IBM, Red Hat and Palo Alto Networks expand software security collaboration
Palo Alto Networks (NASDAQ: PANW), IBM (NYSE: IBM) and Red Hat announced a collaboration to help organizations identify and respond to software vulnerabilities across open source software, commercial applications, operational technology and healthcare technologies.
The partnership integrates Palo Alto Networks' virtual patching capability with Project Lightwell, an initiative backed by IBM and Red Hat's $5 billion commitment to open source security. The combination links network-level threat blocking with software remediation tools that customers can test and deploy in their own environments.
When a vulnerability is discovered, Palo Alto Networks can deploy a network-layer virtual patch the same day to block exploit attempts, while Project Lightwell works on a software-level fix. The arrangement is intended to reduce the time between vulnerability discovery and protection, including cases where no official software patch is yet available.
Palo Alto Networks CEO Nikesh Arora said in a statement: "AI has compressed the window between vulnerability discovery and exploit from weeks to minutes. Traditional patching cannot keep pace. By collaborating with IBM and Red Hat, we are shifting the advantage back to defenders."
IBM Chairman and CEO Arvind Krishna said the collaboration extends security "from the source code directly to the network front lines," adding that the joint solution offers "immediate, automated resilience against emerging threats, combined with the rigorous validation required to safely update their core systems."
The three companies also plan to establish processes for sharing vulnerability information across software vendors, technology providers and security teams, with the goal of supporting coordinated disclosure and providing anonymized telemetry on real-world exploitation attempts.
IBM Security Services will offer advisory and deployment support to help customers prioritize and validate protections across complex environments, working alongside the virtual patching and software remediation capabilities provided by the other partners.
The announcement was made according to a press release issued by the companies.
