Red Hat CEO Matt Hicks: AI Has Changed Open-Source Security
“This breadth of, ‘I use anything I grab from the internet, and I trust it’—I do think those days are over,” Red Hat CEO Matt Hicks said.
Red Hat CEO Matt Hicks said the company’s Lightwell project helps counter AI-powered mass vulnerability exploitation by accelerating open-source patching and reinforcing enterprise trust.
The speed and depth of AI agents exposing open-source software vulnerabilities have changed the industry, Hicks told CRN in an interview. And the changes are for the better.
“It’ll be a great outcome for open source because that transparency drives hygiene,” Hicks said. “The exploitability of seeing it is driving better processes. And we’ll just end up with the best software development practices in the world in open source. … This breadth of, ‘I use anything I grab from the internet, and I trust it’—I do think those days are over.”
[RELATED: IBM CEO Krishna: In The Age Of AI, ‘Who Do You Want To Trust?’]
Securing Open-Source Software In The AI Era
Mechie Nkengla, CEO of Chicago-based solution provider Data Products, which is an IBM partner, said that Red Hat has been evolving beyond a Linux resource into a broader AI infrastructure play through its virtualization and governance capabilities.
“That governance, that people want their own gated, personalized LLM (large language model) within the organization—this is a way to do it,” Nkengla said.
The Red Hat CEO said partners play an important role with Lightwell—a joint effort by Red Hat and its parent company IBM—as well as broadly rethinking protection at the edge, perimeter, network, application level and across IT estates.
During IBM’s latest quarterly earnings call, the company revealed that Lightwell helps to open a multibillion-dollar total addressable market in discovering client security vulnerabilities.
Even though at the time of the call Lightwell had only been available for weeks, the capability has made more than 7,500 open-source patches available for clients securing vulnerabilities.
That number doesn’t count the 30,000 packages done with Linux, HashiCorp, Confluent, Red Hat OpenShift and similar products in IBM’s portfolio. Users range from Bank of America and Morgan Stanley to Wells Fargo and Goldman Sachs, the CEO said.
Lightwell comes at a time when AI models like Anthropic’s Mythos challenge the previous benefit of open-source software having a large community of users policing quality and security. AI now means vendors like Red Hat need to find exploits before threat actors can take advantage—with Hicks noting that proprietary software faces the same issue but with less visibility compared to open source.
“We have GSIs from Deloitte to IBM Consulting saying, ‘Well, if you don’t know how to scan and where your problems are, where can you start to help?’” Hicks said. “There are so many exciting things AI could do, but if we don’t deal with this one first, chasing future opportunities is probably a bit risky.”
Read on for more of Hicks’ thoughts around securing open-source software in the AI era and advice for solution providers navigating the data center components supply chain crisis.
What’s your advice to Red Hat solution providers helping customers address security concerns around Anthropic’s Mythos and other AI models?
Resistance to patching, security hygiene, other things—whether it was the (Anthropic) Mythos moment, whatever created it—it won’t be palatable anymore for companies to not solve this problem.
When we look at what does it take to solve this from critical infrastructure to enterprises, it’s not just going to be one component. We’re working with The Linux Foundation, [the open-source software security initiative] Alpha-Omega and others on, how do you make open-source upstream better in general?
Enterprises do not run the latest software. So we’re stepping up with our Lightwell offerings to say we’ll patch older versions of software. We’re partnered with Palo Alto [Networks] to say: If you can’t patch, how can you mitigate and do intrusion detection rules?
We have GSIs from Deloitte to IBM Consulting saying, ‘Well, if you don’t know how to scan and where your problems are, where can you start to help?’ … On one side, I do appreciate it’s a problem nobody asked for. And we’re busy to begin with.
On the other side, I do think having that hygiene in security—whether you are a bank or an insurance company, wherever you fall—it is a needed hygiene. … This is forcing that topic.
It’s a breadth-and-depth response needed to deal with this. And that’s where I get excited about the partner opportunity.
The broad range of skills from edge and perimeter detection to rethinking your network to your app[lication] spaces to domain experts—we [can] use all the help … we can get.
There are so many exciting things AI could do, but if we don’t deal with this one first, chasing future opportunities is probably a bit risky. … You could hit the downside of it before you’re able to realize the upside and opportunities.
How is AI impacting the patching process?
The application of AI—good and bad actors—it is fundamentally changing processes that we have known and loved for 30 years in open source.
For example, in the olden days, if we found an issue, you would often describe the issue and the core of it because exploitation of those issues were sometimes just so difficult.
You could fix things that may become a future problem without it really becoming a problem. And you could share information easily. It was the ‘1,000 eyes make all bugs shallow’ mentality. … [But] AI is great at finding issues.
It’s also great at building exploits. And you can end up with—those issues that just five years ago couldn’t really be exploitable are now trivially exploitable.
And so we have been going through refining our processes to say, ‘We still have to get things upstream.’ That is the only way I think open source sustains.
We have to reverse this a bit and get patches out first and find smaller trusted circles, which we’ve done to elements on the worst issues and other things.
And now it’s having to become the default. You have to be responsible in how you’re doing disclosures and making sure that we give people a chance to patch. … These have always been potential challenges.
If you found a good enough exploiter—the problem has always been there. AI is just forcing us to very quickly go through and realize these and refine our processes.
It’ll be a great outcome for open source because that transparency drives hygiene. The exploitability of seeing it is driving better processes. And we’ll just end up with the best software development practices in the world in open source.
For us, this isn’t necessarily a challenge we asked for this year. But so be it. We will go in and solve this challenge this year.
Was moving so fast on Lightwell a big shift for Red Hat?
Our whole background has been—we support the software we know. In RHEL (Red Hat Enterprise Linux), we hold binary interfaces (which ensure software compiled for a specific major RHEL version will run properly on later updates without needing to recompile).
We make it as stable as possible, consume the innovation in a way that is reachable for enterprises.
And when we saw this tsunami of issues popping up all over the place in open source—we are familiar with it. We know the space. But we’re not necessarily the experts like we would be in the kernel or Kubernetes.
[But we realized] that if we don’t step in to help this problem, this could damage enterprises’ trust in open source. Even though we can say all day, you should understand the software you’re running. If you’re pulling it for free off the internet, you should probably know what you’re running.
Theorizing what we should have done 20 years ago doesn’t really help. And so, Lightwell moving from software that we’ve known deeply to all open-source software in the world was a big leap for us. But it felt very important.
And we do know AI. So that also changes how fast we can learn software and become experts in it. We certainly know the upstream processes historically, and we want to be a part of, how do we refine and [do] better going forward. And that’s not just for the kernel, but for small communities as well.
And then enterprises really need help. AI is probably better at finding the issues than it is necessarily [better at] building historic software. And we’re very good at that.
Does this feel like an expansion of what Red Hat users expect from the company?
I’ve told a lot of customers, ‘We didn’t even know if this was a business we wanted to be in.’
But it felt like a very important moment to say, ‘Given technology’s changed our knowledge and the market need, it’s the right time to take this leap and go into this space.’
And we’ll learn a lot from it. But it’s been a great experience for us. … [For] partners in the channel, what an opportunity to deeply engage with other partners from hardware partners up that we need to help solve this because the problem is just immense.
So a lot of positive things came out of it. But it [Lightwell] was a stretch for us. It required commitment from us and IBM just on the infrastructure required. Just to build this software required a full conviction and support across everything Red Hat has and everything IBM has. But it was very uniquely positioned to our strengths.
What does the future hold for Lightwell?
Quality has been our first focus. There is the term ‘AI slop.’ AI is very good at finding the issues. [But] truly fixing them—you can go through various studies, but it’s an incredibly challenging space.
Our first focus was: If we give you patches, we need to be pretty confident in what we’re fixing. Which requires this middle ground of—we have to do the uncomfortable work of building exploits to these CVEs (Common Vulnerabilities and Exposures, publicly disclosed computer security flaws). … We can actually do this and fix novel issues with it.
The second challenge just becomes volume and scaling that. How good are we at taking our domain knowledge and amplifying it with AI and moving faster and faster?
But if you go out about three months, the volume that we think we need to get to … in a quarter, we’re probably touching at the reality of what customers could even understand in terms of how much we give them. … Segmentation and packaging, we know [that] will become a very fast reality.
I usually tell customers like, ‘Give us till January.’ … I don’t think we know that yet, whether it is a vertical segmentation.
Whether it’s on a language basis—like how we separate Java from Node. But what we do know is this breadth of, ‘I use anything I grab from the internet, and I trust it’—I do think those days are over.
And so there will be an architectural change we have to figure out with customers. It probably is more of—pick some areas and go deeper. Versus this everything’s trustworthy breadth and I don’t have a deep understanding of it.
But that’ll take time to play out. It is a trend we’re watching. We have gotten to quality. I do think this is solvable.
As it speeds up, given the pace that we need it to speed up on, it’s going to become difficult to understand the information flow. … Let’s say we have 10,000 packages that are out there [hypothetically]. And we’re adding 10,000 a week.
We are still changing the 10,000 that were in there last week. When you look at Red Hat and IBM, maybe as a whole we cover 50,000. We will reach that scope in weeks.
That churn to customers—if you think patching is difficult today, welcome to this world where it’s a constant churn. But we have a lot of technology to bring to bear there.
How could Lightwell pricing and packaging evolve?
If you look at network for $1 million, roughly slightly below, clearing house for [$]5 million, they’re at an account level.
We picked prices which were, if you tried to do this yourself with AI, what are the clear prices that, when you look at your problem and say, ‘If I was the best in the world at AI, could I solve it for this amount?’ We wanted that to be a clear no. … All of this is in the early days. And the problems are changing so fast.
We know we’ll repackage and restructure it. But we tried to pick a point where it encourages partnering and collaboration. We didn’t want price to be a barrier with it.
But I do also appreciate customers say, ‘I didn’t want to have to pay any bill on this.’
I understand. I also didn’t think we should be downloading software from the internet and trusting it. But we are where we are right now.
Does this heightened attention on security open up solution provider opportunities across the Red Hat portfolio?
If you think we’re good at Lightwell, you can see how good we are at Linux on this.
Linux, you have 30 million lines of code just in the kernel. This is the domain we know.
We were scanning in depth on Linux and Kubernetes well before this hit the industry. And so I do think it’s a good area to say, as a partner … if you’re putting a Linux distro (distribution, the complete operating system built around the Linux kernel) in a customer environment, and you don’t know what (recently disclosed Linux kernel security vulnerabilities) Copy Fail, Copy Fail 2, Januscape are, your customers will realize this.
Partnering with us today, we can just take risk off the table. Ansible, OpenShift, these are areas we know incredibly well. And then Lightwell just catches the long tail.
That’s a great area where Lightwell has been a conversation lead and opener. But … the fundamentals are equally valuable to say, ‘It’s not just your app stack.’ At the heart of this, which is often Linux or OpenShift for us, you have to have those secure at this point. Those are really critical entry points for enterprises.
Does this Mythos moment open a discussion around open-source software security compared to proprietary software?
I love the door opener to the conversation, which often can start a little bit negative. ‘What’s all this stuff going on in Linux?’
And then being able to turn that conversation around and say, ‘Linux is one of the most closely scrutinized software bases in the history of the world.’
And yet, AI is still finding actually really substantive vulnerability issues. And we’re fixing them. Do you not think every other vendor and software has the same issues?
What you’re getting to see in open source with Linux in these areas is how well open source does work. Yes, things were found and things were fixed. Linux is the exemplar of how these can be done.
A lot of times, it’ll be what people read in the media. Or they get nervous about it. Flipping that does put customers in a comfortable spot where [they say,] ‘I understand that. That is better. I may not see this as fast in proprietary software where there’s not that open visibility, but it doesn’t mean the issues aren’t there.’
That just creates a whole set of different risks with it. In Linux, you at least know what you’re getting. Or in Kubernetes, you know what you’re getting. You have the whole world focused on actually making these better.
And then it plays right to the heart of—you should only deploy software you understand or from someone who deeply understands it? We do deeply understand RHEL, Linux, OpenShift, Kubernetes.
I like that opportunity. Customers tend to come in maybe a little hot from their CISOs (chief information security officers) frustrated with all the things.
It can become a showcase of just how strong open source is in the space and a really good area for partners to show depth in that area as well.
Going in and not knowing your dependencies on open source, not knowing your position, it’s probably a bit more dangerous to customers or CISOs or CIOs today than it was six months ago.
Anyone who knows how to scan, they can scan proprietary code and open-source code. And they will ask these questions. I have found it a great opportunity with customers just to build that trust a bit more by having depth in the space.
How about on the governance and guardrail side of open source in the AI era?
Open-weight models (AI systems where the final numerical parameters are made publicly available for anyone to download, run and customize) have hit their moment in terms of showing what they can do and where they can compete. … I never thought I would have so many discussions about OpenShell (an open-source security runtime from Nvidia that gives autonomous AI agents safe, isolated sandboxes).
Knowing how powerful agents can be, whether it’s frontier models or open-weight models, how do you put them in a box and trust that work? And we’ve done some great work with Nvidia in this space. … It’s an exciting opportunity because we do have an approach to fix a lot of the cyber issues.
Open-weight models are now becoming very recognized in their capabilities. And keeping that genie in the bottle on it is critically important. And that is a topic all the way down to hardware that we’re really passionate.
Speaking of hardware, what’s been the impact on the Red Hat ecosystem from the global components supply crisis?
Whether it’s good or bad, we tend to be memory or DRAM (dynamic random-access memory) constrained. … The AI demand has been so relentless, you just end up in pinch points where our world of expecting new hardware to be there and racked within a quarter, it probably isn’t going to be stable for a while. … If you look at the core of where we started with OpenShift, it was an efficiency play.
If you go back to the core of virtualization, it was an efficiency play. … While you’re waiting your nine-to-12 months for your new gear to be there, you can make some of these architectural changes that are going to set you up for the future.
Whereas before, it might have just been easier to buy a new box, slap some more VMs (virtual machines) on there, call it a day.
When you end up so infrastructure pinched—whether it’s in storage, RAM, compute, GPUs (graphics processing unit)—there’s an incredible opportunity to look at what you have and figure out how you can use it better.
That’s the sweet spot for Red Hat, from the early days of the kernel on x86 (a popular computer processor instruction set architecture) to the work we’ve done in virtualization to containers [and beyond].
That’s a great area for partners. Instead of just assuming a deal or progress can’t happen because the hardware is delayed, rethinking that to say, ‘OK, if this is AI hardware, I’m going to have to be pretty good at containers to utilize it well.’
Can I kill two birds with one stone? And if I can get them to containers, can they patch better? Do I have a more efficient infrastructure? And then am I set up to use AI?
It takes a level of sophistication there to go through, but this is where partners—this is where they earn their trust with customers in knowing this depth, knowing the technology available and being able to follow through.
Whether it’s virt(ualization), AI work, any of these, there’s a great opportunity for squeezing more out of what you have right now.
What opportunities should partners explore across Red Hat, IBM and IBM’s recently acquired companies?
If you look at Ansible and Hashi(Corp)—I remind people from the dawn of time of CFEngine plus FUNC (Fedora unified network controller) or Puppet and Ansible, that procedural and state based has always existed.
It always will. And there are great opportunities to know how to wield both of those and combine them well.
We obviously do that as one group, but that’s a great opportunity. We partnered well with Hashi before they were at IBM. They’re in the family now. … Confluent, the minute we start talking about AI—I will pick business ops.
If you’re going down an OpenClaw (a free, open-source autonomous AI agent) type background, you end up in a data ingest scenario. … Confluent is a phenomenal opportunity of how are you going to feed in those new data events to process, whether it’s emails or business deals. … In the cyber world, on this, I often tell customers, ‘Look, your first step should be Lightwell Network.’
Plug it in. You see a patch show up in the embargo, you should probably apply it.
But our volume will eventually become more than you’re going to understand. And you’ll need help prioritizing it. And we’re very open in what we do. We publish VEX (Vulnerability Exploitability Exchange) data. Most customers probably are not going to know how to read VEX data. But IBM Concert does.
When you get to the point of saying, ‘I need filtering. I need some prioritization to my environment.’ Concert is a great link there.
Each one of these areas, I do think we have really solid counterparts and complements to what we’re doing on the IBM side. There are a lot more, but those three would jump to mind as combinations I see all the time at this point because they’re strong in their own right.
And being part of one company, it drives us like we’re going to make the integration as strong as we can with these. And so that creates a great opportunity for partners to just have some confidence in how well they’ll work together.