IBM and Red Hat are betting $5 billion that open source needs a security guard

2026-05-28T14:51:49Z7962906a1aa1ddebd0fe7a1567bafcbe97c4bddc00dfd5fb6a675c06ad60c72d
AI agentsAI governanceCarnivalCopilotDigimarcFIFA scamsIBMNPMOpenAIQevlarQumuloRed HatShinyHuntersWindows 365 for AgentsZapierdata breachelection misinformationopen source securitypackage registryphishingproject lightwellprovenanceransomware protectionsupply chain securitytyposquatting

What happened

This feed is a security news roundup highlighting major developments in open source and AI-era security, plus notable incidents. Key items: IBM and Red Hat launched “Project Lightwell” with a $5B commitment to secure open source across upstream and production; Carnival Corporation disclosed a phishing-related data breach impacting ~6 million customers (ShinyHunters claimed the theft); Token Security disclosed a five-stage Zapier exploit chain that allowed write access to public and internal NPM packages, illustrating supply-chain composition risk. Additional stories cover Microsoft 365 Copilot

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
7962906a1aa1ddebd0fe7a1567bafcbe97c4bddc00dfd5fb6a675c06ad60c72d
Enrichment time
2026-05-28T14:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.