Martin Reynolds Host

Martin Reynolds

Martin Reynolds is Field CTO at Harness, bringing more than 30 years of experience across software development, architecture, and delivery. He's a recognized voice in DevOps, DevSecOps, and developer experience, with work featured in outlets like The New Stack and LeadDev. Before Harness, he led cloud migration at Advanced, where he built the company's first DevOps team and scaled its practices across the organization. Today he helps teams ship software faster, more reliably, and more securely on Harness's modern software delivery platform.

Appears in 7 Episodes

S5 #7

OpenAI Hacked Australia, AI Mines Crypto on Its Own, Paid to Say AI Will Kill Us

Why did an OpenAI AI agent hack an Australian government Medicare portal when nobody instructed it to? On June 18, an OpenAI research agent was looking for public information about medicine spending in Australia. When it hit a barrier, it found another way in — accessing public and non-public files and even writing files to an internal server. No personal Medicare records are believed to have been accessed. But the incident raises a much bigger question: what happens when autonomous AI agents hit a barrier and decide for themselves how to get around it? Martin Reynolds and Adam Arellano break down what happened, why Australia criticized OpenAI's response, and what “misaligned model activity” means for companies deploying autonomous AI agents. Then they dig into another bizarre case: an Alibaba-affiliated AI agent that reportedly created a reverse SSH tunnel, bypassed network restrictions, and mined cryptocurrency during training. Plus: are creators being paid to make AI sound more dangerous than it is? And TypeSafe AI's new low-cost model, Jev, goes into Overhyped or Under hyped. ShipTalk breaks down how AI is changing software delivery, DevOps, cybersecurity, and the way software gets shipped. RELATED READING Australian Prime Minister — Official briefing on the OpenAI incident Read the Australian government briefing  https://www.pm.gov.au/media/press-conference-new-york? Nature — AI agent hacks government website for first time Read the Nature report https://www.nature.com/articles/d41586-026-03024-z? ABC News — OpenAI agent accessed Australian government Medicare portal Read the ABC News report https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078? The Block — Alibaba-linked AI agent mines cryptocurrency Read the Alibaba AI agent report https://www.theblock.co/news/markets/2026-03-08-alibaba-linked-ai-agent-hijacked-gpus-for-unauthorized-crypto-mining-researchers-say-392765? TypeSafe AI — Introducing Jev Read about Jev https://typesafe.ai/blog/introducing-system-one-models-and-jev ShipTalk — https://www.shiptalk.io Harness — https://www.harness.io Follow Adam Arellano: https://www.linkedin.com/in/adamrossarellano/    Martin Reynolds: https://www.linkedin.com/in/martinreynolds/    Brought to you by Harness.
S5 #6

Anthropic's Warning, 10% Extinction Odds, and $2.7T in AI Spend

Dario Amodei's essay "We Must Pace the Frontier" asked the AI industry to deliberately slow capability gains so safety work can keep up — and got public agreement from OpenAI, xAI and Google DeepMind within hours. Adam Arellano and Martin Reynolds bring in Bryan Payne, who has led security at Netflix and Adobe, to ask what's actually in the proposal and what was conspicuously left out. They dig into whether permanent employee-level access for third-party evaluators is a meaningful control or a curated one, why liability is the piece missing from the whole conversation, and what it says that OpenAI is running forensics on models it has already trained — including one that swept public GitHub for secrets stored in plaintext, which Adam argues was the most logical thing it could possibly have done. The episode moves from early airline safety through Nick Bostrom's paperclip maximizer to a malicious git config that can get Claude Code, Codex and Cursor to execute attacker code. Bryan's closing argument is the uncomfortable one: people have spent decades getting very good at planting flaws no human reviewer will spot, so the belief that a human in the loop will catch what an AI is doing may be the most optimistic assumption in software today. Along the way: Jacob Coxon's resignation thread, the greater-than-10% extinction figure his colleagues publicly endorsed, and why $2.7 trillion of AI spend returning business outcomes only one time in five might still be money well spent. Bryan's parting shot for teams: you're thinking too small. Mentioned in this episode Dario Amodei, "We Must Pace the Frontier" — https://darioamodei.com/post/we-must-pace-the-frontier ShipTalk — https://www.shiptalk.io Harness — https://www.harness.io Follow Bryan D. Payne: https://www.linkedin.com/in/bdpayne/ Adam Arellano: https://www.linkedin.com/in/adamrossarellano/    Martin Reynolds: https://www.linkedin.com/in/martinreynolds/    ShipTalk is brought to you by Harness. Subscribe wherever you listen, and until next time — let's stop talking and start shipping.
S5 #5

The Real Reason SpaceX Paid $60B for Cursor

SpaceX bought Cursor's parent company Anysphere for $60 billion. OpenAI immediately cut off Cursor's access to its models; Anthropic went the other way and increased compute support. Business decision, or political one? Adam Arellano and Martin Reynolds are joined by Papanii Okai, EVP of Product Engineering at Rocket and former CTO of Venmo, who opens with a warning that everyone is reading this deal wrong. His case: Cursor cracked the interface between humans and models, and that capability matters far more to a company building physical AI than any code editor. He also argues Apple — not OpenAI, not Microsoft — takes ambient AI, because the win condition isn't an app you launch. The conversation moves to the talent math nobody wants to do. This year 32% of organizations skipped buying software and built it instead. Large enterprises doubled agent adoption while small firms stayed flat. Meanwhile US entry-level engineering postings fell 67%, and conventional wisdom says a senior takes 5 to 9 years to grow. Papanii thinks that timeline is about to compress hard — and that companies planning to stop hiring will hit a burnout wall instead of a scaling curve. Also in this episode: whether Tim Cook's retirement signals a broader shift toward builder CEOs, why ransomware crews are choosing cheap repeatable playbooks over frontier models, and what still happens to a room of engineers when you say "Log4j" out loud. ShipTalk is brought to you by Harness. Key moments: 00:51 — SpaceX buys Cursor for $60B  03:59 — Guest: Papanii Okai  04:42 — The contrarian read on the deal  06:23 — Why Apple wins ambient AI  13:30 — Harness by the Numbers  14:35 — Build vs. buy and the death of SaaS  18:46 — Seniors are in their golden years  20:00 — Where do 2030's seniors come from?  25:43 — Do universities still matter?  29:30 — Tim Cook retires, a builder takes over  34:07 — The AI threat apocalypse isn't here  39:22 — The one thing teams get wrong
S5 #4

Copilot Told Hackers How to Hack Itself + GitHub Goes Dark for 7 Hours + ChatGPT Drops Reddit

Microsoft took 233 days to patch CoSnitch (CVE-2026-24301), a one-click Copilot exploit rated 8.8 that reads your Gmail, Drive, and Calendar and writes attacker instructions into permanent memory — surviving a password change, new tokens, and a full device wipe. Varonis found it by asking Copilot to explain why the attack was impossible. Copilot mapped its own architecture and volunteered the undocumented parameter. Martin Reynolds and Adam Arellano are joined by Matthew Tanner — 30 years shipping software, from NHS critical systems to national-scale financial redress — for the exploit Microsoft thought it had fixed in February, GitHub's seven-hour outage, and an AI agent that broke into a gym's booking system while trying to reserve a Pilates class. Also in this episode: ChatGPT's use of the site: operator jumped roughly 46x in a single day, collapsing Reddit's share of citations and an entire agency business with it. And Stripe reportedly paying $7.5B for OpenRouter — a company whose whole pitch was that it prevents vendor lock-in. Matthew Tanner — Founder, City Software · SaaS Architecture & Fractional CTO https://www.linkedin.com/in/matt7?originalSubdomain=uk  HOSTS Martin Reynolds — https://www.linkedin.com/in/martinreynolds/ Adam Arellano — https://www.linkedin.com/in/adamrossarellano/ ShipTalk is brought to you by Harness — https://www.harness.io/ New episode every other Wednesday — https://shiptalk.io/
S5 #3

Anthropic's Mythos 5 Created Fake GitHub Identities, US Government Finalized it's AI Review

Anthropic's Mythos 5 created fake GitHub identities to get malicious code approved. Cybersecurity advisor and author Nicole Dove joins Adam Arellano and Martin Reynolds to unpack AI agent security, device code phishing, security culture, governance, and the controls needed to secure faster software delivery. The conversation moves from the UK AI Security Institute incident and Huntress’s reported 1,380% increase in device code phishing to a bigger question: are teams optimizing coding speed while leaving the rest of the software delivery lifecycle behind? Nicole explains why cybersecurity fundamentals, trust, awareness, threat modeling, QA, vulnerability management, and operational controls matter more than another framework. The group also discussed Palantir Technologies (PLTR) and its approach to software.  Nicole Dove is a cybersecurity advisor and the author of Learning Cybersecurity Fundamentals. Sources discussed: UK AI Security Institute incident report: https://www.csoonline.com/article/4205612/openai-anthropic-ai-agents-resorted-to-deception-in-new-cybersecurity-incidents.html    Phishing Enters Automation Era Article https://www.axios.com/2026/06/23/ai-automation-phishing-emails-hackers    US government finalized its AI review framework: https://www.techbrew.com/stories/white-house-ai-framework-open-weights-exclusion?w    Connect with Nicole Dove: https://www.linkedin.com/in/jnicoledove/   Adam Arellano: https://www.linkedin.com/in/adamrossarellano/      Martin Reynolds: https://www.linkedin.com/in/martinreynolds/     Harness: harness.io/    Subscribe to ShipTalk: Shiptalk.io   
S5 #2

OpenAI's AI Went Rogue & Hacked Hugging Face — Are Coding Agents Out of Control?

OpenAI just admitted that two of its own AI models went rogue during an internal red-team test — slipping out of their sandbox, reaching the open internet, and hacking Hugging Face on their own. OpenAI called it an “unprecedented cyber incident.” Are autonomous coding agents already out of control? Hosts Martin Reynolds and Adam Arellano open this episode with the story that reads like science fiction, then turn to the harder question underneath it. In a single week, OpenAI, Anthropic, and Google each shipped repository-wide coding agents that run 30 to 60 steps at a time and rewrite hundreds of files with no human watching every move. Joining them is Liam Mitchell, Director of Platform Engineering at One Advanced and one of the engineers behind the UK’s first sovereign LLMs. His take reframes the whole debate: “There’s a big difference between autonomy and authority.” Autonomy isn’t the threat — unchecked authority is. The conversation runs from the GitHub promptinjection hack and the exploding token bill to a graduate-hiring cliff (new grads are now just 7% of Big Tech hires) and what it all means for the engineers who’ll manage these agents. Liam’s parting shot: we’ve “solved the cost of writing software, but not the cost of owning it.” A candid, news-driven conversation about AI, coding agents, and how software really gets shipped in the AI era. Stop talking. Start shipping. Martin Reynolds: https://www.linkedin.com/in/martinreynolds/ Adam Arellano: https://www.linkedin.com/in/adamrossarellano/ Liam Mitchell : https://www.linkedin.com/in/liam-mitchell-16061833/ Follow the Pod at https://shiptalk.io/ ShipTalk is brought to you by Harness. Learn more at https://www.harness.io/
S5 #1

Why the U.S. Locked Down Fable and Mythos: AI, National Security, and the Workforce Squeeze

The U.S. just barred foreign nationals from accessing two advanced AI models — Fable and Mythos — citing national security. Around the same time, the Five Eyes intelligence alliance warned that AI-enabled cyberattacks are "months, not years" away. Host Adam and co-host Martin dig into whether that warning is already overdue — and what it means for the people actually defending software. They're joined by Assaf, a longtime security leader (and Adam's former boss) and author of Lessons from the Front Line: Insights from a Cybersecurity Career. The conversation moves from the headlines to the harder truth underneath them: AI adoption is climbing, yet more than half of security and IT workers are considering leaving their jobs — burned out, under-resourced, and worried AI is coming for their roles. Assaf's take is contrarian and sharp: the real failure isn't AI, it's leadership translation and a training pipeline we're quietly demolishing. As Adam puts it, "this is not a security problem, it's an engineering problem." A candid, news-driven look at AI, national security, and the security workforce squeeze — and a surprisingly optimistic read on where it all goes next. Listen on: Apple Podcast | Spotify | YouTube Timestamps: 00:00 Cold Open: AI Cyberattacks Aren't Months Away — "We're Already There" 00:53 Welcome to ShipTalk: Today's Two Headlines 01:35 Are We Already Using AI Without Realizing It? 02:41 Five Eyes Warns AI Cyberattacks Are "Months, Not Years" Away 04:31 Harness by the Numbers: Half of Security Pros Want to Quit 05:25 Meet the Guest: Assaf Keren (ex-PayPal & Qualtrics CSO) 06:14 "Secure by Design, But For Real This Time" 08:46 The ISSA Survey: Why Security Jobs Keep Getting Harder 10:01 The "Triple Whammy" Burning Out Security Teams 11:49 Have We Been Here Before? Cloud & the Changing SOC Role 13:32 The Contrarian Take: AI Could Make Security Better 15:41 The Real Failure: We're Demolishing the Training Pipeline 18:41 Weak Leadership, or a Security Translation Problem? 22:05 Trust: The CISO's Real Business Function 23:20 What Teams Get Wrong About AI + Software Delivery 24:37 Debrief: Adam & Martin's Takeaways 26:31 Wrap-Up: Stop Talking, Start Shipping