Project Lightwell brings open source security into the AI era
Skills:
AI Security80%
Key Takeaways
Introduces Project Lightwell, an open source security initiative for the AI era
Full Transcript
Panelists, what is your biggest concern when it comes to open source security? >> Maintainer burnout. Trust the model, not the code. >> Some projects have zero or one maintainer working part-time. Others have more resources, so you just don't know what you're getting. Mixed bag. >> Hello and welcome to Security Intelligence, IBM's weekly cybersecurity podcast, where our expert panelists turn the biggest industry news stories into practical takeaways that you can use. I'm your host, Matt Kuzinskas, and joining me this week, we've got Dave McGinnis, VP Senior Partner of Global Cyber Threat Management IBM Consulting, and two newcomers to the show. We've got Sophie Cunningham, dark web analyst from X-Force Threat Intelligence, and Brent Holded, Global Field CTO from Red Hat. We'll be chatting about SIM jacking, a new attack technique targeting AI coding agents, and an AI usage report from LayerX. But first, we're going to dive even more into open source security because IBM and Red Hat announced Project Lightwell. Now, this [snorts] is a $5 billion commitment from IBM and Red Hat, and they're aiming to elevate the security posture of the open source ecosystem as a whole by establishing a trusted enterprise clearing house and a team of 20,000 AI augmented engineers to streamline the process of reporting and resolving vulnerabilities, deploying validated patches, and coordinating upstream disclosures. Now, Brent, since you are our first Red Hat guest, I'd like to pose the question to you first. Can you tell us a little bit about Lightwell? Walk us through what the thought process is here. What what light can you shed for us? >> Yeah, sure, man. Thanks for Thanks for having me on. Honor to be the first Red Hat guest. Um hopefully not the last. That's the goal for today. >> [laughter] >> Let's see. Well, Project Lightwell, I think um I'll try and like sort of sum up what Red Hat does really well, and then I'll talk about Project Lightwell Lightwell. What uh What Red Hat does really well is we take upstream open source, we take it as it is, we put it through a productization process, and out come the other side is sort of a trusted binary that customers deploy, rely upon, um they know it's stable, they know they can depend on it when they need to, when it's 3:00 in the morning, right? That's what Red Hat does really well. And you know, Red Hat does that for I'd say about 15,000 packages right now between the three different platforms we ship, between Red Hat Enterprise Linux, OpenShift, and Ansible Automation Platform. Those are the three major platforms we have. I'd say that the the goal of Project Lightwell is to extend that. And how we're extending it is to language libraries. So, think about all the little libraries you use with Java, with Python, with Node.js, even Go, right? There's a lot of things that developers use and leverage. Like, the example I like I love to use is Log4j. I think everyone's heard of Log4j, probably not for the right reasons, but they've heard of it. Uh so, uh almost every Java developer uses it, as we discovered a couple of years ago. And you know, that functionality is critical to the app running. You need it. And the problem is that uh occasionally there are security vulnerabilities discovered in these open source libraries, right? And I think with uh with Mythos, what we've discovered is that not only are there vulnerabilities within individual libraries, but occasionally you'll find these sort of libraries that have low severity vulnerabilities that you can chain together to then use as an exploit and get remote access to either the root root or, you know, get access to customer data, or both. And so, Project Lightwell is a project designed to ship and use Red Hat's productization model for open source, except we're no longer shipping it just for the 15,000 packages, we're shipping it for like the 1 and 1/2 million packages within the language library ecosystem. So, it's a huge undertaking by Red Hat. You think about just how many of these packages customers have deployed. Customers I've seen have deployed if you include like the libraries and the the individual versions, they could go anywhere from, you know, 600,000 to well over a million, right? For some of our larger enterprise high customers. So, I think that's really where uh Red Hat's focusing on now is trying to secure that software supply chain for those language libraries. >> Absolutely. And I was wondering if you could say a little bit more about why now, right? Like why is this the moment that you folks feel like it's time to make this move, to to expand your remit, if you will. What's going on that that's making you feel that way? >> Yeah, it's a great question. Um well, I think everyone's heard of AI, at least, you know, I learned how to spell it recently. You know, when it comes to the impact AI has on security, well, there's a couple things, right? I mentioned how um Mythos has the ability to sort of daisy chain these low severity vulnerabilities. I think we've had those scanners in place for a long time, right? Where what customers will do is they'll take a library from upstream, they'll put it into their artifactory that they host usually either on prem or with a service, and then their developers consume from that, and the scanners usually point to uh this artifactory repository repository just to make sure that the versions they're consuming are considered secure. And, you know, what we found is that well, those tools miss things, right? There's a bunch of sort of undisclosed vulnerabilities that exist within the tools. And I think um just like I said, AI, um the way I've sort of compared it to uh you know, other people internally is sort of like AI is getting a lot smarter, right? And like, I love to play chess. It's one of my favorite hobbies. And I think if you're a beginner, you think like zero one moves ahead. If you're an intermediate, it's three to five. If you're a grandmaster, it's 15 to 20. Mythos is capable of thinking like 50 to 60 moves ahead. So, the things it's able to do are things that a human wouldn't be able to do, sort of chaining those vulnerabilities. It's really incredible what the model's able to accomplish. So, if you think about that way, security is changing pretty dramatically. Not only are we discovering CVEs at a a rapidly increasing rate, but we're also discovering that software is no longer just individual CVEs by themselves. It's a system that interacts together. And so, we have to start thinking about security a little differently, especially when it comes to the application level. And it's really AI and its capabilities that are driving a lot of these discussions. >> Absolutely. And I'm glad you bring up this idea of Mythos being able to chain things together, because that is like emerging to be maybe like call it Mythos's calling card, right? It's the thing that it's really good at is chaining these little vulnerabilities together into a new attack patterns, which scares me. But then Dave over here is telling me he is optimistic about open source security. So, I want to bring you in, Dave. Tell me a little bit more about that. How are you feeling about open source security in light of Light well? What's your take here? >> I think we need to look at at at the move for Light well and and it's it's it's so classic open source. Right? It's it is the Red Hat model for everything else, right? Find me a better example of using open source and and making it safe, making it trusted as Brent talked about in the game. You're not going to find it. >> [snorts] >> Okay. So, so now if we can extend that, which is the whole hope and goal of the 20,000 and the 5 billion, right? Like like that's that's awesome, right? And so, you know, trust trust the model. And in this case, I'm not talking about, you know, an LLM. I'm talking about the model of open secure of open source. Um I mean, I think I think that's that's huge, cuz like as we're talking about this, and you talk about what the frontier models can do, right? And and it was Mythos and then it was GPT-5.5 And what all public models are, you know, what, 9 to 12 months behind the big models. I mean, we're going to come up with a different name every few every few minutes here. Right. So, so the bar has been lowered, right? Like you do not need to be this you know, I dare I say mythical hacker. Um if I can jump on the myth thing there. Um you know, you don't need to be you know, this this like you know, unicorn um you know, of a hacker to to use a tool to do something that you used to be a unicorn to have to piece together. I mean, the amount of knowledge that's out there. Okay. So, then you you look to well, where are the easiest targets? Cuz I need to get to source code. Oh, I have a whole idea of where open source code might be, right? So, so to me this is this is this this is exactly what the industry needs. Right now, right? You need the trusted um uh you know, mediation. You need the you need the multiple sets of eyes. I agree with with Brent and and Sophie, right? You're you know, there's only so many people to go around and you know, see previous podcast AI will probably help us with that. Uh >> [laughter] >> It's kind of it's kind of a thing. Um but like I I I this is the These are the sorts of moves that that make a lot of sense, right? So, um you know, if you don't trust your middleware and you don't trust your open source componentry and if you don't what are you going to build? You're going to write all of your own code? Well, now I got to go back to the AI cuz I'm not writing code anymore, right? AI writes code. Right. So, you know, which which is how we got ourselves into this mess, right? Like nobody set out to write super hacker code, right? It was good hackers don't write bugs. Find bugs, fix bug. Um we just call bugs vulnerabilities, that's all. But I I think this is tremendous, right? And I think when you look at like who's also said, "Wow, that's a that's that's it." It's everyone with like way more money than we want to imagine, right? Like all of the major banks, like everybody who's terrified of these things are uh fully supported, on board, ready to roll. Right? So, I This is This is This is one of those things where you go like, "Oh, you know, we've had 5 weeks of Oh my gosh, Mythos is going to kill us." Or GPT-5 is going to get us. Or Oh, wait, what did Deep Seek do? All right, you know, like you know, you're just kind of on edge and it seemed like every day. It's this sort of thing that says, "Hey, hey, hey, we can use the tools, too." Right? [snorts] And And that's my favorite part about all this. >> Yeah, I like that. And I like that you mentioned, you know, earlier you you this this this idea. And it came up with Brent and Sophie at the very beginning, which is that there's only so many people to maintain open source, right? And And the promise of open source is like you have more eyes looking at it, but those eyes are limited. Uh Sophie, I wanted to to bring you in here to talk a little bit about that. Do you think, as Dave said at the end there, that like AI can help make it so that those eyes might be limited, but they can still do more? What's your take on that part of the challenge? >> Lightwell's to me is really exciting, because I think it's an untapped market. Um just in general, I think we're going to be moving to a kind of new era of development in where we're going to be seeing more and more of this hybrid AI code, human reviewer, human edits, um as well as, you know, Lightwell, who's entire agentic systems. So, for me that's really exciting. And you know, like everyone says here with the the chaining of vulnerabilities, for me Mythos didn't really scare me. For me, it was more of we I just a stage that we have to get through. It's going to be We're going to have a lot of patches, but we'll patch it, we'll use the AI systems, we'll fix it, and then eventually we'll get to a steady state where we're not having to patch a million things a day. Uh so, it's exciting, and I think it's really needed, because in the open source landscape, I've been seeing so many articles in the last couple months of vulnerabilities for um supply chain and like GitHub repos. And so it definitely needed. So I think anything that businesses are putting towards this is really important. >> Absolutely. And I love this idea that you bring up of like a mythos as like a stage we had to go through almost. And in a lot of ways I feel like it's helpful to think about some of these big models as stages, right? As this is development. And as people have constantly pointed out on the show ever since mythos came out, it was only a matter of time before like other models similar to mythos came out too and other people had those capabilities. It's never it doesn't stop. It keeps flowing and keeps evolving. And so we need to keep evolving too. And I think all of you have made a really good case for why this particular evolution is can be a powerful one when it comes to maintaining open source security in this current moment. We could talk about Lightwell all day. I do have to move us along here though, folks. But before I do, the viewers and the listeners on YouTube, if you have thoughts on open source security on Lightwell, drop them in the comments. I read. I respond. I'm there. You can talk to me. But let's move on to our next story which Sophie actually gave me a really good bridge to it, right? Because Sophie, you had mentioned how we're we're we're coming to this hybrid development world where AI writes the code, a human reviews it. And this is an attack tactic that kind of takes advantage of that. This is Sim Jack. Now researchers at Adversa uncovered a new attack technique that's sort of like click fix but with AI coding agents. The way that it works is that attackers compromise a repository or they plant a fake one which includes a malicious instructions file. The file directs the coding agent to copy a quote-unquote video file to a harmless folder. But the destination folder is actually a symbolic link that really resolves to the agent's configuration file and that video is actually another configuration file. So basically what they're doing is they're tricking the AI agent to overwrite its own instructions so that it starts executing attacker code the next time it's started up. Now, human in the loop is supposed to catch exactly this kind of thing, but as Adversary points out, because the destination and the file are masked, when a human sees that prompt and they're asked, "Is it okay to copy this video file to this folder?" They're going to say, "Yeah." cuz they think it's harmless. They don't They don't realize what's actually happening there. >> [snorts]>> Dave, I want to start with you here. You know, especially somebody who's been on the show before talking a lot about the importance of human in the loop, are you worried about these kinds of like, you know, social engineering attacks basically that that start to search short circuit that human in the loop part of AI security? What's your thoughts here? >> We're dealing with the same stuff that we've been dealing with. So, >> [sighs and gasps] >> nice cleansing breath, right? We We We know how to fix these problems, right? This This This This is, you know, every phishing attack ever made, >> [laughter] >> right? Right? So, yes, there are unique AI things that feel like magic, but most of it is not that. Most of it are things that we know how to take care of, right? It's just there's so many of them and they come at us so quickly, right? Like so So, you know, humans aren't going to They're We've never said claimed to be perfect. In fact, I believe when we talk about the weakest link, it's usually a human, right? So, you know, I you know, I think I think I really like you know, the same thing that you just picked up on, um, you know, from Sophie's side is that is that we're kind of in this transitional period, right? And what happens in transitionary periods is you swing from one end of the pendulum to the other. It was, "Okay, AI is going to do everything. Oh my god, humans have to be in the loop for everything." Okay. This is just an example of us over-rotating, you know, the pendulum swung a little bit too far in the humans could check Well, I can't I might not be able to exploit the code, but I can exploit Dave. He's not that He's easy. like, he clicks on everything. Um I don't I don't don't send me anything. >> [laughter] >> But But But I mean, that's kind of what we're talking about here. So So I think there's there's there's some, you know, you know, I I there's a little bit too much hype in it for me. Right? You know, like like Oh, well, we thought we could just put humans in the I don't think [clears throat] anyone thought that. I don't I don't You know, you know, we we go through this transitionary period and then that pendulum starts swinging a little bit more and more and closer and we will revert to the mean. Right? You know, so, you know, again, playing playing the I tend to like on all of this stuff, right? Yes, AI is going to be there and yes, we're going to have security problems, but we will solve all of this. Right? We'll figure out what humans are going to do in the future, too, right? Like all of these things all of these things are there. So, um you know, I I mean, I look at it and I and I see a little bit of a little bit of hyperbole, a little bit more worried than we need to. We know how to stop these types of attacks. Um they're not you know, crazy mythical things. Uh we we might know them by a different name or they're they're coming cloaked, but um yeah, I mean, that like as I kind of, you know, walk through this one, I was like, yeah, yeah, this is this is happening all over the place. We could write an article like this for anything. Right? I mean, you know, AI generated attacks or you guys >> [laughter] >> Yes, it happens. So, um no Like to me, this is this is that pendulum. And what a great analogy. >> Yeah, I I really like the pendulum analogy. And this is, you know, it it seems to be it's an idea that's coming up a lot more and every time I sit down for one of these these shows is people talking about how maybe we're reaching this point of like balance in AI finally. Like the pendulum swung one one way, it swung the other. Are we finally settling into that groove in the middle? Maybe we are. And I also think it's important that you point out that the the sort of hype account, you know, accompanying some of this because I it is worth mentioning that Adversary reported this to all of the LLM makers and and they pretty much unanimously were like, look, we understand your concerns, but like this is a it's a social engineering attack. Like it's not really a flaw in the model. It's a it's it's more like click fixed than anything else. And so if you I see you nodding along there, so I want to pull you in, you know, what are your thoughts on this uh attack technique, whether or not it's something really need to be worried about. I mean, where do you fall on this, you know? >> Yeah, I mean, my view is we have to be worried about everything all the time, but I think at the end of the day, it is research and really realistically what we see most of the time is the low-level attacks are the worst ones. And so just taking away AI, just the fishing component is the concern and um so I think we're fielding that too despite I don't think threat actors are necessarily jumping to this type of attack versus something that they know will yield results and is a lot easier to accomplish. So that was really my my thoughts with it. Um but I like you both said, it is a transition and we'll we just have to learn to protect against it. And right now because it's a transition piece, I wouldn't feel comfortable completely trusting agentic AI to run my systems, you know, read my emails, just because of the stories that come out of them deleting production databases. But it doesn't mean we'll never get to that point and I think we're at we're leveling off and we're getting better at it each day. So it's just a matter of time before I think it really we really get to a point where it's a synergy. >> Yeah, two things there. The first is that I think you should be worried about everything all the time is the new tagline for the show. We're going to take that. But second of all, I like that you point out that like look, on paper this is like an interesting attack technique, but like at the end of the day, if you're an attacker, you can get a similar return for much less effort than like having to poison a repository. Like you could just send a fishing email, like an old school fishing email. And and and you know, Dave mentioned this too that like we've often talked about the humans being the weakest link. And so like these are nifty kind of attacks, but like hackers don't really need them necessarily, you know? Brent, I want to bring you in here because Sophie had mentioned, you know, questions around trusting agents in your pipeline, how much human oversight there should be. Do you have any thoughts on that end about like, you know, does something like SIM jack make you reconsider where agents fit in like the CI/CD pipeline or or you know, what what's your take here? Anything? >> I would agree like there are just so many easier ways to solve that problem. It seems like a really hard way to solve that problem as of now. Uh but who knows, right? Um who knows? I I think in general, um what most companies are looking for are guardrails, right? To prevent that kind of thing. Like both input and output guardrails. Um you know, that's like the like Red Hat acquired a technology called uh Chatterbox earlier this year. And you know, part of the reason was because like that's kind of fundamentally what I what we see our customers using is like they just don't trust the tool by itself. They got to put some guardrails around it to make sure it's not going to do anything uh stupid that they don't trust or uh do any make a decision or make a commitment that they have to follow up on. Like I think for most businesses I talk to, looking at their CI tool is like one thing um and trusting decisions there. They also want to make sure the chatbot on the website like doesn't make a commitment like selling a car for $20 that they have to follow through on. Like that actually happened, right? So I I think like that um you know, it's interesting to hear like the uh you know, the concerns cuz yeah, eventually like um we will get to a point where like it's robots talking to robots creating software and then it's all specifications that go in. Yeah, we'll totally get there. Um but I would agree like it I think for most of those sophisticated companies I talk to, um they do have sort of checkpoints because they want people to be liable for the code that gets produced at the end, right? So, even if there is like a sort of a robot generating the code and it goes through code review, at some point there has to be a human that's on the hook for liability for that. And like, I think Amazon experienced this, they had this change set that was pushed by AI and they immediately made a policy change after it took down like a whole availability zone. Hey, like, no more just straight commits by AI, a human has to review it, right? So, I think there So, yeah, a human in the loop for guard like that's one type of guardrail, guardrails for the agent, making sure that like you can sort of protect against those injection counts and making sure that what comes out of it is trustworthy. Um and sort of within bounds of what you expect. >> Absolutely. And I'm glad you mentioned kind of guardrails cuz that's where I wanted to to kind of close out this segment today was, you know, looking at something like Sim Jack or just thinking about AI coding agent security in general, what kinds of hardening steps are we thinking about now? And Brent, I think you covered really well kind of like those human guardrails and the guardrails around what the agents do. What is there anything else that we should be throwing on there? Dave, any thoughts anything to add there in terms of making sure our agents behave the way you want them to? >> Just going to continue to overuse the pendulum in the in the transitional period. Uh I, you know, I find something I like and I just I'm on it. Right, so so but you know, I think and and having a lot of conversations with clients around around this thing, right? And most of the time it's You know how to solve that, though. But you know how to solve that, though. But you know how to solve that, though. Right? And so so you have you have you have this. So So, what are the two things that we really want to we want to watch for? And and Brent, you just kind of talked about, you know, a technical way to go do it, but you want guardrails around your business processes, right? Those are the things that companies rely on to make money. Right? Or whatever their stated purpose in in the world is, right? So, they have these workflows, these processes that need to execute from point A to point Z, right? And they can be disrupted at anywhere along the way and get, you know, covered. All right, well, if I'm going to build agents to go do that, I'd be able I should be able to watch all the steps. I watch the humans that did it before, right? I've been building automation and orchestration without AI prior, right? So, I know how to solve the problem. This is process is one and the second one, um which, you know, as a security practitioner, I love that folks are paying attention to is just protect the data, man. Nothing works if the data is not trustworthy, if it's not available, or or you can ransom it, right? Like I mean, that's that's what that, you know, those are the two things, right? So, the thing you act on and the thing that does the acting, right? And so, you know, kind of putting those those sorts of controls in place, um strengthening them, is great. The complicating factor is the complexity, right? Like it's really easy for me to sit here and say like, "Oh, you just got to put guardrails and watch your data, man. What are you doing?" Right? Like but, you know, when you start when you look back and you think about like, well, what let's go to the let's go to the you know, the the business outcomes, the flows. Small, even medium-size enterprises, right? You know, have all kinds of homegrown code. All kinds. Right? I I I was with a um a fairly large client last week, right? And and, you know, they just can't fathom like they I know what to go do, I know what we're going to do. I just have to do it 20,000 times. 20,000, you say? Oh, yes, because now, they they live in a in a in a in an IT and OT world. So, their OT world, like nothing talks to each other. So, everything grew up bespoke, and they like, you know, 10,000 was just a swag. They don't They really don't know what they've got, right? And so, it you know, again, we don't have to learn what to do. We have to figure out how to address the complexity and the speed that's required, right? And and that to me that's the harder part, right? So, um but we do know what to do. It's a whole lot better than going like, "Hey, this thing just happened. We don't know what it is." Right? So, um we can watch for it, we can protect against it, we can do all these things. It's just the the staggering amount of complexity that we've built into into our systems, right? So, um you know, maybe as we're rewriting them all or the Sorry, as as the agents rewrite themselves or whatever, as the robots start doing like, you know, maybe that'd be a great place to start putting in these these checks and guardrails, things like that. So. >> Yeah, I like this idea that like you know how to solve it, right? Because it reminds me of again something that came up last week. We were talking, you know, with about the sort of almost call them eternal cycles of security, right? Which is that like we solve a problem, but then a new one pops up, but it looks a lot like the old one. It's just a different technology this time. And like that there there are certain patterns of vulnerability that just kind of recur, right? And so now we're just we're dealing with them in an AI world. It's just about like you said, we know how to solve it. It's just about adapting to uh we have to move on though, folks, to our last story for the day. This is the AI usage report. LayerX Security has released a state of AI usage report for 2026, which looks at how people are really using AI in the enterprise. And there are some findings and implications that security pros should pay attention to. Uh among them the fact that AI use and the associated risk is concentrated among a group of superusers, not really spread evenly through the enterprise. Uh and the fact that, you know, AI is evolving beyond just a chatbot people talk to. It's now, you know, it's in browser extensions, AI connectors are growing. It's it's it's spread throughout, right? So, the use is concentrating, but its appearance is like fragmenting. It's a very interesting kind of dynamic there. Sophie, I'd [snorts] like to start with you before digging in anything specific and anything that I want to dig into. Looking at this report, did anything stand out to you? Like what what did it get you thinking about when when you looked at this? >> I mean, first, uh statistics are tricky. I think Mark Twain said it best with his quote. Um and we also don't know the type of organizations, the size, who they're interviewing. So, I like to keep that in mind when looking at reports. The most interesting point to me was that power user element. And in the report, they kind of recommended focusing on that those users for security guidelines. And I understand their their point, but I kind of agree to disagree in that I think a lot of times the less power users can often be more dangerous and and when I'm thinking of this, I'm thinking of the command line in So, the TAC where threat actors will send you a command line code and you insert it and I think power users of the command line are less likely to fall for that versus people who occasionally use the command line will likely put that in. So, I don't want to completely discount non-power users or usual users and not protect against that, but I do agree with their kind of underlying point in that you need a baseline. So, you need to understand where your organization is at, understand how it's using AI because there's going to be different protections if you're using it for chatbots or if you're using agentic structures. Um and get a baseline so you understand really the best way to protect and implement the correct policies. >> Absolutely. And I think click fix is a really good comparison here, right? It's like you said, sure, you know, a command line is a great example I think of something where like use of that is is really concentrated cuz your average user is never touching that thing ever, right? And so, when they do come across something like a clickfix attack, they have nothing really compared to. They'll they'll put it in there and and and cause all kinds of problems. So, I think it is I I I think you're very right to kind of shed a different light on this than than than maybe some of the interpretation that in the report is. So, I like that. Uh Brent, how about you? Looking at this report, did anything stick out for you? Was there anything that caught your attention? What do you What are you thinking about? >> um I'm getting a hug from the company this week uh with Project Lightwell. So, um I'm saturated with that. You know what? I think in general um I tend to agree with Sophie, which is that the power users I'm less worried about. And largely because there's almost like a mindset shift there as well. I'll tell you what I've seen talking to a lot of customers, which is the more novice folks are the folks that are like sort of interacting directly in in either like through a web browser, like Gemini for example, or um through like cloud code in an interactive session. Those are the folks who are sort of like um I wouldn't necessarily consider them power users. They're still like directly sort of interacting. They may just find a way to use AI to sort of accelerate a task. The folks that are really powerful with it are the ones that think about it differently. And the ones that think about it differently are the ones that think, "Well, instead of just using AI for code completion, they're using AI to not just write code, but they're handing off a task to them, and AI is just doing the thing for them." And so, they're think about it like as a developer, I used to show up at 9:00 a.m., right? And then I would leave at 5:00, and I would code and review pull requests all day, and that was my job. And now my job is no longer writing code, it's managing the system that's writing code. And I think the really sophisticated users of AI, that's the way they think about the problem is like for operators, they're no longer operating systems, they're operating the system that operates the system. >> [snorts] >> And so, I think in general, like I I tend to be a lot less worried about the power users because they understand sort of that nuance of that that mindset shift. It's the folks who tend to be more interactive with AI and sort of force-feeding AI things to do, those are the ones that are more susceptible to security risks, I think. Um for the most part, I view humans as sort of the weakest link in security. I totally agree with the things that Dave said, right? Um you know, folks the folks I know like I'm not as worried about um you know, some of some of the folks that work on our team that are power users of AI than I am worried about like some of the folks that you know, they're interacting with Gemini and maybe that's going to like delete data just mistakenly because of like some prompt they put in. So, um so I tend to sort of lean more on that. Um I don't know if that answers the question exactly, but >> No, I think it absolutely it absolutely does, right? Because I think again, you know, all three of our stories today have had to deal with like have had or rather not had to deal with, but have been about like AI and how it's changing things. And a lot of what we talk about on the show is about AI because that's what everybody's talking about. But I think that another thing that's come up in like every single segment and I love when this happens organically on the show like it does this episode is this recurring theme of like don't let AI distract from the fact that like people are still people and they're still running things. They're still they're using the agents, they're writing the agent like you know, so it's I just I like that we're shifting that back and we're thinking about realistically, okay, how do people use AI? And and and given how they use it, what does the actual most likely attack pattern look like rather than just like something we can do in a lab and it's neat, but maybe it doesn't actually change anything in the real world, you know? Um [snorts] Dave uh we're coming up on the end of the show here, but I want to do bring you in, you know, to close us out. Looking at this report, any thoughts pop up for you? What's your take on the state of AI usage and and the risk it poses today? Anything? >> Yeah, at the risk of being repetitive, right? I agree with what all three of you you've said, but I think I think the way you know, like I look at it like so, okay, we're going to go after the people who are using AI. Okay, but you can't draw that as a comparison to privilege users or super like privilege users have access. You've given them that, right? So So I I think we have to kind of go back to, you know, like the worry here is is got two parts to it, right? You know, one are the human users who really thought the Nemo Cloud demo was awesome. Or boy, Co-work has really just made my life amazing. And they write terrible prompts and they give it way too much permission and then they're off off you go. Right? Now, um there are controls to stop right there's always a balance. Um but like like I think it's it's just a little too simplistic. I think that that's what all three of you have kind of said like to just say like, "Well, just go after the people who are using it." Well, yeah, but how long it like what's that going to last you till? Friday? Right? I mean like AI is being adopted so fast, you don't know you like it's it's impossible to kind of go down that path, right? So, you know, I think I think that's the human side. >> And and then you have all of the non-human. Right? You know, there are identities that are non-human. We call them agents, right? That that that do things. When improperly prompted or not properly guard railed or not harnessed or you know, pick your term or pick your environment, right? It's off to go do the job it was told to do. Right? And so, you know, if it's told to do something and it's like, "Well, I don't I didn't say not to do that." But so it it kind of goes back to like I'm just kind of echoing, you know, just kind of maybe maybe maybe through a just if nothing else a different voice uh the same sorts of things that the three of you have already said. Right? Um but I I just I think that that that that's a it's a little bit of an oversimplification and and I'm tend to be the positive one on all this stuff, but what was it we're we have to be afraid about everything all the time? So, thank you so much. >> time. Yes, exactly. >> So, you know, I'm going to bring you full circle. There you go. >> [laughter] >> You heard it here, folks. You have to be afraid of everything all the time. No, I'm kidding. But that does do it for this episode. I want to thank our panelists, Brent, and Dave, and Sophie. Thank you to the viewers and the listeners. Thank you to our producers. Subscribe to Security Intelligence wherever podcasts are found so that you never miss an episode. Stay safe out there, and be sure to check out our latest bonus episode all about security in multimodal AI environments with IBM's VP of Data Security, Vishal Kamat. bonus episode. It's available on Spotify, YouTube, and all the usual listening platforms. So, go check it out.
Original Description
Explore the podcast → https://ibm.biz/~20kwS8piW
Open source software powers more than 90% of Fortune 500 companies. It also powers a growing number of cyberattacks.
This week on Security Intelligence, we dig into IBM and Red Hat's $5 billion answer to that problem: Project Lightwell, a massive investment in AI-augmented engineers and a trusted security clearinghouse designed to shore up the open source ecosystem from the inside out.
We also break down SymJack, a clever new attack technique that turns AI coding agents against themselves by tricking them into overwriting their own configuration files. And the most worrisome part is how it gets around human-in-the-loop checks.
And: LayerX's "State of AI Usage Report 2026" shows AI adoption isn't spreading evenly across organizations. We explore what it means for cybersecurity pros when AI fragments throughout the software supply chain while simultaneously concentrating in the hands of a few power users.
Segments:
00:00 - Intro
1:05 - Project Lightwell
12:51 - SymJack
26:11 - AI usage in 2026
The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity.
AI news moves fast. Sign up for a monthly newsletter for AI updates from IBM → https://ibm.biz/~nwd2OS9Lz
#projectlightwall #SymJack #cybersecurity
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
More on: AI Security
View skill →Related Reads
📰
📰
📰
📰
What smart people are saying about IBM’s AI warning and SaaSpocalypse fears
Dev.to AI
Dutch company ASML is $300bn from a trillion. AI could close the gap
The Next Web AI
ARR 2026 Meta Review score [D]
Reddit r/MachineLearning
The AI Debate Isn’t New. History Has Heard It Before.
Medium · AI
Chapters (4)
Intro
1:05
Project Lightwell
12:51
SymJack
26:11
AI usage in 2026
🎓
Tutor Explanation
DeepCamp AI