An AI agent created fake GitHub identities to get malicious code approved. Cybersecurity advisor and author Nicole Dove joins Adam Arellano and Martin Reynolds to unpack AI agent security, device code phishing, security culture, governance, and the controls needed to secure faster software delivery.
The conversation moves from the UK AI Security Institute incident and Huntress’s reported 1,380% increase in device code phishing to a bigger question: are teams optimizing coding speed while leaving the rest of the software delivery lifecycle behind? Nicole explains why cybersecurity fundamentals, trust, awareness, threat modeling, QA, vulnerability management, and operational controls matter more than another framework. The group also discussed Palantir Technologies (PLTR) and its approach to software.
Nicole Dove is a cybersecurity advisor and the author of Learning Cybersecurity Fundamentals.
Sources discussed:
UK AI Security Institute incident report: https://www.csoonline.com/article/4205612/openai-anthropic-ai-agents-resorted-to-deception-in-new-cybersecurity-incidents.html
Phishing Enters Automation Era Article https://www.axios.com/2026/06/23/ai-automation-phishing-emails-hackers
US government finalized its AI review framework: https://www.techbrew.com/stories/white-house-ai-framework-open-weights-exclusion?w
Connect with
Nicole Dove: https://www.linkedin.com/in/jnicoledove/
Adam Arellano: https://www.linkedin.com/in/adamrossarellano/
Martin Reynolds: https://www.linkedin.com/in/martinreynolds/
Harness: harness.io/
Subscribe to ShipTalk: Shiptalk.io
The conversation moves from the UK AI Security Institute incident and Huntress’s reported 1,380% increase in device code phishing to a bigger question: are teams optimizing coding speed while leaving the rest of the software delivery lifecycle behind? Nicole explains why cybersecurity fundamentals, trust, awareness, threat modeling, QA, vulnerability management, and operational controls matter more than another framework. The group also discussed Palantir Technologies (PLTR) and its approach to software.
Nicole Dove is a cybersecurity advisor and the author of Learning Cybersecurity Fundamentals.
Sources discussed:
UK AI Security Institute incident report: https://www.csoonline.com/article/4205612/openai-anthropic-ai-agents-resorted-to-deception-in-new-cybersecurity-incidents.html
Phishing Enters Automation Era Article https://www.axios.com/2026/06/23/ai-automation-phishing-emails-hackers
US government finalized its AI review framework: https://www.techbrew.com/stories/white-house-ai-framework-open-weights-exclusion?w
Connect with
Nicole Dove: https://www.linkedin.com/in/jnicoledove/
Adam Arellano: https://www.linkedin.com/in/adamrossarellano/
Martin Reynolds: https://www.linkedin.com/in/martinreynolds/
Harness: harness.io/
Subscribe to ShipTalk: Shiptalk.io
- (00:00) - Cold open: AI agents, phishing, and controls
- (00:46) - The AI agent that created fake GitHub identities
- (05:03) - Device code phishing jumps 1,380%
- (06:08) - Meet Nicole Dove
- (07:24) - Attackers automated before defenders
- (09:19) - Cybersecurity fundamentals still win
- (10:43) - Security culture vs. security tooling
- (12:31) - Simulating the pain of a breach
- (15:10) - Building trust with engineering and the business
- (16:50) - Why phishing exploits trusted brands
- (19:03) - Continuous security learning
- (19:53) - AI coding speed vs. secure software delivery
- (21:36) - Government AI reviews and open-weight models
- (24:47) - Policies do not protect you—controls do
- (27:25) - Federal AI, Palantir, and old security assumptions
- (29:05) - What teams get wrong about AI and software delivery
- (30:29) - Final takeaways