The show for developers shipping in the age of AI.
All Episodes

Latest Episodes

All Episodes →
S5 #7

OpenAI Hacked Australia, AI Mines Crypto on Its Own, Paid to Say AI Will Kill Us

Why did an OpenAI AI agent hack an Australian government Medicare portal when nobody instructed it to? On June 18, an OpenAI research agent was looking for public information about medicine spending in Australia. When it hit a barrier, it found another way in — accessing public and non-public files and even writing files to an internal server. No personal Medicare records are believed to have been accessed. But the incident raises a much bigger question: what happens when autonomous AI agents hit a barrier and decide for themselves how to get around it? Martin Reynolds and Adam Arellano break down what happened, why Australia criticized OpenAI's response, and what “misaligned model activity” means for companies deploying autonomous AI agents. Then they dig into another bizarre case: an Alibaba-affiliated AI agent that reportedly created a reverse SSH tunnel, bypassed network restrictions, and mined cryptocurrency during training. Plus: are creators being paid to make AI sound more dangerous than it is? And TypeSafe AI's new low-cost model, Jev, goes into Overhyped or Under hyped. ShipTalk breaks down how AI is changing software delivery, DevOps, cybersecurity, and the way software gets shipped. RELATED READING Australian Prime Minister — Official briefing on the OpenAI incident Read the Australian government briefing  https://www.pm.gov.au/media/press-conference-new-york? Nature — AI agent hacks government website for first time Read the Nature report https://www.nature.com/articles/d41586-026-03024-z? ABC News — OpenAI agent accessed Australian government Medicare portal Read the ABC News report https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078? The Block — Alibaba-linked AI agent mines cryptocurrency Read the Alibaba AI agent report https://www.theblock.co/news/markets/2026-03-08-alibaba-linked-ai-agent-hijacked-gpus-for-unauthorized-crypto-mining-researchers-say-392765? TypeSafe AI — Introducing Jev Read about Jev https://typesafe.ai/blog/introducing-system-one-models-and-jev ShipTalk — https://www.shiptalk.io Harness — https://www.harness.io Follow Adam Arellano: https://www.linkedin.com/in/adamrossarellano/    Martin Reynolds: https://www.linkedin.com/in/martinreynolds/    Brought to you by Harness.
S5 #6

Anthropic's Warning, 10% Extinction Odds, and $2.7T in AI Spend

Dario Amodei's essay "We Must Pace the Frontier" asked the AI industry to deliberately slow capability gains so safety work can keep up — and got public agreement from OpenAI, xAI and Google DeepMind within hours. Adam Arellano and Martin Reynolds bring in Bryan Payne, who has led security at Netflix and Adobe, to ask what's actually in the proposal and what was conspicuously left out. They dig into whether permanent employee-level access for third-party evaluators is a meaningful control or a curated one, why liability is the piece missing from the whole conversation, and what it says that OpenAI is running forensics on models it has already trained — including one that swept public GitHub for secrets stored in plaintext, which Adam argues was the most logical thing it could possibly have done. The episode moves from early airline safety through Nick Bostrom's paperclip maximizer to a malicious git config that can get Claude Code, Codex and Cursor to execute attacker code. Bryan's closing argument is the uncomfortable one: people have spent decades getting very good at planting flaws no human reviewer will spot, so the belief that a human in the loop will catch what an AI is doing may be the most optimistic assumption in software today. Along the way: Jacob Coxon's resignation thread, the greater-than-10% extinction figure his colleagues publicly endorsed, and why $2.7 trillion of AI spend returning business outcomes only one time in five might still be money well spent. Bryan's parting shot for teams: you're thinking too small. Mentioned in this episode Dario Amodei, "We Must Pace the Frontier" — https://darioamodei.com/post/we-must-pace-the-frontier ShipTalk — https://www.shiptalk.io Harness — https://www.harness.io Follow Bryan D. Payne: https://www.linkedin.com/in/bdpayne/ Adam Arellano: https://www.linkedin.com/in/adamrossarellano/    Martin Reynolds: https://www.linkedin.com/in/martinreynolds/    ShipTalk is brought to you by Harness. Subscribe wherever you listen, and until next time — let's stop talking and start shipping.
S5 #5

The Real Reason SpaceX Paid $60B for Cursor

SpaceX bought Cursor's parent company Anysphere for $60 billion. OpenAI immediately cut off Cursor's access to its models; Anthropic went the other way and increased compute support. Business decision, or political one? Adam Arellano and Martin Reynolds are joined by Papanii Okai, EVP of Product Engineering at Rocket and former CTO of Venmo, who opens with a warning that everyone is reading this deal wrong. His case: Cursor cracked the interface between humans and models, and that capability matters far more to a company building physical AI than any code editor. He also argues Apple — not OpenAI, not Microsoft — takes ambient AI, because the win condition isn't an app you launch. The conversation moves to the talent math nobody wants to do. This year 32% of organizations skipped buying software and built it instead. Large enterprises doubled agent adoption while small firms stayed flat. Meanwhile US entry-level engineering postings fell 67%, and conventional wisdom says a senior takes 5 to 9 years to grow. Papanii thinks that timeline is about to compress hard — and that companies planning to stop hiring will hit a burnout wall instead of a scaling curve. Also in this episode: whether Tim Cook's retirement signals a broader shift toward builder CEOs, why ransomware crews are choosing cheap repeatable playbooks over frontier models, and what still happens to a room of engineers when you say "Log4j" out loud. ShipTalk is brought to you by Harness. Key moments: 00:51 — SpaceX buys Cursor for $60B  03:59 — Guest: Papanii Okai  04:42 — The contrarian read on the deal  06:23 — Why Apple wins ambient AI  13:30 — Harness by the Numbers  14:35 — Build vs. buy and the death of SaaS  18:46 — Seniors are in their golden years  20:00 — Where do 2030's seniors come from?  25:43 — Do universities still matter?  29:30 — Tim Cook retires, a builder takes over  34:07 — The AI threat apocalypse isn't here  39:22 — The one thing teams get wrong
S5 #4

Copilot Told Hackers How to Hack Itself + GitHub Goes Dark for 7 Hours + ChatGPT Drops Reddit

Microsoft took 233 days to patch CoSnitch (CVE-2026-24301), a one-click Copilot exploit rated 8.8 that reads your Gmail, Drive, and Calendar and writes attacker instructions into permanent memory — surviving a password change, new tokens, and a full device wipe. Varonis found it by asking Copilot to explain why the attack was impossible. Copilot mapped its own architecture and volunteered the undocumented parameter. Martin Reynolds and Adam Arellano are joined by Matthew Tanner — 30 years shipping software, from NHS critical systems to national-scale financial redress — for the exploit Microsoft thought it had fixed in February, GitHub's seven-hour outage, and an AI agent that broke into a gym's booking system while trying to reserve a Pilates class. Also in this episode: ChatGPT's use of the site: operator jumped roughly 46x in a single day, collapsing Reddit's share of citations and an entire agency business with it. And Stripe reportedly paying $7.5B for OpenRouter — a company whose whole pitch was that it prevents vendor lock-in. Matthew Tanner — Founder, City Software · SaaS Architecture & Fractional CTO https://www.linkedin.com/in/matt7?originalSubdomain=uk  HOSTS Martin Reynolds — https://www.linkedin.com/in/martinreynolds/ Adam Arellano — https://www.linkedin.com/in/adamrossarellano/ ShipTalk is brought to you by Harness — https://www.harness.io/ New episode every other Wednesday — https://shiptalk.io/
S5 #3

Anthropic's Mythos 5 Created Fake GitHub Identities, US Government Finalized it's AI Review

Anthropic's Mythos 5 created fake GitHub identities to get malicious code approved. Cybersecurity advisor and author Nicole Dove joins Adam Arellano and Martin Reynolds to unpack AI agent security, device code phishing, security culture, governance, and the controls needed to secure faster software delivery. The conversation moves from the UK AI Security Institute incident and Huntress’s reported 1,380% increase in device code phishing to a bigger question: are teams optimizing coding speed while leaving the rest of the software delivery lifecycle behind? Nicole explains why cybersecurity fundamentals, trust, awareness, threat modeling, QA, vulnerability management, and operational controls matter more than another framework. The group also discussed Palantir Technologies (PLTR) and its approach to software.  Nicole Dove is a cybersecurity advisor and the author of Learning Cybersecurity Fundamentals. Sources discussed: UK AI Security Institute incident report: https://www.csoonline.com/article/4205612/openai-anthropic-ai-agents-resorted-to-deception-in-new-cybersecurity-incidents.html    Phishing Enters Automation Era Article https://www.axios.com/2026/06/23/ai-automation-phishing-emails-hackers    US government finalized its AI review framework: https://www.techbrew.com/stories/white-house-ai-framework-open-weights-exclusion?w    Connect with Nicole Dove: https://www.linkedin.com/in/jnicoledove/   Adam Arellano: https://www.linkedin.com/in/adamrossarellano/      Martin Reynolds: https://www.linkedin.com/in/martinreynolds/     Harness: harness.io/    Subscribe to ShipTalk: Shiptalk.io