Governance & Risk Management
,
Patch Management
IBM Charges Enterprises $1M Annually for Validated Legacy Open-Source Patches

Reporting flaws and deploying patching for open-source software at scale is a multi-billion-dollar market that IBM is eager to monetize, the company’s CEO told investors Wednesday.
See Also: The End of Plausible Deniability: Data Privacy Compliance in 2026
Alongside subsidiary Red Hat, IBM launched a $5 billion initiative dubbed Lightwell that verifies, discloses and remediates open-source vulnerabilities, including those in company-specific software that contain open-source packages.
There is an annual subscription fee of $1 million to access remediated open-source packages, and leading financial institutions are already paying, CEO Arvind Krishna said. “We looked at this historically, and we said that is the place that we want to go play.”
In the weeks since its May 28 launch, Lightwell has provided patches for more than 7,500 package versions with the help of 20,000 engineers and frontier artificial intelligence models, Krishna said.
Palo Alto Networks collaborates with IBM and Red Hat in the effort by offering virtual protections at the network layer to block exploit attempts as Lightwell distributes software remediation for organizations to test and deploy in their environments, Red Hat said in a June press release.
“The demand is real, and it is bigger than any single company or product,” Kara Sprague, CEO of bug bounty platform HackerOne, told ISMG. IBM is a HackerOne client for vulnerability disclosure.
Finding vulnerabilities used to be the hard part until AI made discovery fast and cheap, Sprague said. “We just watched AI models discover and chain novel flaws on their own. Discovery is no longer the constraint,” she said.
“The bottleneck has moved downstream, to remediation. Open source is where this bites hardest,” Sprague said. “That is why organizations will pay for tested patches.”
Five years ago, there was no economic return in systemically patching open source, Krishna said, because it would have taken an army of people with specific expertise and designated environments. Now, there is incentive.
IBM expects to attract hundreds of customers in the first few months, Krishna said, and use that client base as a “flywheel” to identify the patches they need and feed that information back into the network.
“If I look at the amount of running code out there, I would posit to you that open source is now larger than all proprietary code in terms of the volume of software that is there,” Krishna said. “At the same time, the number of people who have been able to commercialize it or monetize it is limited.”
For the past two years, the Defense Advanced Research Projects Agency has been backing cybersecurity companies and research teams through the Artificial Intelligence Cyber Challenge to build AI systems that can automatically find and fix software vulnerabilities. One of the startups to emerge from that effort, Artiphishell, said IBM’s market assessment reflects what it has seen.
“These large commercial vendors that are being supported by open-source software but only in a version that existed five, 10 years ago – if they were to try and update, it would require them millions of dollars themselves to rewrite their own software to comply with whatever the latest and greatest is,” Artiphishell CEO Wil Gibbs told ISMG.
The open-source community underpins much of the commercial market, sometimes with a single developer maintaining software that supports entire industries, Gibbs said.
One challenge is silent vulnerability fixes, which are bugs that developers unknowingly correct without realizing they were security vulnerabilities that could lead to exploitation. Because those fixes are never disclosed or assigned a CVE, organizations running older versions remain exposed with no public warning that a vulnerability ever existed, Gibbs warned.
There are also instances where organizations run older versions of software, and the latest patch modifies code that doesn’t exist in those versions, even though the underlying vulnerability persists. It requires specialized knowledge to apply the fix to the old code while still maintaining functionality, Gibbs said.
“IBM is going in the right direction, but we’re not there,” Gibbs said. “There’s just a lot of work that will need to go into it to make sure that it’s done properly.”
