2 links tagged with all of: ai-security + vulnerability-management
Click any tag below to further narrow down your results
Links
IBM, Red Hat and Palo Alto Networks are integrating Palo Alto’s network-based virtual patching in Prisma with IBM/Red Hat’s Project Lightwell to spot and shield against open-source software flaws. The joint effort uses shared vulnerability intelligence and AI-driven processes to deliver preemptive, same-day network protections while patches are developed.
- IBM/Red Hat's Project Lightwell now feeds vulnerability intelligence into Palo Alto's Prisma so virtual patches can deploy the same day a flaw is confirmed, shrinking the discovery-to-defense window from weeks to minutes.
- The integration sits under IBM and Red Hat's $5 billion Project Lighthouse, with Lightwell acting as an AI-driven clearinghouse that validates and tests fixes across massive volumes of open-source code before delivering them via subscription.
- Early adopters include major banks and financial firms (Bank of America, Citi, Goldman Sachs, JPMorgan Chase, Mastercard, Visa), gaining preemptive protection across open-source libraries, commercial apps, OT and IoT environments.
- This builds on existing IBM-Palo Alto collaboration on quantum-safe readiness and AI risk assessment, adding network-level virtual patching as a stopgap while permanent fixes are developed.
Four high-severity flaws in the open-source Dify platform allow authenticated users to read private chats, preview documents, and leak files across tenants by abusing tracing endpoints, plugin daemon APIs, and flawed file permissions. One issue also stems from a vulnerable PDFium version (CVE-2024-5846). Dify 1.14.2 patches these bugs; operators should update immediately and apply WAF rules for CVE-2026-41948.
- Four "DifyTap" flaws in Dify (used by 1M+ AI apps) let authenticated users cross tenant boundaries to read private chats, steal files, and hijack plugin data.
- Worst bug (CVE-2026-41947, CVSS 9.1) abuses the tracing API's missing tenant checks to create a persistent exfiltration channel from any public app.
- Plugin daemon flaw (CVE-2026-41948, CVSS 9.4) allows arbitrary GET/POST calls enabling path traversal and cross-tenant plugin manipulation.
- All issues, plus an outdated PDFium library vulnerable to CVE-2024-5846, are fixed in Dify 1.14.2—upgrade immediately and apply WAF rules for CVE-2026-41948.