AI agents turn old dependencies into new attack surfaces

AI-generated photorealistic 3D render of a massive, glowing digital padlock shattering from golden energy bursts above a city
AI is shrinking the window between software flaws being discovered and exploited — and Red Hat says that should worry telcos sitting on years-old open-source code. (Google Gemini)
  • AI is accelerating how fast attackers can exploit old open-source vulnerabilities
  • Red Hat and IBM’s Lightwell has found 400 previously unknown vulnerabilities in Java libraries, including flaws still running in customer production environments
  • Telcos’ long network software lifecycles could leave aging open-source dependencies exposed

AI has turned old software flaws from a slow-burn risk into an immediate target — and Red Hat has found hundreds of previously unknown vulnerabilities hiding in plain sight. That’s bad news for telecom operators, which, like many enterprises, are running significant amounts of aging open-source code.

Mike McGrath, Red Hat’s VP of software engineering, told Fierce that around 60% of the code enterprises are running are upstream open-source unsupported code. The remaining 40% or so is software like Red Hat Enterprise Linux or code that was developed in-house.

“I think a lot of enterprises have had a cross-your-fingers-and-hope sort of model. And the way operators should think about this is they probably should be worried about what they're running,” McGrath said. “The time it takes for attackers to find these vulnerabilities has gone from years and months to days and hours.”

Lightwell, a clearinghouse established by IBM and Red Hat in May to find and fix open-source vulnerabilities before attackers do, has already dug up a lot of dirt. The pair announced this week Lightwell has found 400 previously unknown vulnerabilities in Java libraries.

McGrath told Fierce the oldest vulnerability found was from 2001 (though this was in a non-Java package) and the oldest Lightwell has fixed to date is from 2015. And yes, “these are things customers still have in production and running,” McGrath said.

These issues run the gamut from critical to moderate, but McGrath noted even the lesser-rated vulnerabilities can turn into a big deal in the AI era. “One thing AI does much better than humans is string several vulnerabilities together to create a higher level of vulnerability,” he explained.

Why it all matters for telcos

The takeaway for telcos? Stable no longer means safe – if it ever did. 

“I think the biggest thing is around the life cycle. Telcos tend to have a much longer lifecycle than a standard enterprise, at least in my experience,” McGrath said. And even those that are quick to adopt new technology seem to have “a strong preference to stay on that technology for many, many years. And it’s that long tail that Lightwell can really help out with.”

Backporting is the practical heart of Lightwell’s pitch because it gives operators a way to fix security holes without ripping apart the software stacks they already depend on. Instead of forcing a customer to upgrade to the latest version of a package – and potentially absorb new features, broken APIs or integration changes – Lightwell aims wherever possible to surgically pull the security fix from a newer release and apply it to the older version already running in production. 

In other words, backporting lets telcos reduce exposure to newly discovered vulnerabilities while preserving operational stability and buying time to modernize on their own schedule, rather than under pressure from a security incident, McGrath said.

Fixing the problem – for everyone

Lightwell currently operates using a two-tiered subscription model, with members accessing remediations through Lightwell’s repositories. 

The process of finding vulnerabilities is being undertaken by both Lightwell staff and clearinghouse members. When one is found, McGrath said Lightwell assesses the flaw, develops a fix, tests it and then sends the update to customers. That kicks off a 14-day window designed to give customers a head start on patching their own systems before the issue is pushed upstream. 

McGrath said the approach gives customers an incentive to scan for problems because it gives them lead time, while still ensuring the broader open-source community benefits from the fixes.

“Basically, we have found a way that is very valuable for enterprise customers to spend significant amounts of money on these products in a way that directly funnels code and fixes back into upstream communities,” he said.

But that doesn’t mean open-source maintainers are able to jump on the fixes right away.

As of late last week, McGrath said Red Hat had already sent 25 of these vulnerabilities upstream, with mixed results. In some cases, community maintainers said they did not have time to address an issue immediately, leaving it in the backlog; in others, they accepted the fix but downgraded the severity from critical to moderate or important. 

“We understand that just because we found our vulnerability and reported it upstream that doesn't mean that upstream is going to drop everything they're doing and work on just our vulnerability until it's fixed,” he concluded. 

Read more about open source and security issues on Fierce Network

AI agents are popping up in more places – that’s bad news for telcos

Zero trust for AI agents: SASE vendors race to secure non human users

Cisco rides 'Mythos effect' as AI threats age out old gear

Kubernetes co-founder flags the cloud's big open source problem

AI agents expose 5G core security risks for telecom operators