IBM and Red Hat have announced Project Lightwell, a $5 billion initiative deploying 20,000 AI-augmented engineers to extend Red Hat's productization model from 15,000 packages to 1.5 million language library packages (Java, Python, Node.js, Go), creating a trusted enterprise clearing house for open source vulnerability reporting and patching. The podcast panel also covers SIMJack, a new attack technique where malicious repository instructions trick AI coding agents into overwriting their own configuration via symbolic links — though panelists largely view it as a social engineering variant rather than a novel threat. A third segment examines the Layer X 2026 AI usage report, with panelists debating whether power users or casual users pose greater security risks, and emphasizing the need for guardrails around both human and non-human (agent) identities in enterprise AI workflows.