Searchable transcript of GLM-5.2: The real security risk? Plus: Vibe hunting, the end of CVSS and updates on Lightwell — IBM Technology (35:06). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:00 Open-weight models are reportedly reaching Mythos-level capabilities in at least some domains. Panelists, how is that making you feel? EvilMog, we'll start with you. I mean, these models are getting scarier and scarier all the time, which makes my life easier because the real legitimate models are adding more and more classifiers, preventing use even within the cyber verification programs.
00:20 Same sentiments of a little scared, a little excited. I think, it's pretty exciting to see what people are able to come up with, and it's a little bit frightening to know that people are going to be able to have these capabilities without having to run them anywhere. People who are benefiting the most are probably the hardware providers. Hello, and welcome to Security Intelligence, IBM's weekly cybersecurity podcast, where our expert panelists turn the biggest industry news stories into practical takeaways that you can
00:45 use. I'm your host, Matt Kosinski. And joining me this week, as you've seen, we've got Claire Nunez, Creative Director, IBM X-Force Cyber Range. We've got Dustin "EvilMog" Heywood, he's X-Force Executive Managing Hacker and Senior Technical Staff member. And Ian Molloy, Department Head, Security Research. Plus later in the show, Brent Holden of Red Hat is going to join us again to chat about the latest developments with Lightwell.
01:10 That's IBM and Red Hat's new offering tackling vulnerabilities in the open-source infrastructure that powers much of our current IT reality. But before that, we're also going to be talking about CISA's new model for patch prioritization and vibe hunting, vibe coding's cybersecurity cousin. But first, we are talking about GLM 5.2. Now Mog is the first one to flag this story to me a few weeks ago, based on a Substack article by Joshua Saxe, who works on machine learning and cybersecurity at Meta.
01:43 The article, for those interested— and it's worth a read—is called "GLM 5.2, not Mythos is the real security emergency." Listeners might recall that we referenced GLM 5.2 last week as well. This is the open-weight model from Chinese firm Z.ai that is said to have those Mythos- level capabilities. Saxe notes that at the same time that we're locking down our frontier models, restricting access and applying guardrails, attackers are getting their hands on these unlocked open models, and that can create a kind of dangerous
02:09 imbalance in the landscape. Here's a good quote I like from his article: "The problem isn't to put the AI genie back in the bottle, it's to make the genie ubiquitous across defender networks, hardening our positions before the cyberattack world has its own Claude Code automation moment." Now, as I mentioned, EvilMog, you were the first one to bring this to my attention, so I want to open up with you.
02:29 What was it about this story that caught your attention, and why did you flag it for the show? What are you thinking about? This was inevitable. Now, the thing to understand, though, is this GLM- 5.2 model requires eight H100s. That's a lot of compute, but with quantization you can get it down tinier. You can fit them in these small 128 gig of RAM systems like the DGX Spark.
02:50 So the capability is getting out of there now. GLM-5.2 on its own isn't exactly that terrifying from a cyber perspective, but it's the obliterated models and the extraction models with the modified weights that make this deadly. Because if you disable its refusal techniques, then it's going to be more evil. That makes a lot of sense to me. Ian, how about you?
03:09 I'd like to hear you kind of elaborate, especially, I remember you had mentioned up top thinking about how the hardware providers might also stand to benefit a little bit here. Walk us through some of your thoughts for us, please. Well, I guess a couple of things. I mean, one, I don't know if you've ever had to have like a Mythos model to find vulnerabilities.
03:25 My team has been quite successful using much smaller models a little bit, you know, creative how you prompt them to be able to kind of come up with and finding and explaining the vulnerabilities. I think Mythos was, you know, kind of a game changer there, but it's not an absolute requirement. There are lots of people who've actually been able to replicate some of these different results.
03:42 What I will say is that if everyone's going to be trying to run, you know, with these very, very large models, you know, you can quantize it, but, yeah, you know, eight H100s, H200s. I don't have that in my basement. I can't acquire it. I'm not sure what the lead time for that is. But again, you know, they're the ones that are definitely kind of benefiting here if you can just, like, burn more tokens, like that is benefiting the model providers, the hardware providers, things along those lines.
04:06 But the scary thing is, when you can do that level of compute, of creating those abilities from much, much, much smaller models. And so as we are able to, like, distill it down or actually better prompt the models or, you know, remove, you know, some of the guardrails, or you kind of isolate that offensive capability, that's where things will actually become quite scary.
04:26 Well, yeah. Things like qwen, qwythos, there's a few of the other scary ones coming out. Seems I'm seeing every day there's something new that's downright terrifying that fits on a tiny little like MS-A2. Yeah. And I think that that's a really good point that you both bring up there about, like the shrinking of the models, because I think there's a tendency, and I fall into this too, which is that you treat each one of these things like it is the event instead of part of a chain of events.
04:48 Right? And so it's like, yeah, maybe GLM 5.2 is scary, maybe it's not. But like as they get smaller, that opens up these new possibilities, and I think it's worth looking at that as much as we're looking at the current state of things. Claire, let me bring you in here. What are your thoughts? How are you feeling about GLM 5.2? These open-weight models showing up real powerful.
05:04 What's your take? Yeah, I don't remember if it was in this article or a separate one that I read about GLM 5.2, but it was something like, "We have Mythos at home," which I thought was really interesting because like, there's all this like Mythos is kind of like a locked box, essentially, but it's like if if attackers are going, if it exists, you know, somebody can replicate it in some way.
05:26 It's kind of like almost an AI space race to an extent where it's like, you know, it's possible. You just need to figure out your way of doing it, and you're going to figure it out on your, like, compute power and all of that as well. So it's just kind of like someone's going to figure it out. Whether we let defenders have it, whether we let attackers have it.
05:44 So it's it's just kind of like, okay, what, how do we want to handle it in the most optimal way to give defenders the best chance at, you know, preventing anything bad from coming from this? I got a problem with a couple statements in there. "Whether we let defenders get," "whether attackers get"— they've already got it. I mean, it's already out there and there is no putting this genie back in that bottle.
06:08 So it's either you annoy people like me with controls or I'll start using all the other systems. Like here's an example. I had the Opus-4.8 working perfectly under cyber use cases for ages up until 24 hours ago, and all of a sudden, even the mere mention of a fuzzer turned me into blocks. People are gonna start working around this, either legit researchers or, you know, defenders, and soon the only option could be an open-weight model.
06:33 So I think our chance to control things was gone the moment we declared these export control weapons and the US started, you know, stopping the export of real, you know, frontier models. That is the kind of question that we face now. Right? And you know, Claire, this phrase that you used, "AI space race," I think it kind of sums it up, right? Because it's like, look, we can put guardrails on certain things, but as Mog pointed out, it's not really up to us who gets them.
06:58 It reminds me of something that Jeff said last episode, which is that like safeguards are great, but those are for the good guys. They're not for the bad guys. The bad guys are bad guys because they don't follow the safeguards in the first place, right? And so you have this real danger of ending up in a place where, like, we have to make these model—or "have" to make these models— safe.
07:14 But are those safeguards interrupting the work of cybersecurity defenders? It's tough to figure out how we do that. So shifting gears a little bit, and I'm not saying we're going to figure it out on this episode right here live. But like it does leave me wondering, so what's the so what for us, right? Like we can't control open models the same way we control other models.
07:34 You know, we can't put safeguards on that kind of thing. They're open. So like, what does it mean for us? What do we do? And Ian, I want to bring you in here. Do you think anything changes for defenders right now immediately, or is it still just kind of a game of watching how things play out? What, what are you seeing? Well, it's kind of hard to say, because, I mean, the defenders can also use the same models that the attackers can use.
07:52 Like they can go, they can download GLM-5.2, we can download it, we can run it. They do have access to things like Mythos, through Glasswing, to Mythos Preview, through Daybreak, the latest GPT models. So they are trying to give, you know, defenders access to some of these models and these additional capabilities. They are trying to restrict. Whether or not we're at this point now, it is kind of worth asking the question at some point: Is there a hypothetical model where that becomes too dangerous that we actually
08:21 wouldn't want to release it? Like, is that something that actually does exist, or is it always going to be, well, no, we'll always be able to release more and more powerful models, and that's just something we're gonna have to get used to? Yeah, I don't think anybody can answer that question. And but I do think you're right like that. Are we headed towards that point?
08:37 I don't know, but we kind of have to look out and kind of prepare ourselves for the possibility. I think in some ways. Claire, how about you? Any thoughts on, like, concrete sort of next steps? The so what? What does it matter for defenders right now? I'm not really sure like what the next exact step would be. I know that I'm hearing from a lot of clients that they are very freaked out about this.
08:57 They're very, you know, scared about everything that's going on. I think it's like the general reminder is to kind of use AI to combat AI, like over high, super high level, but like kind of using. You can't just use the old-school tactics forever. So yeah. And that ties in nicely with what Ian was saying. Right. Which is that like as, as scary as this can be for clients, some, a lot of folks legitimately have access to Mythos already, right?
09:25 Like if you're on the defender's side, you already have these kinds of capabilities. So it might be sort of a little nerve-racking to see them fall into more people's hands without safeguards. But like, if you're if you're one of the defenders, you have access to similar things already. So it's, there's there's more parity than we might think based on some of the coverage.
09:42 Mog, close us out on this segment. What are your thoughts in terms of the so what, the takeaway here for everybody? I mean, I hate saying I was right. I mean three months out and we've already got the equivalent. I think an AI model will come out one day that we can't ever release, but I think we'll never be in a position to stop it. I mean, it's going to come out regardless, as we've proven.
10:00 So we're on this ride whether we like it or not. I love that as a way to close out the segment, folks, for the viewers and the listeners watching on YouTube, leave your thoughts in the comments. If you've got thoughts on GLM 5.2 on whether or not there might be a model someday that's too powerful to release, let us know what you're thinking. I do read, I do respond, but I've got to move us along to the second story for today.
10:20 Folks. This is CISA swaps CVSS scores for a new approach. So last month, the US Cybersecurity and Infrastructure Security Agency, or CISA, issued BOD 26-04. Now, this is notable because this new directive introduces a four variable model for prioritizing vulnerabilities and a more dynamic approach to remediation timelines. The four variables you're supposed to pay attention to now are: First, public exposure.
10:49 Is the vulnerability reachable from outside the agency network? Second, is the vulnerability being exploited in the real world? Third, can the exploitation be automated? And fourth, does exploitation give total control of the affected system? And then based on your answers to those, you know, the remediation timelines change. The most critical vulnerabilities, you have like three days.
11:10 The least critical, you can wait until there's a system upgrade even. I'm wondering what we think about this new framework right off the bat. How do we think it will help us address patching problems? Will it help us address patching problems and other security concerns? Claire, let me start with you. Any thoughts on on this kind of new model, this new approach to categorizing, addressing vulns?
11:31 The clients I usually work with, they're not really thinking about where vulns are kind of categorized or anything. I'm usually working with like an executive audience. Right. So at the end of the day, if this is going to help organizations like kind of patch things faster and prevents, you know, crises at a large scale, then I think, you know, that higher level audience will be a little happier with this.
11:54 At the same time, I do know that this is something that is like required for federal agencies to start and that it's something that other organizations will kind of consider taking on later. I think it's something that's going to take a long time for people to more broadly adopt. But I mean, if it's something that helps organizations patch more quickly, then I would say it's a good thing.
12:17 Yeah, you kind of read my mind there because I was wondering about adoption timelines myself and if we'll see it adopted. Right. Because as you point out, and I should clarify, because I didn't in the intro. But like this is a directive for federal agencies. Right. It's not like a civilian organization necessarily, or a private organization necessarily has to follow these.
12:32 It's more like here's a model. This is what the federal agencies are using. You could use it if you want. We do see a lot of times the private organizations will adopt federal models kind of, you know, by their own choice because they like them. But there is that wonder, right? Like, will we see similar adoption here? And if we do, whether the timeline will be long.
12:49 But I also like that you point out, Claire, that maybe this could help, I don't know, communicate a little bit better with some of those executives who maybe they're not worried about a CVSS score or a CVE or anything like that. They just want to know answers to these four simple questions, right? So I could see some possible benefits there. Mog, how about you?
13:04 Any thoughts on your end on this model, especially compared to previous ways of classifying vulns? You know, I'm going to remain a little bit open-minded about the changes. Don't get me wrong. I just am a little skeptical because people didn't go back in and update things like the impact, the environment. It was never really used for what it was intended.
13:23 And then the enrichment in the NVD, the National Vulnerability Database, hasn't been happening for such a long time that, you know, the entire process has been broken. CVEs in general, people will clout chase crashes for CVE numbers to be assigned to them. The whole ecosystem itself is kind of a mess, so we'll see how it works out. Usually gov takes over.
13:43 Everyone mandates gov, which means all the software updates and we go kick this down the cat, or kick this cat down the road. But I'm still a little iffy because, I don't know, CISA hasn't really rolled out some best hits lately. And we'll see how all this rolls out. No, I think it's a fair point. It's kind of a wait and see thing. Right? And as you point out, I mean, CVSS has been kind of a mess for a long time.
14:04 And so some people are kind of celebrating this as the death of CVSS scores. And we'll see if that's where we're at. Ian, how about you? Any thoughts on your end? On this new model? Well, I was a little bit surprised when I was reading that how many vulnerabilities like never get patched or how long it is to like a vulnerability finally gets patched.
14:22 And I think the interesting thing is going to be like, how quickly is it going to be until something's weaponized? Or how quickly until you start to be able to exploit some of these vulnerabilities when you start having models that are actually able to, like, chain multiple vulnerabilities? So you're going to have like a whole bunch of lows and mediums and all of a sudden that is going to in aggregate give you these additional capabilities.
14:40 It's not clear to me if the current model is actually going to address that, or at least address that sufficiently, or if you need like a critical vulnerability before that actually pops to the top. And instead, you know, that you're not actually going to be able to, like, patch anything because you're going to wait until the next patch window. So maybe it's going to be one of these, we'll see how it actually ends up playing out before we know if it's actually going to be anything beneficial.
15:02 But it's a little bit surprising they're boiling the whole thing down to like four bits. Things like for example, the way CVSS pops out is they don't update it with updated data when, say, let's look at WannaCry or the the Eternal Blue. They start off as like a seven-point something, and these are made up numbers for the people listening. So don't quote me on this.
15:21 But they'll start out low and they'll move themselves high. A lot of the vulns don't do that. So when organizations rely on this updated enriched data, here's the thing. They never update it. They never enrich it. So it's useless for large scale programs. So I don't see how this is going to fix those problems when people aren't going to do the updates anyways.
15:40 So yeah, we lose some data, but most of the data wasn't being used, so it's really a wash. I think I think all that now boils down to one bit though. It's like that, that last bit like, does it give you total or partial control? Like everything you're talking about now is a binary variable. Like, that's what I'm saying. It's a little bit coarse-grained to see how it's actually going to work out.
15:57 And if everything is now going to be exploitable, if it's all just going to, you know, homogenize to like, you know, whether or not it's the, what, three day with or without triage type of thing. Yeah. Same problem we already have right now. Yeah. We haven't addressed the resource allocation problem. People can't actually patch things sufficiently quickly.
16:13 I think that's kind of where I wanted to head next, given how this conversation has evolved here. Right. It's like, well, look, we've talked about maybe some of the potential benefits of a model like this and how maybe it can help make some decisions, maybe help communicate certain things to certain stakeholders. And and I want to give it credit for that.
16:28 But there is, I, you know, first of all, it sounds like there might be something that's maybe lost when we, as you said Ian, kind of boil it all down to 4 bits. Right. Is there certain information that's not getting captured by that? And I think that's worth thinking about. And then. Yeah. Does this leave, does this address the kind of big pain point of like, okay, great.
16:46 Now we know how fast we have to patch this thing. Do we actually have the resources to patch it? And I don't know, I mean, maybe that's a place where AI comes in and helps, but maybe I'm just kind of being optimistic and hand-waving things. Let me ask you this. Would you trust AI to patch your system autonomously with a large, all the interlocking components with an SBOM and everything else autonomously?
17:08 I don't think I would, I don't think I would. And that's why I kind of I see it as hand-waving, right. It's like it's like oh the AI will help. Okay. Sure. But like, how is it going to help? I, I can't tell you that right now, you know. And I don't know that anybody can so it's almost like, I don't know, it's I am interested in this model, but I see a lot of the concerns that you folks raise.
17:28 And I really do think this kind of patch management, uh, resources, like actually focusing on that angle. That's what we actually have to think about, and like, how are we going to manage that? How are we going to manage a three-day turnaround. Right. That's that's pretty quick. And as folks have already pointed out on the panel, a lot of stuff never gets patched.
17:43 And now we're saying certain things have to get patched in three days. I don't know. It's not just patching in three days, I think it's patching, and then if you hit that other criteria, it's all of the forensics also has to happen in three days. I think that's a really good point, right? Speedy, I don't know. That I look, I, I do think, you know, if for the agencies adopting this obviously there's going to have to be a lot of thought about how they do this.
18:06 And for organizations adopting this, there's also going to have to be a lot of thought about how realistic, can it be realistic? Maybe it's going to be the kind of thing where, when this model hits hits the reality, some of this might change, right? Like this might be the kind of thing that sounds good, very good in a, you know, in a boardroom and maybe less good in practice.
18:22 We'll see. But to close out the segment, Claire, I just wanted to give you, any any last thoughts here for, for folks on on the model, on how it might affect things, on what you're thinking about? Any last takes for us? I'm just thinking it's, even for an agency. I mean, three days is very tight for all of those efforts, and to kind of base it all on just four variables, it's, I don't know.
18:41 Is it good for an audience that doesn't necessarily know the ins and outs of all these technicalities? Sure. But do they really need that? I don't know, so it just feels like it's going to be a struggle for, you know, a lot of agencies and commercial organizations, too. I think this is, this is developing into the theme of this episode is kind of like, we'll see, you know.
19:05 We'll see where GLM 5.2 goes. We'll see where this model goes. And I think the next story honestly, too, is also kind of going to be a we'll see story. Right. Because I, I want to talk to you folks next about vibe hunting. Vibe hunting is basically the threat hunting equivalent of vibe coding. Right? So like instead of doing the hunting yourself, you kind of make a plan and pass it off to an AI that carries it out for you.
19:36 And it seems to me to be having a moment. Maybe this is just my feeds and the people I follow on LinkedIn, but I feel like I've seen a lot of vibe hunting talk recently. And as much as it seems kind of like an implementation of, like, you know, this idea we talked about in the beginning of the show, embracing AI for defenders, kind of getting into that AI space race.
19:54 I also wonder if we've worked out the kinks. I mean, in the very previous segment, Mog himself was just saying, would you trust an AI to go patch everything? So the question is like, would you trust an AI to go threat hunting everything for you? Are we there yet? I'll start, but look, I'm just the host. I'm not the expert. So I'll start asking the experts for your thoughts on on on vibe hunting.
20:13 How do you feel about it? Optimistic? Does it look cool to you? What's your take? I mean, first, I think before we start, I'm kind of curious. Are we going to start prefixing everything with "vibe" going forward? Kind of reminds me like, yeah, probably. Yeah. Okay. Just just just, just we had to put that on record now. So we're going to be vibe-podcasting this.
20:32 This is yeah this is a vibe podcast from now on. Go ahead. So, more more more seriously, I think you know, it obviously, I think it's going to be a very, very useful thing. You know, it's going to be accelerating, you know, how we go about doing the threat hunting process and everything, which is obviously very, you know, human constrained. Some of the challenges that they kind of talk about there of like, well, how do I know how to write a query on this different format and like ETL, like, these are challenges that
20:58 we've known for a while, and my team had actually created like special like threat hunting languages to actually go do that. You actually write things to just IOBs, and it would go and it would pull it down. And obviously I don't think it was, you know, it didn't revolutionize everything because not everyone's using it currently. But we kind of tried to address some of these challenges.
21:17 So whether or not that is actually what's going to help out, it'll be hard to tell. I'm really curious to see if it allows you to, like, investigate, you know, more deeply, certain threats that humans might not have time for. And I remember reading a debrief of the RSA SecurID hack where it says one person just kept digging and digging and digging and digging, and no one else thought there was anything there, but he just kept going until he finally found that there was a breach.
21:42 These types of things, if—and this is a big if— you know, the agents are good enough to actually follow and see those signals, will actually be very, very interesting. But again, like, you know, Dustin said, like if they aren't that, you know, that good they don't pick up on the signals. They tend to look at, you know, more aggregate things and not necessarily the needle in the haystack.
22:00 It might actually end up providing a false sense of security. Again, I think this is all coming down to it's going to be very, very expensive. Like is it going to be good? It could potentially be amazing, but it's gonna be very expensive. See, and that's where I think there's a difference between how you interpret vibe anything. So let me use the parallel to this.
22:17 X-Force has a vibe fuzzer now. A vibe fuzzer is basically the same thing as a vibe threat hunter. Only this time I'm searching for crashes in a platform. I control the fuzzer, etc. Same deal with a vibe hunt. I chat with an LLM. I say I'm pulling on a thread. It gathers some things. A human says, okay, gather these more threads. I view it as a really advanced assistant.
22:38 I don't think we'll go 100% autonomous, but if I can have it do my triage and enrichment on an automatic basis for me, that's way better than going to a SOC and going click, run 14 run books, I'll come back in six hours. If I can dynamically shape the the hunt effectively by asking for things I'm seeing. So yeah, I saw 30 tickets for this, combine it with a little bit of info on this, and some IP on this, and a threat flash on this, run this hypothesis.
23:03 I'll come back after coffee. That would be far more useful than oh, I'm going to autonomously threat hunt, right. You need to give it some kind of input. Yeah. Ian and Mog, I think both of your responses get it something which is like this, this is a parallel with a lot of the language we've seen around vibe coding. Right? Which is that like, sure, you can have an AI write the code for you and it might be pretty good code, but if you yourself operating it don't know the principles of good software engineering, how good
23:22 is that code going to be, right? Similarly, if you yourself don't know the principles of good threat hunting, how useful is your AI agent going to be when it does that threat hunting? If you can't set it up with the right context, if you can't integrate all that information, and I think that this is worth keeping front of mind when we talk about this stuff, because I think sometimes the eagerness to automate— and I understand why that eagerness is there—but like, it can skip over the fact that that that knowledge is
23:47 like a fundamental, basic requirement there. Claire, let me bring you in here. Any thoughts on your end in terms of, you know, what you're seeing with the conversation around vibe hunting? Are you excited about it? Scared? Interested? What's your take? I feel like we don't need to do everything based on vibes. Like, I don't think we need to vibe code.
24:07 I don't think we necessarily need to vibe hunt. Like the amount of vibe-coded apps I see on LinkedIn in a given day is is a lot. And it's just kind of like, okay, in some instances it makes sense. In other instances, it's just kind of like, what are we doing here? We're doing it just to do it. And I think, like, if the right person is vibe hunting, if the right person is vibe coding, like, I don't want to, like, you know, gatekeeping AI in terms of coding or hunting, but I feel like it it's just like, you need to be
24:36 very detail oriented, still. You need to know what you're querying. You need to, you might miss things if you're just not somebody that has the experience hunting, you know, without the vibes. So it's just kind of, I don't know, I feel like it's in theory, it's great because it allows you to free up your time and all this kind of stuff. In actuality, there's so many little details that kind of make that not a reality right now.
25:05 So I just think you'd probably miss a lot, but I think it would be helpful for somebody who, you know, already knows what they're looking for and is just trying to automate specific tasks within that hunt. But then I guess that's not vibe hunting, because if you're vibe hunting, I guess the definition would be you're just telling the AI to go do it.
25:28 So I guess it depends how you define. I'd argue, though, that vibe hunting is still more useful than a SOC triage analyst manually clicking yes, no, yes, no on tickets all night long. So if I'm going to use these people that have, all of a sudden I've automated triage and put them on level two, I can wrap them in a little AI security blanket and say, go hunt things using the muscle memory you already have.
25:47 Because we trained you for the last year. Go look into the basic things that you did and that might make the people a bit better. So I mean, is it really any different from arming a SOC with 40+ people who just, like, stare at a ticket and close the alert? Well, that's that's the question, right? And that's where I'm kind of getting. I'm wondering, is that like, is it, is something lost?
26:05 Is anything lost? Is it different when you do something like this? Ian, I want to, I want to pose it to you, like, do, you know, either you know, my question about whether something is lost or Mog's question about how different is it, any thoughts there? Like, what's your take? There's definitely going to be like a muscle memory that is lost after a certain point of time.
26:24 So it'll be interesting to see some long-term studies if it's, you know, a big benefit, you know, short term. But then people come to rely on it too much. And like long-term, do they kind of lose their, their feel? Would you be able to continue to do your job if suddenly we took away these tools? I mean, I think that that's a legitimate question, and it's something that I worry about a lot when it comes to things like vibe coding, vibe hunting.
26:46 Now, you know, any kind of use of AI for some of this stuff. Sometimes I wonder, like, how do we keep that muscle memory going? Although it does remind me, in all fairness, not to be, you know, to not be a total doomer about certain things. It does remind me of I, I hosted an episode of MoE once, and I forget who said this. I think, you know, I think it was Martin Keen who said this specifically, which was that like, look, there is a way in which AI can be a thing that atrophies those muscles, but if you're smart about
27:08 it, you can actually use it to build those muscles up, right? Like you can use it to make yourself even better, not just by offloading things, but even better understanding some of that cognitive work that you might be having it doing. So. And so I try to, you know, I try to keep, I try to focus on that optimistic use of it, but. Here's the good thing, right.
27:25 Like, let's look at cursive. I don't use cursive anymore. I got rid of that skill for the ability to go type really fast instead. Yeah, we're gonna lose some skills. We'll gain others. I don't care if I can go Google what an IP is attached to an ASN really fast when I can just look it up using a bash script and some Python APIs. I think that that's a really nice analogy, and I think it's a great place to kind of close out the panel for this week, folks.
27:47 So I want to thank you so much for your time here today. But listeners, stick around because next up, we've got Red Hat's Brent Holden giving us an update on Lightwell. Brent, thanks for joining us. Back in May you came on the show to chat about Project Lightwell, the precursor to this latest announcement. And now we've got the commercial launch of two Lightwell offerings.
28:12 This is Lightwell Network and Lightwell Clearinghouse Premier. To start off, can you just tell us a little bit about what these offerings are, what's going on in Lightwell world? Yeah. Sure thing. Boy, I can't believe it was May. It feels like it was last year in May. A lot has happened since then. So you're right. We GA-ed two products. One full GA was Lightwell Network.
28:31 The way I would frame the products is, like, I worked in manufacturing 20 years ago. I think I mentioned that in the last call. And, you know, when you're, when you run a facility, there was the assembly line, right, of, like, the thing that builds the widget. And then at the end of the line, there's the widget in a box, and you put that in a warehouse.
28:51 So the Lightwell Network, what we GA-ed fully was the warehouse. So it's the place where all the things get put, all the libraries. So you can go download. There's a mixture of Java and Python in there. There's also a mixture of, you know, what we put in there. Some of it was validated libraries that we basically aligned with the upstream community and said, well, here's what's latest in upstream.
29:13 We're going to validate that and put that into the repo. And then there are these remediated libraries. Those are the previous versions that customers typically pin to that they run in production, that we just got to go fix those, give them the updated patch and the updated or the previous version. Now, what we've been working on for the last, let's say, six weeks or so has been primarily building the Lightwell Engine.
29:36 That's the thing that is the assembly line, right. So it's going to take in library reports. That's the cold-rolled steel that comes in. That's the raw materials that we use. Then put it through the assembly line, which, you know, when we first started, was very manual. We were just trying to figure out, you know, the best way to create these libraries.
29:53 At this point, it's a it's like 99% automated with some AI assistance. And then at the end, we have this artifact at the end that then we can then push into the warehouse. So that's where we are. So I really love that industrial analogy you kind of spun up there, because I think when you talk about something like Lightwell, it can sound kind of abstract, right?
30:14 Like, oh, we're securing open source software. Great. What does that actually look like? Well, now you kind of lay it out for us in a way that feels much more concrete. And this is all kind of positioned as part of an effort on on IBM and Red Hat's end to kind of help build the trust infrastructure, as they call it, for open source AI era. I was hoping you could say a little bit more about what exactly it means to to build a a trust infrastructure.
30:35 What is that, and why do we need to build one in the first place? Oh boy, there's a lot in there that you probably didn't necessarily realize, because there's the, when you talk about the clearinghouse, there's just how do people report in when they find vulnerabilities or those vulnerabilities, something that's novel and new, and how do we handle disclosure and embargo and all those sorts of things?
30:56 What does the clean room look like, and how do we take that and validate what they've reported and then put it into the system? Can we check to see like if something has been reported that looks novel, but it's actually related to something that we've already found previously, it's just maybe lower priority? So those are the types of things that we've been working on.
31:14 I think the problem gets a lot bigger when you start talking about these other clearinghouse efforts. So you have these other clearinghouse efforts like Akrites, for example. There's other vendors in the mix. We have, like the European Central Bank is also starting to go through these motions, you know, creating their own clearinghouse. U.S. government is going to be creating a clearinghouse for, you know, who knows who's going to be part of that.
31:35 And so what are the rules of interaction and engagement? Who's actually remediating the thing? Who gets to report the thing? And how does that all work? I think we're still trying to figure all that out. So to answer your question, I think there's a lot of sort of open questions to answer basically around, like, we know what it takes to run a clean room.
31:53 We know what it takes to anonymize vulnerabilities and make sure that nobody's name is on them. And how do we run embargo and disclosure and things like that. But the tougher part becomes like, you know, I would describe complexity as a communication network, and it's the communication network around how do vulnerability disclosures happen among these different clearinghouses, and then who becomes a part of a clearinghouse.
32:16 Is it industry-specific? Is it government-specific? Is it related to like sovereign borders of a country? Like, does France have a clearinghouse for all of the things within its borders? Like that's what some countries are going to have to look at. So it's all those types of problems that, you know, when you talk about running a trust infrastructure, there's just so much more to talk about related to that.
32:39 No, absolutely. And I think it sounds like it's the kind of thing that, you know, we're in a lot of ways we're learning by doing. Right. Like we're figuring out what, like you said, we have to figure out who gets to report these things, who gets trusted in these areas. And that makes a lot of sense to me. So to kind of close out this segment, you know, thinking about this latest announcement from Lightwell, what do you think is kind of the key takeaways for, for for listeners, for viewers out there who are
32:58 thinking about this issue of how we, you know, secure open source software, what do you want them to walk away knowing? Thinking about? What I want them to walk away thinking about is that I've heard from so many customers around, you know, should they use upstream? Should they continue using these libraries that they have? I think for customers, they're going to have to answer that question for themselves.
33:19 But I would generally say the world is completely oriented around patching the internet, as my boss calls it, which is a very abstract thing, just like you said. What does it mean to do that? I think when you get down to the reality of what it looks like for most enterprises, you really have to, you're going to have policies in place. That's probably going to be something like, you're going to have to look at having those libraries in place.
33:42 You're going to have to have the means for patching or remediating within a certain period of time. That used to be six months. Six months is going to be nowhere near quickly enough. I think most companies are looking at 72 hours now. So what does that look like for you? Both, what versions you allow developers to run? How quickly can you get patches into production, and then how important is that next level down, those business applications that can't necessarily update to the latest and greatest?
34:09 There's plenty of them out there. So what does it mean to have a partner like Red Hat? Yeah. And what's really cool to me is that that all really dovetails with so much of what we talked about on this episode. You know, you weren't here for the panel, but like we talked about those accelerating patch timelines, we talked about kind of the use of, of AI in our approaches to vulnerability discovery and fixing those vulnerabilities.
34:30 And so, you know, it's very it's very zeitgeisty, if you will. But that does it for the episode today. I want to thank you, Brent, for being here. Thank you to our panelists, Claire and EvilMog and Ian. Thank you to the viewers and the listeners. Thank you to our producers. Subscribe to Security Intelligence wherever podcasts are found, so that you never miss an episode.
34:47 Stay safe out there, and check out Lightwell. We do have links in the show notes to more information, should you be interested in digging into the nitty-gritty details that we couldn't cover on the episode.
The real risk is not GLM-5.2 alone, but modified or distilled open-weight models with disabled refusal techniques that can run on increasingly smaller systems and provide offensive capabilities without provider guardrails.
The problem isn't to put the AI genie back in the bottle, it's to make the genie ubiquitous across defender networks.
I don't think we'll go 100% autonomous, but if I can have it do my triage and enrichment on an automatic basis for me, that's way better.
Six months is going to be nowhere near quickly enough. I think most companies are looking at 72 hours now.
Works on machine learning and cybersecurity at Meta and wrote the Substack article about GLM-5.2.
01:36