Searchable transcript of Project Lightwell brings open source security into the AI era — IBM Technology (35:16). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:00 Panelists: What is your biggest concern when it comes to open source security? Maintainer burnout. Trust the model, not the code. Some projects have 0 or 1 maintainer working part time. Others have more resources, so you just don't know what you're getting. Mixed bag. Hello, and welcome to Security Intelligence, IBM's weekly cybersecurity podcast, where our expert panelists turn the biggest industry news stories into practical takeaways that you can use.
00:25 I'm your host, Matt Kosinski. And joining me this week we've got Dave McGinnis, VP/Senior Partner, Global Cyber Threat Management, IBM Consulting and two newcomers to the show. We've got Sophie Cunningham, Dark Web Analyst from X-Force Threat Intelligence, and Brent Holden, Global Field CTO from Red Hat. We'll be chatting about SymJack, a new attack technique targeting AI coding agents, and an AI usage report from LayerX.
00:52 But first, we're going to dive even more into open source security because IBM and Red Hat announced Project Lightwell. Now, this is a $5 billion commitment from IBM and Red Hat, and they're aiming to elevate the security posture of the open source ecosystem as a whole by establishing a trusted enterprise clearinghouse and a team of 20,000 AI augmented engineers to streamline the process of reporting and resolving vulnerabilities, deploying validated patches, and coordinating upstream disclosures.
01:23 Now, Brent, since you are our first Red Hat guest, I'd like to pose the question to you first. Can you tell us a little bit about Lightwell? Walk us through what the thought process is here. What light can you shed for us? Yeah, sure man. Thanks for. Thanks for having me on. Honored to be the first Red Hat guest. Hopefully not the last. That's the goal for today.
01:43 Let's see. Well. Project Lightwell. Well, I think, I'll try and, like, sort of sum up what Red Hat does really well. And then I'll talk about Project Lightwell. What Red Hat does really well is we take upstream open source. We take it as it is. We put it through a productization process and out come the other side is sort of a trusted binary that customers deploy, rely upon.
02:13 They know it's stable. They know they can depend on it when they need to, when it's 3:00 in the morning. Right. That's what Red Hat does really well. And, you know, Red Hat does that for let's say, about 15,000 packages right now between the three different platforms we ship, between Red Hat Enterprise Linux, OpenShift and Ansible Automation Platform.
02:27 Those are the three major platforms we have now. I'd say that the the goal of Project Lightwell is to extend that. And how we're extending it is to language libraries. So think about all the little libraries you use with Java, with Python, with Node.js, even Go, right. There's a lot of things that developers use and leverage. Like the example I like, I love to use is log4j.
02:52 I think everyone's heard of log4j, probably not for the right reasons, but they've heard of it. So almost every Java developer uses it, as we discovered a couple of years ago. And, you know, that functionality is critical to the app running. You need it. And the problem is that occasionally there are security vulnerabilities discovered in these open source libraries.
03:15 Right. And I think with Mythos, what we've discovered is that not only are there vulnerabilities within individual libraries, but occasionally you'll find these sort of libraries that have low severity vulnerabilities that you can chain together to then use as an exploit and get remote access to either the root route or, you know, gain access to customer data or both.
03:38 And so Project Lightwell is a project designed to ship and use Red Hat's productization model for open source, except we're no longer shipping it just for the 15,000 packages we're shipping it for, like the 1.5 million packages within the language library ecosystem. So it's a huge undertaking by Red Hat. You think about just how many of these packages customers have deployed.
04:01 Customers I've seen have deployed, if you include, like the libraries and the individual versions, they could go anywhere from 600,000 to well over a million. Right. For some of our larger FSI customers. So I think that's really where Red Hat's focusing on now, is trying to secure that software supply chain for those language libraries. Absolutely. And I was wondering if you could say a little bit more about why now?
04:22 Right. Like, why is this the moment that you folks feel like it's time to make this move to to expand your remit, if you will? What's going on that's making you feel that way? Yeah, that's a great question. Well, I think everyone's heard of AI at least. You know, I learned how to spell it recently. You know, when it comes to the impact AI has on security.
04:41 Well, there's a couple of things, right? I mentioned how Mythos has the ability to sort of daisy chain these low severity vulnerabilities. I think we've had those scanners in place for a long time. Right. Where what customers will do is they'll take a library from upstream. They'll put it into their artifactory that they host, usually either on prem or with the service, and then their developers consume from that.
05:02 And the scanners usually point to this artifact repository just to make sure that the versions they are consuming are considered secure. And, you know, what we've found is that, well, those tools miss things, right? There's a bunch of sort of undisclosed vulnerabilities that exist within the tools. I think, just like I said, AI, the way I've sort of compared it to, you know, other people internally is sort of like AI is getting a lot smarter, right?
05:30 Like, I love to play chess. It's one of my favorite hobbies. And I think if you're a beginner, you think like zero, one moves ahead. If you're an intermediate, it's 3 to 5. If you're a grandmaster, it's 15 to 20. Mythos is capable of thinking like 50 to 60 moves ahead. So the things it's able to do are things that a human wouldn't be able to do, sort of chaining those vulnerabilities.
05:52 It's really incredible what the model is able to accomplish. So if you think about it that way, security is changing pretty dramatically. Not only are we discovering CVEs at a rapidly increasing rate, but we're also discovering that software is no longer just individual CVEs by themselves. It's a system that interacts together. So we have to start thinking about security a little differently, especially when it comes to the application level.
06:17 And it's really AI and its capabilities that are driving a lot of these discussions. Absolutely. And I'm glad you bring up this idea of Mythos being able to chain things together, because that is like emerging to be maybe like call it Mythos' calling card, right? It's the thing that is really good at is chaining these little vulns together into new attack patterns, which scares me.
06:34 But then Dave over here is telling me he is optimistic about open source security. So I want to bring you in, Dave. Tell me a little bit more about that. How are you feeling about open source security in light of Lightwell? What's your take here? I think we need to look at at the move for Lightwell. And it's it's so classic open source. Right. It is the Red Hat model for everything else.
06:53 Right. Find me a better example of using open source and making it safe and making it trusted, as Brent talked about in the beginning. you're not going to find it. Okay, so so now if we can extend that, which is that whole hope and goal of the 20,000 and the 5 billion, right. Like, like that's that's awesome. Right. And so, you know, trust trust the model.
07:19 And in this case I'm not talking about, you know, an LLM. I'm talking about the model of open source. I mean, I think I think that's, that's huge because like, as we're talking about this and you talk about what the frontier models can do, right? And and it was Mythos and then it was GPT-5.5 and what all public models are, you know what, 9 to 12 months behind the big models.
07:42 I mean, we're going to come up with a different name every few, every few minutes here. Right. So? So the bar has been lowered, right? Like, you do not need to be this, you know, dare I say mythical hacker. If I can jump on the myth thing there. You know, you don't need to be, you know, this this, like, you know, unicorn, you know, of a hacker to to use a tool to do something that you used to be a unicorn to have to piece together.
08:07 I mean, the amount of knowledge that's out there. Okay. So then you look to, well, where are the easiest targets? Because I need to get to source code. Oh, I have a whole idea of where open source code might be. Right. So, so to me, this this is this. This is exactly what the industry needs right now. Right. You need the trusted mediation. You need the you need the multiple sets of eyes.
08:38 I agree with, with Brent and Sophie. You know, there's only so many people to go around and, you know, see previous podcasts. AI will probably help us with that. It's kind of. It's kind of a thing. But like, I this is the. These are the sorts of moves that that make a lot of sense. Right. So, you know, if you don't trust your middleware and you don't trust your open source componentry, and if you don't, what are you going to build?
09:02 You're going to write all of your own code. Well, now I get to go back to the AI because I'm not writing code anymore. Right. AI writes code, right. So you know which which is how we got ourselves into this mess, right? Like nobody set out to write super hacker code. Right. It was good hackers don't write bugs. Find bugs, fix bugs. We just called bugs vulnerabilities.
09:21 That's all. But I think this is tremendous, right? And I think when you look at, like, who's also said, wow, that's a that's that's it. It's everyone with like way more money than we want to imagine. Right. Like all of the major banks, like everybody who's terrified of these things are fully supported on board, ready to roll. Right. So this is this is this is one of those things where you go like, oh, you know, we've had five weeks of, oh my gosh, Mythos is going to kill us, or GPT-5.5 is going to get us, or oh, wait,
09:48 what the DeepSeek do. All right. You know, like and you're just kind of on edge. And it seems like every day it's this sort of thing that says, hey, we can use the tools too. Right. And, and that's my favorite part about all of this. Yeah, I like that. And I like that. You mentioned, you know, earlier you this this idea. And it came up with Brent and Sophie at the very beginning, which is that there's only so many people to maintain open source.
10:11 Right. And the promise of open source is like, you have more eyes looking at it, but those eyes are limited. Sophie, I wanted to to bring you in here to talk a little bit about that. Do you think, as Dave said at the end there, that, like AI can help make it so that those eyes might be limited, but they can still do more? What's your take on that part of the challenge?
10:28 Lightwell, to me is really exciting because I think it's an untapped market. Just in general, I think we're going to be moving to a kind of new era of development in where we're going to be seeing more and more of this hybrid: AI code, human reviewer, human edits, as well as, you know, Lightwell, and entire agent systems. So for me, that's really exciting.
10:48 And, you know, like everyone says here with the the chaining of vulnerabilities. For me, Mythos didn't really scare me. For me, it was more of a just a stage that we have to get through. It's going to be we're going to have a lot of patches, but we'll patch it. We'll use the AI systems, we'll fix it, and then eventually we'll get to a steady state where we're not having to patch a million things a day.
11:17 So it's exciting. And I think it's really needed because in the open source landscape, I've been seeing so many articles in the last couple of months of vulnerabilities for supply chain and like GitHub repos. And so it's definitely needed. So I think anything that businesses are putting towards this is really important. Absolutely. And I love this idea that you bring up of, like Mythos as like a stage we had to go through almost.
11:47 And in a lot of ways, I feel like it's helpful to think about some of these big models as stages, right? As this is development, and as people have constantly pointed out on the show, ever since Mythos came out, it was only a matter of time before, like other models similar to Mythos came out too, and other people had those capabilities. It's never, it doesn't stop.
12:06 It keeps flowing, it keeps evolving. And so we need to keep evolving too. And I think all of you have made a really good case for why this particular evolution, it can be a powerful one when it comes to maintaining open source security, in this current moment. We could talk about Lightwell all day. I do have to move us along here though, folks. But before I do, the viewers and listeners on YouTube, if you have thoughts on open source security, on Lightwell, drop them in the comments.
12:30 I read, I respond, I'm there, you can talk to me, but let's move on to our next story, which Sophie actually gave me a really good bridge to it. Right? Because, Sophie, you had mentioned how we're coming to this hybrid development world where AI writes the code, a human reviews it, and this is an attack tactic that kind of takes advantage of that. This is SymJack.
12:53 Now, researchers at Adversa uncovered a new attack technique that's sort of like ClickFix, but with AI coding agents. The way that it works is that attackers compromise a repository, or they plant a fake one, which includes a malicious instructions file. The file directs the coding agent to copy a quote unquote video file to a harmless folder, but the destination folder is actually a symbolic link that really resolves to the agent's configuration file.
13:16 And that video is actually another configuration file. So basically what they're doing is they're tricking the agent to overwrite its own instructions so that it starts executing attacker code the next time it started up. Now human in the loop is supposed to catch exactly this kind of thing. But as Adversa points out, because the destination and the file are masked, when a human sees that prompt and they're asked, 'Is it okay to copy this video file to this folder?'
13:40 they're going to say yeah, because they think it's harmless. They don't they don't realize what's actually happening there. Dave, I want to start with you here. You know, especially somebody who's been on the show before talking a lot about the importance of human in the loop. Are you worried about these kinds of, like, you know, social engineering attacks, basically, that start to sort of short circuit that human in the loop part of of AI security.
14:01 What's your thoughts here? We're dealing with the same stuff that we've been dealing with. So. Nice cleansing breath, right? We we we know how to fix these problems. Right. This this this this is, you know, every phishing attack ever made. Right? Right. So yes, there are unique AI things that feel like magic, but most of it is not that. Most of it are things that we know how to take care of.
14:26 Right. It's just there's so many of them and they come at us so quickly. Right? Like so. So, you know, humans aren't going to. We've never claimed to be perfect. In fact, I believe when we talk about the weakest link, it's usually a human right. So, you know, I you know, I think I think I really like, you know, the same thing that you just picked up on, you know, from Sophie, is that we're kind of in this transitional period.
14:54 Right? And what happens in transitionary periods is you swing from one end of the pendulum to the other. It was, okay, AI is going to do everything. Oh my God. Humans have to be in the loop for everything. Okay. This is just an example of us overrotating. You know, the pendulum swung a little bit too far in. The humans could say. Well, I can't I might not be able to exploit the code, but I can exploit Dave.
15:16 He's not that he's easy. Like he clicks on everything. I don't, I don't. Don't send me anything. But, but but I mean, that's kind of what we're talking about here, so. So I think there's, there's there's some, you know, you know, I there's a little bit too much hype in it for me, right. You know, like like. Oh, well, we thought we could just put humans in the loop.
15:37 I don't think anyone thought that. I don't. You know, we go through this transitionary period, and then that pendulum starts swinging a little bit more and more and closer, and we will revert to the mean. Right. You know. So, you know, again playing, playing. I tend to like on all of this stuff. Right. Yes. AI is going to be there and yes, we're going to have security problems, but we will solve all of this, right?
16:02 We'll figure out what humans are going to do in the future too. Right. Like all of these things, all of these things are there. So, you know, I mean, I look at it and I see a little bit, a little bit of hyperbole, a little bit more worried than we need to. We know how to stop these types of attacks. They're not, you know, crazy mythical things. We might know them by a different name, or they're coming cloaked, but.
16:24 Yeah, I mean, like, as I kind of, you know, walked through this one, I was like, yeah, yeah, this is this is happening all over the place. We could write an article like this for anything, right? I mean, you know, AI-generated attacks, you guys. Yes. It happens. So. No, no. Like, to me, this is this is that pendulum. What a great analogy. Yeah, I really like the pendulum analogy.
16:48 And this is, you know, it seems to be it's an idea that's coming up a lot more, every time I sit down for one of these these shows, is people talking about how maybe we're reaching this point of like balance in AI finally. Like, the pendulum swung one way, it's swung the other. Are we finally settling into that groove in the middle? Maybe we are. And I also think it's important that you point out that the sort of hype, you know, accompanying some of this, because it is worth mentioning that Adversa reported this to all
17:09 of the LLM makers and, and they pretty much unanimously were like, look, we understand your concerns. But like this is a it's a social engineering attack. Like it's not really a flaw in the model. It's, it's it's more like ClickFix than anything else. And Sophie, I see you nodding along there. So I want to pull you in, you know, what are your thoughts on this attack technique, whether or not it's something really need to be worried about?
17:30 I mean, where do you fall on this? You know? Yeah. I mean, my view is we have to be worried about everything all the time. But I think at the end of the day it is research and really realistically what we see most of the time is the low level attacks are the worst ones. And so just taking away AI, just the phishing component is the concern. And so I think we're fielding that too, despite I don't think threat actors are necessarily jumping to this type of attack versus something that they know will yield results and is
18:05 a lot easier to accomplish. So that was really my my thoughts with it. But I, like you both said, it is a transition and we we just have to learn to protect against it. And right now, because it's a transition piece, I wouldn't feel comfortable completely trusting agentic AI to run my systems, you know, read my emails just because of the stories that come out of them deleting production databases.
18:34 But it doesn't mean we'll never get to that point. And I think we're at we're leveling off and we're getting better at it each day. So it's just a matter of time before I think it really, we really get to a point where it's a synergy. Yeah, two things there. The first is that I think you should be worried about everything all the time is the new tagline for the show.
18:55 We're going to take that. But second of all, I like that you point out that, like, look on paper, this is like an interesting attack technique. But like at the end of the day, if you're an attacker, you can get a similar return for much less effort than like having to poison a repository. Like, you could just send a phishing email, like an old school phishing email.
19:09 And you know, Dave mentioned this too, that like we've often talked about the humans being the weakest link. And so like these are nifty kind of attacks, but like hackers don't really need them necessarily. You know? Brent, I want to bring you in here because Sophie had mentioned, you know, questions around trusting agents in your pipeline, how much human oversight there should be.
19:29 Do you have any thoughts on that end about like, you know, just something like SymJack make you reconsider where agents fit in, like the CI/CD pipeline or, you know, what's your take here? Anything? I would agree. Like, there are just so many easier ways to solve that problem. It seems like a really hard way to solve that problem as of now, but who knows, right?
19:50 Who knows? I, I think in general, what most companies are looking for are guardrails, right, to prevent that kind of thing, like both input and output guardrails. you know, that's like the, like Red Hat acquired a technology called Chatterbox earlier this year. And, you know, part of the reason was because, like, that's kind of fundamentally what what we see our customers using is like they just don't trust the tool by itself.
20:16 They got to put some guardrails around it to make sure it's not going to do anything stupid that they don't trust or do anything, make a decision or make a commitment that they have to follow up on. Like I think for most businesses I talk to, looking at their CI tool is like one thing and trusting decisions there. They also want to make sure the chatbot on the website, like doesn't make a commitment, like selling a car for $20 that they have to follow through on.
20:36 Like that actually happens, right? So I think like that, you know, it's interesting to hear like the, you know, the concerns because, yeah, eventually, like, we will get to a point where, like, it's robots talking to robots, creating software and then it's all specifications that go in. Yeah, we'll totally get there. But I would agree, like, I think for most of the sophisticated companies I talked to, they do have sort of checkpoints because they want people to be liable for the code that gets produced at the end.
21:07 Right. So even if there is like sort of a robot generating the code and it goes through code review, at some point, there has to be a human that's on the hook for liability for that. And like I think Amazon experienced this. They had this, change set that was pushed by AI, and they immediately made a policy change after it took down like a whole availability zone.
21:22 Hey, like no more just straight commits by AI. Human has to review it. Right. So I think there. So yeah. Human in the loop for sure. Like. That's one type of guardrail. Guardrails for the agent. Making sure that like, you can sort of protect against those injection attacks and making sure that what comes out of it is trustworthy and sort of within bounds of what you expect.
21:43 Absolutely. And I'm glad you mentioned kind of guardrails, because that's where I wanted to to kind of close out this segment today was, you know, looking at something like SymJack or just thinking about AI coding agent security in general. What kinds of hardening steps are we thinking about now? And, Brent, I think you covered really well, kind of like those human guardrails and the guardrails around what the agents do.
22:04 But is there anything else that we should be throwing on there? Dave, any thoughts, anything to add there in terms of making sure our agents behave the way you want them to? I'm just going to continue to overuse the pendulum in the in the transition period. I, you know, I find something I like, and I just I'm on it. Right? So, so but, you know, I think and having a lot of conversations with the clients around, around this thing.
22:25 Right. And most of the time it's, you know, how to solve that though. But you know how to solve that, though. But you know how to solve that, though. Right. And so so you have you have you have this. So, so what are the two things that we really want to, we want to watch for? And Brent, you just kind of talked about, you know, a technical way to go do it.
22:43 But you want guardrails around your business processes. Right. Those are the things that companies rely on to make money. Right. Or whatever their stated purpose in the world is. Right. So they have these workflows, these processes that need to execute from point A to point Z, right. And they can be disrupted anywhere along the way and get, you know, covered.
23:04 All right. Well, if I'm going to build agents to go do that, I'd be able I should be able to watch all the steps. I watched the humans that did it before. Right. I've been building automation and orchestration without AI prior. Right. So I know how to solve the problem. Business process is one. And the second one, which, you know, as a security practitioner, I love that folks are paying attention to is just protect the data, man.
23:26 Nothing works if the data is not trustworthy or if it's not available. Or you can ransom it, right? Like, I mean, that's that's what that, you know. Those are the two things, right? So the thing you act on and the thing that does the acting, right. And so, you know, kind of putting those, those sorts of controls in place, strengthening them. It's great.
23:50 The complicating factor is the complexity, right? Like it's really easy for me to sit here and say like, oh, you just got to put guardrails and watch your data, man. What are you doing? Right. Like, but you know, when you start, when you look back and you think about like, well, what? Let's go to the let's go to the, you know, the business outcomes.
24:04 Small, even medium-sized enterprises, right, you know, have all kinds of homegrown code, all kinds. Right. I was with a, a fairly large client last week. Right. And and, you know, they just can't fathom, like, they. I know what to go do. I know what you're going to do. I just have to do it 20,000 times. 20,000, you say? Oh, yes. Because now they they live in a in a in an IT and OT world.
24:35 So their OT world, like nothing talks to each other. So everything grew up bespoke and they like, you know ten, 20,000 was just a SWAG. They don't they really don't know what they've got. Right. And so you know again we don't have to learn what to do. We have to figure out how to address the complexity and the speed that's required. Right. And that to me that's the harder part.
24:59 Right. So but we do know what to do. It's a whole lot better than going like, hey, this thing just happened. We don't know what it is. Right? So we can watch for it. We can protect against it. We can do all these things. It's just the staggering amount of complexity that we've built into into our systems. Right? So, you know, maybe as we're rewriting them all or the sorry, as, as the agents rewrite themselves or whatever as the robots start doing like, you know, maybe that would be a great place to start putting in
25:28 these, these checks and guardrails and things like that, so. Yeah, I like this idea that like, you know how to solve it, right. Because it reminds me of, again, something that came up last week. We were talking, you know, about the sort of almost, call them 'eternal cycles' of security, right. Which is that like we solve a problem, but then a new one pops up.
25:45 But it looks a lot like the old one. It's just a different technology this time. And like that, there are certain patterns of vulnerability that just kind of recur. Right. And so now we're just we're dealing with them in an AI world. And it's just about like you said, we know how to solve it. It's just about adapting to that. We have to move on, though, folks, to our last story for the day.
26:03 This is the AI usage report. LayerX Security has released a state of AI usage report for 2026, which looks at how people are really using AI in the enterprise. And there are some findings and implications that security pros should pay attention to. Among them, the fact that AI use and the associated risk is concentrated among a group of super users, not really spread evenly through the enterprise.
26:30 And the fact that, you know, AI is evolving beyond just a chatbot people talk to, it's now, you know, it's in browser extensions. AI connectors are growing. It's spread throughout. Right. So the use is concentrating, but its appearance is like fragmenting. It's a very interesting kind of dynamic there. Sophie, I'd like to start with you before digging into anything specific that I want to dig into, looking at this report, did anything stand out to you?
26:54 Like what? What did it get you thinking about when you looked at this? I mean, first, statistics are tricky. I think Mark Twain said it best with his quote. And we also don't know the type of organizations, the size, who they're interviewing. So I like to keep that in mind when looking at reports. The most interesting point to me was that power user element.
27:17 And in the report, they kind of recommended focusing on those users for security guidelines, and I understand their point, but I kind of agree to disagree, in that I think a lot of times the less power users can often be more dangerous. And and when I'm thinking of this, I'm thinking of the command line. And so the tack where threat actors will send you a command line code and you insert it.
27:43 And I think power users of the command line are less likely to fall for that versus people who occasionally use the command line will likely put that in. So I don't want to completely discount, non- power users or usual users and not protect against that. But I do agree with their kind of underlying point in that you need a baseline, so you need to understand where your organization is at.
28:15 Understand how it's using AI because there's going to be different protections if you're using it for chatbots or if you're using agentic structures. And get a baseline so you understand really the best way to protect and implement the correct policies. Absolutely. And I think ClickFix is a really good comparison here. Right. It's like you said. Sure.
28:33 You know, a command line is a great example, I think, of something where like use of that is really concentrated because your average user is never touching that thing ever. Right. And so when they do come across something like a ClickFix attack, they have nothing really compared to. They'll put it in there and cause all kinds of problems. So I think it is I think you're very right to kind of shed a different light on this than maybe some of the interpretation in the report is, I like that.
28:59 Brent, how about you? Looking at this report, did anything stick out for you? Is there anything that caught your attention? What are you what are you thinking about? I admit I'm getting a hug from the company this week with Project Lightwell, so been saturated with that. You know, I think in general, I tend to agree with Sophie, which is that the power users I'm less worried about, and largely because there's almost like a mindset shift there as well.
29:18 I'll tell you what I've seen talking to a lot of customers, which is the more novice folks or the folks that are like sort of interacting directly in either like through a web browser like Gemini, for example, or through like Claude Code in an interactive session, those are the folks who are sort of like, I wouldn't necessarily consider them power users.
29:40 They're still directly sort of interacting. They may just find a way to use AI to sort of accelerate a task. The folks that are really powerful with it are the ones that think about it differently, and ones that think about it differently are the ones that think, well, instead of just using AI for code completion, they're using AI to not just write code, but they're handing off a task to them, and AI is just doing the thing for them.
30:06 And so their, think about it. Like as a developer, I used to show up at 9 a.m., right? And then I would leave at five, and I would code and review pull requests all day. And that was my job. And now my job is no longer writing code. It's managing the system that's writing code. And I think the really sophisticated users of AI, that's the way they think about the problem is, like for operators, they're no longer operating systems, they're operating the system that operates the system.
30:30 And so I think in general, like I tend to be a lot less worried about the power users because they understand some of that nuance and that that mindset shift. It's the folks who tend to be more interactive with AI and sort of force feeding AI things to do. Those are the ones that are more susceptible to security risks, I think. For the most part, I view humans as sort of the weakest link in security.
30:50 I totally agree with the things that Dave said. Right. You know, folks, the folks I know, like, I'm not as worried about some of some of the folks that work on our team that are power users of AI than I am worried about, like some of the folks that, you know, they're interacting with Gemini and maybe that's going to like delete data just mistakenly because of like some prompt they put in.
31:11 So. So I tend to sort of lean more on that. I don't know if that answers the question exactly, but. No, I think it absolutely. It absolutely does. Right. Because I think, again, you know, all three of our stories today have had to deal with, like, have had or rather not had to deal with, but have been about like AI and how it's changing things. And a lot of what we talk about on the show is about AI, because that's what everybody's talking about.
31:30 But I think that another thing that's come up in like every single segment, and I love when this happens organically on the show, like on this episode, is this recurring theme of like, don't let AI distract from the fact that, like, people are still people and they're still running things, they're still they're using the agents, they're writing the agent like, you know, so it's I just I like that we're shifting that back and we're thinking about realistically, okay, how do people use AI and given how they use it, what
31:59 does the actual most likely attack pattern look like, rather than just like something we can do in a lab? And it's neat, but maybe it doesn't actually change anything in the real world, you know? Dave, we're coming up on the end of the show here, but I wanted to bring you in, you know, to close this out, looking at this report, any thoughts pop up for you?
32:13 What's your take on the state of AI usage and the risk it poses today? Anything? Yeah, at the risk of being repetitive. Right. I agree with what all three of you you've said, but I think I think the way I look at it, like so okay, we're going to go after the people who are using AI, okay. But you can't draw that as a comparison to privileged users or super.
32:34 Like, privileged users have access. You've given them that. Right. So so I think we have to kind of go back to, you know, like the worry here has got two parts to it, right. You know, one are the human users who really thought the NemoClaw demo was awesome, or boy, Cowork has really just made my life amazing, and they write terrible prompts and they give it way too much permission and they're off.
33:05 Off you go. Right now there are controls to stop, right? There's always a balance. but like like, I think it's just a little too simplistic. And I think that's what all three of you kind of said. Like to just say like, well, just go after the people who are using it. Well, yeah, but how long? Like, what's that going to last you to, Friday? Right. I mean, like, AI is being adopted so fast, you don't know, like, it's it's impossible to kind of go down that path, right?
33:27 So, you know, I think I think that's the human side. And then you have all of the non-human. Right. You know, there are identities that are non-human. We call them agents, right? That, that, that do things when improperly prompted or not properly guardrailed or not harnessed or, you know, pick your term or pick your environment, right. It's off to go do the job it was told to do.
33:57 Right. And so, you know, if it's told to do something and it's like, well, it didn't say not to do that. Right. So it kind of goes back to like I'm just kind of echoing, you know, just maybe, maybe, maybe through just, if nothing else, a different voice, the same sorts of things that the three of you have already said. Right. but I just, I think that that that that's a it's a little bit of an oversimplification and I tend to be the positive one and all this stuff, but what was it?
34:25 We have to be afraid about everything all the time. So thank you. Everything all the time. Yes, exactly. So you know, I'm going to bring you full circle. There you go. You heard it here, folks. You have to be afraid of everything all the time. No, I'm kidding, but that does do it for this episode. I want to thank our panelists, Brent and Dave and Sophie.
34:38 Thank you to the viewers and the listeners. Thank you to our producers. Subscribe to Security Intelligence wherever podcasts are found so that you never miss an episode. Stay safe out there and be sure to check out our latest bonus episode, all about security in multi-modal AI environments, with IBM's VP of Data Security, Vishal Kamat. This is an audio-only bonus episode. It's available on Spotify, YouTube and all the usual listening platforms, so go check it out.
Upstream open-source software is processed into a stable, trusted binary that customers can deploy and rely on.
An expanded version of Red Hat's productization model for language-library packages, supported by vulnerability reporting, validated patches, upstream disclosure coordination, and AI-augmented engineering.
Trust the model, not the code.
You have to be afraid of everything all the time.
IBM company whose open-source productization model is being extended through Project Lightwell.
00:47Organization associated with Sophie Cunningham's dark web analyst role.
00:40Company cited as having changed policy after an AI-pushed change set took down an availability zone.
21:22Repository platform referenced in discussion of open-source supply-chain vulnerabilities.
11:28