**Brian Gracely** (0:05)
Good morning, good evening, wherever you are, and welcome back to The Enterprise AI Show. I'm your host, Brian Gracely. And today, I want to dive into a topic that's starting to get some buzz. We're starting to see some interesting announcements as well as some global announcements around the idea of what's gonna be the intersection between AI, these new AI tools, and security, and security vulnerabilities, and how companies are gonna be able to keep up with what could potentially be a very large volume and a very large velocity of security vulnerabilities that are gonna start getting created. Unfortunately, because as much as your software developers have access to outstanding coding development tools and things that are gonna help them build software faster, the hackers have just as much access to those tools, or at least they will be very, very soon. So, we're recruiting this on June 16th. I know there's been some things in the news about the Anthropic tools, both Mythos and Fable. This is gonna be a space that's gonna move very, very quickly, but I wanna dive into some things that are happening around the industry and announcements in this space, as well as some discussion about some things to start considering in terms of making sure that your teams are prepared, your organizations are prepared, your infrastructure and environments are prepared for what could begin to be, again, a larger volume of vulnerabilities, a larger velocity, faster velocity of those vulnerabilities, and what that means downstream in terms of impacting your developers, impacting their day-to-day, impacting their ability to keep up with stuff, and then ultimately your infrastructure teams and your operations teams in terms of trying to keep up, make sure that your teams are well prepared for security, for audits, for all the things that come from a legal and compliance perspective. And we're going to dive into that right after the break.
Today's show is sponsored by Nasuni. There's a growing gap in AI right now between what's possible in theory and what successfully works at scale inside an enterprise. The difference comes down to unstructured file data. Many AI initiatives struggle because the file data they depend on is scattered, unstructured, and disconnected from where and how work actually happens. Nasuni changes that. It brings your unstructured file data into a single secure foundation, so AI, both generative and agentic, can access it with the context, governance, and performance it needs in production. Bring AI to where your unstructured data lives. See what it takes to activate your data for AI and request a demo at nasuni.com.
This episode is brought to you by Outshift, Cisco's incubation engine. AI agents today operate in silos, limiting their potential. Scaling up models isn't enough. We need to scale out. Like humans did 70,000 years ago, agents must share knowledge, goals, and innovation to evolve. Outshift by Cisco is building the Internet of Cognition, transforming isolated AI systems into orchestrated super intelligence. This open infrastructure enables agents and humans to share intent, context, and reasoning. The cognition evolution for agents is here. Learn more at outshift.com. That's outshift.com.
Today's show is sponsored by Sharegate. You're out of time. Co-pilot needs to be deployed ASAP, but your tenant really isn't ready for it. Years of data, permissions, and users lurk in its shadows, ready to be exposed by AI. Sharegate Protect sees it all, so you can find the exposure risks, fix them fast, and deploy AI with confidence. Microsoft 365 Governance, they've got this. Learn more at sharegate.com/protect.
We're back. As I mentioned at the top of the show, I want to dive into this thing I'm starting to call on. I'm starting to see more discussion around what I'm calling the vulnerability gap and let me frame this up for you. Obviously, LLMs have been around now for three, three and a half years. People have had wide scale access to that. And while we've talked a million times about the growth that we've seen around it being used for software development and building software tools, building all sorts of things with it, whether it's vibe coding or professional coding, whatever it might be, that also means that those tools are being used by hackers, people that are looking to do some bad things from a security perspective. And so the downside to the advantages of using these tools from a productivity perspective for developers is that the folks developing things that are going to create security vulnerabilities, things that will make your life difficult as a developer, have just as many tools as you do. And in fact, they probably have almost more motivation now because it's cheaper to use those tools. And then this all got put on steroids a few months ago as Mythos from Anthropic was released and kind of released not only out into the wild, well, released in terms of an announcement, partially released to a small number of companies, I think around 40 companies. It's now been expanded to about 150 companies. We've since seen OpenAI come out with the GPT 5.5 cyber. So not only have the ability to create security vulnerabilities and to do stuff been out there with the LLM tools because they're essentially coding tools and they can decode software and do all sorts of things like that. But we're now starting to see a class of these models being built to secure this, specifically around... I'm interested to see if a name comes out of this. I'm calling it sort of AI cyber. Another name may emerge out of this, a more vibe coding type of name. But anyways, they're there looking to not only help folks that are doing cybersecurity, but also can be kind of reverse engineered and be used to create problems for cybersecurity. So you're starting to hear more and more people talk about this idea of sort of a mythos moment in which the industry is going to have to come to this realization that the bad guys, if you will, now have faster and cheaper ways to create vulnerabilities. And this is ultimately going to cause two challenges for companies. The first challenge within this mythos moment is really just an extension of this breaking point that we're starting to get to around 2026 And it's all about the breadth of software that's being developed. So if you look at some numbers, and there's all sorts of stats that come out. But it jumped out at me. I think GitHub published a study here recently. And they basically said about 20% of the world's software has been created this year. And that feels a little bit like when we were in the early days of the internet, where it was like, oh, all of the world's information has doubled in the last two or three years. So 20% of all repositories in GitHub have now been created in this last year or the last six months. It just sort of goes to show that when these tools start to make it very, very easy to write software, to vibe code, to take on projects, to begin to build agents, you're going to see the byproduct of a lot of software being developed. And for a long time, we've said, hey, that's a fantastic thing. Software is eating the world. And we've talked about companies that are good at building software and managing software in a more rapid way, are able to create some really interesting business advantages. So if we go back to software is eating the world circa 2011, we would have thought of software as distinctly a business opportunity. It was going to be a thing that was going to change your business, disrupt business models, do all sorts of things. Now as we get to 2026 and we're seeing massive amounts of software being built, which on the positive side, it's like, okay, new ideas are turning into technology, new opportunities are happening for a whole new class of people that weren't necessarily professional software developers. The flip side of that is somebody or something has to maintain all that software, right? So whether it is having to build things to make sure that it doesn't create hallucinations, whether it is just software maintainers who are getting overwhelmed by AI-generated bugs and PRs and so forth and all sorts of things, we're really getting to a breaking point where, while it's in some cases considered great, we can develop a lot more software for lots of different reasons, whether they are business reasons or personal reasons, the folks who have to maintain that software, and in many cases, those Vibe coders aren't maintaining it. Maybe they're doing the old throwing it over the wall. Somebody is maintaining that. And whether that is in individual projects or it's in massively used open source projects, the folks who are burdened with maintaining it, maintaining its software, maintaining its stability, maintaining its scalability, all those sort of things, are pretty overwhelmed. And now you throw on top of it tools like Mythos and GPT-5, Cyber, and just the wider spread of that, and that breaking point is coming fairly quickly. Right. So what it ultimately kind of has happened is, we're starting to see and we've seen a couple of announcements here in the last couple of weeks, whether it is Project Lightwell from IBM and Red Hat or Athena, which was announced this week from Chain Guard and several other companies. We may see more coming down the road to be determined. Again, we're recording this on June 16th, 2026 But what we're seeing in response to that is we're seeing groups who are either multiple companies or collections of companies. We may see this come out of communities. Basically saying, hey, the old model of software is going to be maintained mostly by humans. You're going to then have a subset of developers who have to keep track of not only maintaining the software, but dealing with prioritization, fixing bugs, dealing with new request, looking at architectures that change, all those things just aren't able to keep up when we're no longer dealing with just human develop software. We've heard for years and years that software developers or maintainers were getting burned out just from dealing with human created software because more and more software is being created. Now, they are distinctly at a disadvantage when the machines are also contributing to the software. So anyways, we're seeing these projects come along and they've got very, very bold claims and really noble concepts to go after. How do we, whether as a collective or a group of people or individual companies, whatever it might be, how do we go about ensuring or better securing open-source software? That's the focus of both Project Lightwell as well as Athena. Now, it's going to be to be determined as to what the scope of that means, because obviously, we know that open-source has thousands and thousands of projects. Some projects are far more widely used than others. I mean, you could just go out to the CNCF landscape or go out to the Linux Foundation or a number of other things, and you're going to see which projects are more widely used than others, or at least there's more dependency upon them. I don't know if I should say widely used, because there's always going to be that use case of that one tool that's used by billions and billions of people, but nobody really knows about some little tiny project. But anyways, we're starting to see these groups that are saying, hey, I guess ultimately in the race to keep up with vulnerabilities, you can look at it one of two ways. You can look at it as if you're an individual company, you're an individual organization, if you try and take this on yourself, you've got three or four things that you really have to consider. Number one is how well are we going to be able to identify what's happening? What are going to be our sources of vulnerabilities? How well are we able to track them? The second is how much skill set do you have in house to go about fixing those things?
15 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000773069225