Company Does Not Provide H1B Sponsorship
Red Hat sells subscriptions for open-source software and related services to enterprises. Its products, like Red Hat Enterprise Linux, OpenShift, and Ansible, are open-source but come with guaranteed updates, patches, and professional support through a subscription, so customers install the software and receive ongoing assistance. The company differentiates itself with an enterprise-focused, integrated stack and services around hybrid cloud, containers, and automation, backed by IBM as a strategic owner while Red Hat operates as a distinct unit. Its goal is to help large organizations deploy, manage, and scale open-source software across complex IT environments with predictable, enterprise-grade support.
Work here?Claim your company
Industries
Company Size
10,001+
Company Stage
Acquired
Total Funding
$34B
Headquarters
Raleigh, North Carolina
Founded
1993
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$34B
Above
Industry Average
Funded Over
1 Rounds
Health Insurance
Dental Insurance
Vision Insurance
401(k) Retirement Plan
401(k) Company Match
Paid Vacation
Paid Sick Leave
Paid Holidays
Parental Leave
Family Planning Benefits
Tuition Reimbursement
Zscaler collaborates with IBM and Red Hat to protect private applications from frontier ai-powered threats. New collaboration combines Zscaler Autonomous Application Shield with Lightwell from IBM and Red Hat to help organizations reduce exposure between vulnerability disclosure and patch deployment through inline protection and validated remediation. October 05, 2026 08:00 ET | Source: Zscaler, Inc. SAN JOSE, Calif., Oct. 05, 2026 (GLOBE NEWSWIRE) - Zscaler, Inc. (NASDAQ: ZS), the cybersecurity platform for the AI era, today announced a collaboration with IBM and Red Hat to help organizations protect private applications during the period between vulnerability disclosure and patch deployment. The collaboration combines Zscaler Autonomous Application Shield, delivered through the Zscaler Zero Trust Exchange(TM) security platform, with Lightwell from IBM and Red Hat to deliver adaptive, application-specific protection with validated software remediation in a single coordinated response. "Lightwell helps keep open source safe by patching and fixing these vulnerabilities at machine speed. Collaborating with partners like Zscaler brings..." "As attackers weaponize newly disclosed vulnerabilities faster than enterprises can respond, organizations need a way to protect private applications..." "Our collaboration with IBM and Red Hat brings together inline, application-specific protection and validated remediation to help customers reduce risk during..." "AI is shrinking the window between vulnerability discovery and vulnerability exploitation. A window that was months or weeks is now hours and minutes," The economics of exploitation have shifted. Capabilities that once required elite skills and weeks of manual effort are now widely available, and attackers are weaponizing newly disclosed vulnerabilities faster than enterprise patch cycles can respond. According to Mandiant's M-Trends 2026 report, the mean time to exploit a vulnerability has fallen below zero, meaning vulnerabilities are increasingly exploited before a public patch exists. Patching remains necessary, but on its own it can no longer keep pace. Organizations need protection that can be applied at machine speed while remediation is prepared and deployed. This collaboration extends Zscaler's protection-first operating model for private applications, which assumes a remediation window will always exist and builds resilience around it: hide applications with Zscaler Private Access(TM)(ZPA(TM)) so they are harder to discover and target, segment access with Autonomous User-to-App Segmentation so a foothold does not become broad reachability, and shield reachable applications with Autonomous Application Shield so exploit attempts are stopped inline while the root cause is fixed. By uniting Zscaler Autonomous App Shield with Lightwell, the collaboration provides customers a coordinated path from immediate protection to durable fix. Operating through the Zero Trust Exchange, Zscaler App Connectors continuously perform safe assessments of each private application's exposure points and vulnerabilities. The Zscaler cloud individually evaluates each application, ensuring only necessary protections are applied. When a new vulnerability emerges, adaptive protections can be applied inline and in real time, without waiting for a patch. Through this collaboration, Lightwell helps Zscaler defend its customers from potential cyber threats, with Zscaler blocking exploit attempts immediately at the network level. Lightwell then provides validated remediations for affected open source software, enabling customers to fix the underlying flaw at the source. "As attackers weaponize newly disclosed vulnerabilities faster than enterprises can respond, organizations need a way to protect private applications immediately while fixes are being prepared and deployed," said Joby Menon, Senior Vice President of Product Management at Zscaler. "Our collaboration with IBM and Red Hat brings together inline, application-specific protection and validated remediation to help customers reduce risk during that gap." Through this collaboration, Zscaler, IBM, and Red Hat will deliver integrated capabilities across the application security lifecycle, addressing critical needs including: * Exposure Discovery: Providing a current understanding of a private application's actual risk profile, updated as fast as applications change, rather than relying on periodic scans. * Preemptive, Application-Specific Protection: Bridging the gap between vulnerability and patching. Applying only the protections a given application needs during the gap between disclosure and patching, reducing exposure while remediation is underway and avoiding one-size-fits-all policy noise. * Machine-Speed Response: Deploying protections inline and in real time when a new vulnerability emerges, informed by global threat intelligence from across Zscaler's worldwide customer base. * Validated Source-Level Remediation: Delivering tested software fixes through Lightwell so organizations can resolve the underlying vulnerability, with advisory and deployment support to prioritize and validate protections across complex environments. "AI is shrinking the window between vulnerability discovery and vulnerability exploitation. A window that was months or weeks is now hours and minutes," said Gunnar Hellekson, vice president and general manager, Lightwell, Red Hat. "Lightwell helps keep open source safe by patching and fixing these vulnerabilities at machine speed. Collaborating with partners like Zscaler brings Lightwell's capabilities to the forefront of enterprise networks, mitigating potential vulnerabilities head-on while patches are applied to critical systems." Autonomous Application Shield is currently available through an Early Access Program. Availability, capabilities, and timing of the collaboration described herein are subject to change. For a deeper dive into how Zscaler is helping protect against AI threats, please visit this blog. Forward-Looking Statements This press release contains forward-looking statements that are based on our management's beliefs and assumptions and on information currently available to our management. These forward-looking statements include the expected performance and benefits of Zscaler Autonomous Application Shield and its collaboration with IBM and Red Hat, including the delivery of adaptive, machine-speed protection for private applications. These forward-looking statements are subject to the safe harbor provisions created by the Private Securities Litigation Reform Act of 1995. A significant number of factors could cause actual results to differ materially from statements made in this press release, including those factors related to Zscaler's ability to achieve partner and customer adoption of Autonomous Application Shield and the collaboration described herein. Additional risks and uncertainties are set forth in our most recent Annual Report on Form 10-K filed with the Securities and Exchange Commission ("SEC") on September 3, 2026, which is available on our website at ir.zscaler.com and on the SEC's website at www.sec.gov. Any forward-looking statements in this release are based on the limited information currently available to Zscaler as of the date hereof, which is subject to change, and Zscaler will not necessarily update the information, even if new information becomes available in the future. About Zscaler Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange(TM) platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 200+ public data centers globally and thousands of private sites at the edge, the SASE-based Zero Trust Exchange is the world's largest in-line cloud security platform. Media Contacts Nick Gonzalez, Director of Public Relations, [email protected]
Critical Red Hat Satellite flaw could enable root password theft and code execution attacks. Red Hat has fixed a high-impact vulnerability in Red Hat Satellite that could allow a low-privileged authenticated user to access sensitive host information, including root passwords. Under unsafe configurations, the flaw could also escalate to arbitrary command execution as the Foreman service account. Tracked as CVE-2026-96659, the issue affects the Foreman component used by Red Hat Satellite for infrastructure provisioning, configuration management, and lifecycle operations. Red Hat assigned the vulnerability an Important severity rating and a CVSS v3 score of 9.1. The vulnerability was publicly disclosed on October 1, 2026. The attacker needs network access and a valid low-privileged account, but does not require user interaction. Successful exploitation can have a high confidentiality impact. The flaw stems from an authorization weakness in Foreman template preview endpoints. A user assigned only the Viewer role can submit crafted requests to these endpoints and retrieve information that should be available only to higher-privileged administrators. Red Hat Satellite vulnerability. According to Red Hat, the affected endpoints can expose sensitive host attributes. This may include host root passwords, creating a serious risk for organizations that use Satellite to provision or manage large fleets of Red Hat Enterprise Linux systems. The issue is classified under CWE-267, an access-control weakness that can allow users to access restricted features, sensitive data, administrative functions, or identities beyond their assigned permissions. A compromised Viewer account could therefore become an entry point for broader environment exposure. Stolen root credentials could be used to access managed servers, move laterally across a network, alter workloads, or establish persistence. The primary impact of CVE-2026-96659 is unauthorized information disclosure. However, Red Hat warned that the security impact becomes more severe when Foreman template Safemode protections have been turned off or can be circumvented. In such insecure configurations, an attacker may be able to execute arbitrary commands as the Foreman service account. This could give an attacker a foothold on the Satellite server itself, which is particularly concerning because Satellite often holds credentials, host inventory data, provisioning templates, configuration details, and content-management access for enterprise Linux infrastructure. Red Hat's Satellite 6.16 advisory also lists CVE-2026-96658, a separate Foreman Safemode bypass flaw that can lead to remote code execution. Organizations should treat these related Foreman security issues as a priority patching event rather than addressing CVE-2026-96659 in isolation. Red Hat has released fixes for the following products: For Satellite 6.16, Red Hat released Foreman version 3.12.0.23-1 for RHEL 8 and RHEL 9 as part of the Satellite 6.16.14 update. The advisory also contains fixes for several other security flaws affecting Foreman and related Satellite components. Administrators should apply the relevant Red Hat security errata immediately, review all Viewer-role accounts, and remove unnecessary access. They should also verify that Foreman Safemode protection remains enabled and investigate template preview activity for unusual requests or access to sensitive host attributes. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post critical Red Hat Satellite flaw could enable root password theft and code execution attacks appeared first on cyber security News. Related cyber security News posts. A serious security vulnerability has been discovered in Red Hat's NetworkManager-libreswan plugin that could allow local attackers to escalate privileges and gain root access to Linux systems. The flaw tracked as CVE-2024-9050 has received a CVSS base score of 7.8, indicating its high severity. The security issue stems from the... In "Cybersecurity News - Original News Source is cybersecuritynews.com" Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that could allow unauthenticated remote attackers to take over arbitrary user accounts. Tracked as CVE-2026-18963, the flaw affects the password recovery process and carries a CVSS v3.1 score of 9.1. The vulnerability exists in the reset-credentials... In "Cybersecurity News - Original News Source is cybersecuritynews.com" A critical use-after-free vulnerability has been discovered in the Linux kernel's netfilter subsystem. This vulnerability could potentially allow local, unprivileged users with CAP_NET_ADMIN capability to escalate their privileges. The flaw, identified in the upstream commit 5f68718b34a5 ("netfilter: nf_tables: GC transaction API to avoid race with control plane"), can cause a... In "Cybersecurity News - Original News Source is cybersecuritynews.com"
Lightbits SDS certified with Red Hat OpenStack Services on OpenShift. Certification enables simplified migration of Red Hat OpenStack Platform workloads to Red Hat OpenStack Services on OpenShift while accelerating performance and simplifying operations. Lightbits Labs, inventor of the NVMe over TCP storage protocol and Inferra, intelligent KV cache orchestration engine, announced that its software-defined block storage platform, Lightbits SDS, is certified for and can be fully integrated with Red Hat OpenStack Services on OpenShift.The certification provides organizations with a validated path to modernize existing Red Hat OpenStack Platform environments to Red Hat OpenStack Services on OpenShift and deliver a highly scalable, ultra-fast, disaggregated NVMe/TCP storage layer for building modern hybrid clouds from scratch. "At Red Hat, our vision for Red Hat OpenStack Services on OpenShift is to bring customers into the Kubernetes era using the standard APIs and lean operational models they rely on. The back-end storage platform should hold the same values," said Sean Cohen, senior director, product management, Red Hat. "Lightbits SDS certified on Red Hat OpenStack Services on OpenShift provides a compelling migration path where the storage layer brings disaggregation, standard Ethernet simplicity and scales with the platform." Running Lightbits block storage in a Red Hat OpenStack Services on OpenShift environment enables IT teams to consolidate cloud infrastructure and containerized workloads onto a single orchestration layer while maintaining the performance required for demanding virtual machine (VM) workloads. "As an integration hub connecting financial institutions to the markets in Brazil, millisecond-level latency and absolute stability are critical requirements for our data infrastructure systems. Lightbits' integration with Red Hat OpenStack Services on OpenShift delivers the performance profile and stability that works for our data center while dramatically simplifying our operations," said André Nazário de Souza, director, RTM's Cloud Infrastructure. The Red Hat OpenStack Services on OpenShift integration operates at two levels: * Cinder backend integration: Lightbits serves as the Cinder block storage backend on the Red Hat OpenShift control plane, enabling on-demand volume provisioning for Red Hat OpenStack Services on OpenShift * Direct NVMe/TCP integration: Lightbits also serves as a direct NVMe/TCP target for External Data Plane Management (EDPM) compute nodes, providing ultra-low-latency access to virtual machines at scale Lightbits SDS disaggregated storage capacity and performance can scale independently over standard 100 GbE Ethernet, eliminating infrastructure complexity and the need for proprietary networking while delivering ultra-low-latency access to VMs at scale. "This certification empowers organizations to run Red Hat OpenStack Platform control plane services as Kubernetes pods directly on OpenShift," added Sagy Volkov, field CTO, Lightbits Labs. "Lightbits brings disaggregation, NVMe performance, and operational simplicity on standard Ethernet infrastructure - without proprietary hardware, and without compromising the performance that today's workloads demand." Key benefits of Lightbits SDS on Red Hat OpenStack Services on OpenShift: * Unmatched Performance without Proprietary Hardware: NVMe/TCP delivers ultra-low latency and high throughput without requiring proprietary networking technologies * Unified, Simplified Operations: Kubernetes-native lifecycle management enables administrators to manage Red Hat OpenStack Services on OpenShift and storage through a unified operational model * Independent, Disaggregated Scaling: Capacity and performance can be expanded independently, helping organizations avoid stranded resources and improve infrastructure efficiency "Integrating a high-performance, software-defined storage layer with our Red Hat OpenStack Services on OpenShift cloud was paramount to our implementation; we needed to avoid the performance bottlenecks of legacy systems and the high costs of proprietary hardware," said Abhimanyu Bhatter, co-founder and head, solution and technology, Coredge.io. "Lightbits solved all of our challenges around availability, scaling, and operational simplicity. In our Red Hat OpenStack Services on OpenShift environments, Lightbits delivers more performance than Ceph at 3-4x lower cost, while being easier to manage during upgrades and migrations. It has given us the resilient, cost-effective block storage fabric we need to run our business efficiently." Organizations planning an OpenStack-to-Red Hat OpenStack Services on OpenShift migration can download the "Lightbits Storage Integration with RHOSO - Technical Reference Guide" from the Lightbits Resource Center, and download the Lightbits Cinder driver for Red Hat OpenStack Services on OpenShift. Read also: Superior Tokenomics. Predictable SLAs - Unbounded LLM at Scale Native Ubuntu Support Simplifies Deployment of High-Performance Software-Defined Block Storage for Private Clouds Built in Kubernetes and OpenStack Environments Inventor of NVMe/TCP & KV Cache accelerator validates initial connectivity to bring high-performance block storage to Windows Server environments
Why Red Hat is building an open foundation for enterprise agents with OpenClaw Enterprise. Vice President and General Manager, AI Business Unit at Red Hat Applications are moving beyond predefined workflows toward agentic systems that can reason, use tools, interact with enterprise data, execute code, delegate work and collaborate with other agents to accomplish goals. This has driven the development of new capabilities in areas like agent sandboxing to secure agent execution, AI gateways to secure access to models and tools, AgentOps for tracing, observability, evaluation and more. Red Hat, Inc. believe another important layer of the enterprise AI stack is emerging: an open control plane for agents. This is why Red Hat, Inc. is excited about contributing to OpenClaw and the newly announced OpenClaw Enterprise, an enterprise-grade control plane for deploying and operating persistent agents across users and teams. From rapid innovation to enterprise-readiness OpenClaw has evolved rapidly over the past year, maturing from an agile open-source project into a production-grade foundation for AI agents. That evolution continues with the newly announced OpenClaw Enterprise project, built specifically to securely deploy these agents in enterprise environments. Red Hat, NVIDIA and others are collaborating on OpenClaw Enterprise development in the open. Both OpenClaw and OpenClaw Enterprise are fully open source, driving both innovation as well as transparency and trust for enterprise AI deployments. A proven history with Linux and Kubernetes Its approach with OpenClaw follows a familiar playbook at Red Hat. Throughout Red Hat's history, some of the biggest changes in enterprise computing have been driven by fundamental shifts in how applications are built and operated. Linux helped enterprises move applications from proprietary Unix systems and specialized hardware onto an open operating system running on industry-standard infrastructure. Later, containers and Kubernetes helped drive another transformation toward cloud-native applications composed of distributed microservices. Red Hat Enterprise Linux and Red Hat OpenShift helped make those transitions possible for many enterprise customers, powered by Red Hat's extensive work in upstream projects to drive underlying technologies that are open, trusted, and secure. Today, AI agents are driving the next evolution of enterprise applications. This is fueling new innovations across the open source ecosystem and projects like OpenShell, vLLM, Pytorch and more that Red Hat is contributing to. Its work in the OpenClaw community and on OpenClaw Enterprise will help bring new agent runtime capabilities and an open agent control plane to the enterprise. "Enterprises want the flexibility and innovation of open source with the governance, security, and reliability they expect from enterprise software," said Kevin Lin, who leads OpenClaw Enterprise efforts at OpenAI. "OpenClaw Enterprise brings those pieces together, and working with Red Hat and the broader community will help make it a trusted, open foundation for how agents are managed and deployed in the enterprise." Building upstream together Red Hat recently announced its sponsorship of the OpenClaw Foundation and Red Hat, Inc. is putting engineers behind it. Red Hat engineers are already contributing to OpenClaw, and Red Hat, Inc. is expanding that investment with expertise in Linux, Kubernetes, distributed systems, security and enterprise infrastructure. Building on its internal use of OpenClaw today, Red Hat, Inc. look forward to deploying OpenClaw Enterprise to orchestrate internal agent deployments and help directly inform its upstream contributions. Red Hat, Inc. intend to work with OpenAI, NVIDIA and the broader OpenClaw community on the capabilities required to operate agents at enterprise scale to drive the evolution of this technology and help establish open standards. Joe Fernandes is Vice President and General Manager of the Artificial Intelligence (AI) Business Unit at Red Hat, where he leads product management, product marketing, and technical marketing for Red Hat's AI platforms, including Red Hat Enterprise Linux AI (RHEL AI) and Red Hat OpenShift AI. Original podcast
Fwupd 2.1.8 released with new hardware support from ASUS, Lenovo & others. Lead LVFS/Fwupd developer Richard Hughes of Red Hat announced Fwupd 2.1.8 today as the newest feature release for this open-source firmware updating solution for Linux systems. With Fwupd 2.1.8 comes support for a number of newer devices plus plenty of bug fixes. Fwupd 2.1.8 introduces a new plug-in for notifying bootupd when the EFI System Partition (ESP) changes, RSA-3072 signature verification support for Lenovo hardware, and a number of different bug fixes from memory leaks and buffer overflows to supporting larger Redfish firmware blobs. New hardware support in Fwupd 2.1.8 includes: - ASUS GX5407 - Elan PID 0CB6 - FocalTech MOC fingerprint sensors - Lenovo ThinkPad Thunderbolt 4 Dock Gen 2 7000 - MaxLinear MxL862xx - MediaTek MT9700 FCTE and MT9701 KSMU - Pixart PID 4F01, 4F02, 4F0D and 4F0E - Rolling RW101 The ASUS ProArt P16 GX5407 support is for a quirk with the ILITEK touch controller's firmware. Great seeing the continued firmware updating support for Lenovo, MaxLinear, MediaTek, and PixArt devices. Downloads and the full list of Fwupd 2.1.8 changes can be found via GitHub.
Find jobs on Simplify and start your career today
Industries
Company Size
10,001+
Company Stage
Acquired
Total Funding
$34B
Headquarters
Raleigh, North Carolina
Founded
1993
Find jobs on Simplify and start your career today