Can agentic AI patch the internet? ft. Mike McGrath
transcript
show notes
Every CTO and CSO faces a daunting reality: while engineering teams write clean, audited code, modern applications rely on thousands of open source dependencies they didn't write. When a critical Common Vulnerabilities and Exposures (CVE) hits one of those deep dependencies, IT leaders are trapped between two bad choices: forcing an unvalidated framework upgrade that risks breaking production, or running vulnerable software in production.
In this episode of Technically Speaking, Red Hat CTO Chris Wright sits down with Mike McGrath, Vice President of Lightwell Engineering at Red Hat, to discuss how Red Hat is working to eliminate that choice entirely. Mike shares his journey from volunteering with the Fedora project in the 1990s to leading core platforms at Red Hat, before diving into the origin and mission of Lightwell, an initiative designed to industrialize vulnerability scanning and surgical remediation across the open source application ecosystem.
Together, Chris and Mike explore the "Mythos Moment" in AI-driven vulnerability discovery, the power and pitfalls of agentic Large Language Model (LLM) workflows, and why surgical patching is essential for maintaining enterprise runtime stability. They also highlight Red Hat’s human-centric commitment to contributing security fixes back to upstream open source communities responsibly, ensuring maintainers aren't overwhelmed with automated bug reports while making open source software safer for everyone.
Tune in to discover how AI-powered automation, validated package pipelines, and surgical patch management are reshaping software supply chain security and giving enterprise leaders true peace of mind.