IBM and Red Hat assign 20,000 engineers to the new Project Lightwell service as Anthropic's Mythos findings ignite debate over how to secure the open source software supply chain.

IBM has launched a significant initiative, codenamed Project Lightwell, involving 20,000 engineers from IBM and Red Hat. This effort is reportedly a response to concerns surrounding the security of the open-source software supply chain, amplified by findings from Anthropic's AI model, Mythos.
The Mythos findings, generated by Anthropic's AI, have sparked a debate within the industry regarding the best methods for securing open-source software. The scale of IBM's commitment, dedicating a large portion of its engineering workforce, underscores the perceived urgency and importance of addressing these security challenges.
Project Lightwell is positioned as a new service aimed at tackling the complexities of open-source software security. While specific details about the service's functionalities are not provided, its broad scope suggests a comprehensive approach to identifying and mitigating vulnerabilities within the open-source ecosystem.
The involvement of both IBM and Red Hat, a subsidiary of IBM known for its enterprise Linux and open-source solutions, indicates a strategic effort to leverage their combined expertise and resources. This collaboration is likely intended to create robust security solutions for the vast array of open-source components used across the software industry.
The connection to Anthropic's Mythos findings suggests that AI-driven analysis may play a role in IBM's strategy. The ability of AI to potentially uncover vulnerabilities at scale could be a key factor driving this new initiative and the broader industry discussion.
The open-source software supply chain is a critical component of modern technology infrastructure, with many organizations relying heavily on open-source components. Ensuring the security of this supply chain is paramount to preventing widespread security breaches and maintaining trust in software.
IBM's substantial investment in Project Lightwell signals a strong commitment to enhancing the security posture of open-source software. The success of this project could have significant implications for how open-source software is developed, maintained, and secured in the future.
The debate ignited by Anthropic's findings highlights the evolving landscape of cybersecurity and the increasing role of advanced technologies like AI in identifying and addressing threats. IBM's proactive approach through Project Lightwell aims to provide tangible solutions to these pressing concerns.

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as