addresses a growing remediation gap due to rapid AI-driven vulnerability discovery outpacing human security teams.
- Anthropic's Mythos Preview AI model discovered almost 3,900 high or critical-severity vulnerabilities in open-source software.
- IBM and Red Hat committed $5 billion to Project Lightwell, aimed at securing enterprise open-source software with AI tooling.
- Project Lightwell establishes a security clearinghouse for enterprises to report vulnerabilities, with IBM developing and backporting fixes.
- The initiative addresses the accelerating rate of AI-driven vulnerability discovery, which is outpacing human remediation efforts.