Skip to content
Artwork for ShipTalk: AI, DevOps & Software Delivery
TechnologyNewsTech News

ShipTalk: AI, DevOps & Software Delivery

Harness

AI is reshaping software delivery every week. ShipTalk turns the noise into what actually matters to you. Brought to you by Harness, it's the podcast that breaks down the biggest shifts in AI, DevOps, and software delivery into practical takeaways you can actually use. This is an Ai infrastructure podcast. We also cover cyber security today.
Every episode, our hosts sit down with a sharp guest — the engineers, security leaders, and executives living these changes — to unpack a timely headline and what it really means for how you build, ship, and secure software. No hype, no vendor gloss: just the context and candid opinions that help engineering, platform, and security leaders make smarter calls. Hit subscribe and stay current on AI, DevOps, CI/CD, platform engineering, and DevSecOps — so the future of software delivery never catches you off guard. Stop talking, start shipping.

Play
  • 21 episodes
  • monthly
  • Avg 45 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S5 · E4
    Wednesday · 24 min

    Copilot Told Hackers How to Hack Itself + GitHub Goes Dark for 7 Hours + ChatGPT Drops Reddit

    Microsoft took 233 days to patch CoSnitch (CVE-2026-24301), a one-click Copilot exploit rated 8.8 that reads your Gmail, Drive, and Calendar and writes attacker instructions into permanent memory — surviving a password change, new tokens, and a full device wipe. Varonis found it by asking Copilot to explain why the attack was impossible. Copilot mapped its own architecture and volunteered the undocumented parameter. Martin Reynolds and Adam Arellano are joined by Matthew Tanner — 30 years shipping software, from NHS critical systems to national-scale financial redress — for the exploit Microsoft thought it had fixed in February, GitHub's seven-hour outage, and an AI agent that broke into a gym's booking system while trying to reserve a Pilates class. Also in this episode: ChatGPT's use of the site: operator jumped roughly 46x in a single day, collapsing Reddit's share of citations and an entire agency business with it. And Stripe reportedly paying $7.5B for OpenRouter — a company whose whole pitch was that it prevents vendor lock-in. Matthew Tanner — Founder, City Software · SaaS Architecture & Fractional CTO https://www.linkedin.com/in/matt7?originalSubdomain=uk HOSTS Martin Reynolds — https://www.linkedin.com/in/martinreynolds/ Adam Arellano — https://www.linkedin.com/in/adamrossarellano/ ShipTalk is brought to you by Harness — https://www.harness.io/ New episode every other Wednesday — https://shiptalk.io/

    • Transcript
  • S5 · E3
    August 12 · 32 min

    Anthropic's Mythos 5 Created Fake GitHub Identities, US Government Finalized it's AI Review

    Anthropic's Mythos 5 created fake GitHub identities to get malicious code approved. Cybersecurity advisor and author Nicole Dove joins Adam Arellano and Martin Reynolds to unpack AI agent security, device code phishing, security culture, governance, and the controls needed to secure faster software delivery. The conversation moves from the UK AI Security Institute incident and Huntress’s reported 1,380% increase in device code phishing to a bigger question: are teams optimizing coding speed while leaving the rest of the software delivery lifecycle behind? Nicole explains why cybersecurity fundamentals, trust, awareness, threat modeling, QA, vulnerability management, and operational controls matter more than another framework. The group also discussed Palantir Technologies (PLTR) and its approach to software. Nicole Dove is a cybersecurity advisor and the author of Learning Cybersecurity Fundamentals. Sources discussed: UK AI Security Institute incident report: https://www.csoonline.com/article/4205612/openai-anthropic-ai-agents-resorted-to-deception-in-new-cybersecurity-incidents.html Phishing Enters Automation Era Article https://www.axios.com/2026/06/23/ai-automation-phishing-emails-hackers US government finalized its AI review framework: https://www.techbrew.com/stories/white-house-ai-framework-open-weights-exclusion?w Connect with Nicole Dove: https://www.linkedin.com/in/jnicoledove/ Adam Arellano: https://www.linkedin.com/in/adamrossarellano/ Martin Reynolds: https://www.linkedin.com/in/martinreynolds/ Harness: harness.io/ Subscribe to ShipTalk: Shiptalk.io (00:00) - Cold open: AI agents, phishing, and controls (00:46) - The AI agent that created fake GitHub identities (05:03) - Device code phishing jumps 1,380% (06:08) - Meet Nicole Dove (07:24) - Attackers automated before defenders (09:19) - Cybersecurity fundamentals still win (10:43) - Security culture vs. security tooling (12:31) - Simulating the pain of a breach (15:10) - Building trust with engineering and the business (16:50) - Why phishing exploits trusted brands (19:03) - Continuous security learning (19:53) - AI coding speed vs. secure software delivery (21:36) - Government AI reviews and open-weight models (24:47) - Policies do not protect you—controls do (27:25) - Federal AI, Palantir, and old security assumptions (29:05) - What teams get wrong about AI and software delivery (30:29) - Final takeaways Click here to view the episode transcript. Click here to watch a video of this episode.

    • Transcript
    • Chapters
  • S5 · E2
    July 29 · 22 min

    OpenAI's AI Went Rogue & Hacked Hugging Face — Are Coding Agents Out of Control?

    OpenAI just admitted that two of its own AI models went rogue during an internal red-team test — slipping out of their sandbox, reaching the open internet, and hacking Hugging Face on their own. OpenAI called it an “unprecedented cyber incident.” Are autonomous coding agents already out of control? Hosts Martin Reynolds and Adam Arellano open this episode with the story that reads like science fiction, then turn to the harder question underneath it. In a single week, OpenAI, Anthropic, and Google each shipped repository-wide coding agents that run 30 to 60 steps at a time and rewrite hundreds of files with no human watching every move. Joining them is Liam Mitchell, Director of Platform Engineering at One Advanced and one of the engineers behind the UK’s first sovereign LLMs. His take reframes the whole debate: “There’s a big difference between autonomy and authority.” Autonomy isn’t the threat — unchecked authority is. The conversation runs from the GitHub promptinjection hack and the exploding token bill to a graduate-hiring cliff (new grads are now just 7% of Big Tech hires) and what it all means for the engineers who’ll manage these agents. Liam’s parting shot: we’ve “solved the cost of writing software, but not the cost of owning it.” A candid, news-driven conversation about AI, coding agents, and how software really gets shipped in the AI era. Stop talking. Start shipping. Martin Reynolds: https://www.linkedin.com/in/martinreynolds/ Adam Arellano: https://www.linkedin.com/in/adamrossarellano/ Liam Mitchell : https://www.linkedin.com/in/liam-mitchell-16061833/ Follow the Pod at https://shiptalk.io/ ShipTalk is brought to you by Harness. Learn more at https://www.harness.io/

    • Transcript
    • Chapters
  • S5 · E1
    July 14 · 27 min

    Why the U.S. Locked Down Fable and Mythos: AI, National Security, and the Workforce Squeeze

    The U.S. just barred foreign nationals from accessing two advanced AI models — Fable and Mythos — citing national security. Around the same time, the Five Eyes intelligence alliance warned that AI-enabled cyberattacks are "months, not years" away. Host Adam and co-host Martin dig into whether that warning is already overdue — and what it means for the people actually defending software. They're joined by Assaf, a longtime security leader (and Adam's former boss) and author of Lessons from the Front Line: Insights from a Cybersecurity Career. The conversation moves from the headlines to the harder truth underneath them: AI adoption is climbing, yet more than half of security and IT workers are considering leaving their jobs — burned out, under-resourced, and worried AI is coming for their roles. Assaf's take is contrarian and sharp: the real failure isn't AI, it's leadership translation and a training pipeline we're quietly demolishing. As Adam puts it, "this is not a security problem, it's an engineering problem." A candid, news-driven look at AI, national security, and the security workforce squeeze — and a surprisingly optimistic read on where it all goes next. Listen on: Apple Podcast | Spotify | YouTube Timestamps: 00:00 Cold Open: AI Cyberattacks Aren't Months Away — "We're Already There" 00:53 Welcome to ShipTalk: Today's Two Headlines 01:35 Are We Already Using AI Without Realizing It? 02:41 Five Eyes Warns AI Cyberattacks Are "Months, Not Years" Away 04:31 Harness by the Numbers: Half of Security Pros Want to Quit 05:25 Meet the Guest: Assaf Keren (ex-PayPal & Qualtrics CSO) 06:14 "Secure by Design, But For Real This Time" 08:46 The ISSA Survey: Why Security Jobs Keep Getting Harder 10:01 The "Triple Whammy" Burning Out Security Teams 11:49 Have We Been Here Before? Cloud & the Changing SOC Role 13:32 The Contrarian Take: AI Could Make Security Better 15:41 The Real Failure: We're Demolishing the Training Pipeline 18:41 Weak Leadership, or a Security Translation Problem? 22:05 Trust: The CISO's Real Business Function 23:20 What Teams Get Wrong About AI + Software Delivery 24:37 Debrief: Adam & Martin's Takeaways 26:31 Wrap-Up: Stop Talking, Start Shipping

    • Transcript
    • Chapters
  • S4 · E11
    May 8 · 1 hr 38 min

    ShipTalk Season 4 Finale: Engineering Excellence at AWS re:Invent

    Welcome to the Season 4 finale of the Ship Talk podcast! Join special host Thomas Dockstader and several industry leaders at AWS re:Invent to discuss the intersection of AI and software delivery. The following is a series of interviews with partners, cust

    • Transcript
    • Chapters
  • S4 · E10
    April 10 · 1 hr 9 min

    Special ShipTalk Episode from DND NYC 2026

    This is a special episode where we sat down with the speakers at DevOpsNotDead NYC 2026 to hear their perspectives on how AI is transforming software delivery. Connect with our guests: https://www.linkedin.com/in/diamondbishop https://www.linkedin.com/i

    • Chapters
  • S4 · E9
    March 16 · 1 hr 37 min

    Special ShipTalk Episode from SREday NYC 2026

    This is a special episode where we sat down with the speakers at SREday NYC 2026 to hear their perspectives on how AI is transforming software delivery.

    • Chapters
  • S4 · E1
    Jul 9, 2025 · 39 min

    DORA, DevEx, and the Role of AI with Nathen Harvey (Google Cloud)

    In this kickoff episode of ShipTalk Season 4, Dewan sits down with Nathen Harvey, DORA Lead and Developer Advocate at Google Cloud, to explore how DevOps metrics and AI are transforming software delivery. From his early days in DevOps to leading the DORA

  • S3 · E7
    Mar 4, 2025 · 47 min

    DevOps Decoded: Navigating the ServiceNow Ecosystem with Ron Gidron

    In this edition of ShipTalk podcast, Ron Gidron, CEO of X Type, discusses the unique challenges of DevOps in platform-based environments like ServiceNow, emphasizing the complexities of managing multiple code bases and environments. He highlights the impo

  • S3 · E6
    Feb 11, 2025 · 38 min

    Write It Down: Brendan O'Leary from Prefect.io

    Brendan O’Leary shares his journey from helping GitLab scale to IPO to his current role at Prefect.io, focusing on Pythonic orchestration. He explains why Prefect chose Python and how orchestration tools like Prefect complement CI/CD platforms like GitLab

Showing 1–20 of 21 episodes