Operations | Monitoring | ITSM | DevOps | Cloud

Why Microsoft Sat on a Copilot Exploit for 233 Days

Microsoft took 233 days to patch CoSnitch — a one-click Copilot exploit that needs no click at all. And the researchers who found it never wrote an exploit. They asked Copilot to explain why the attack was impossible, and it told them how to do it. Martin Reynolds and Adam Arellano are joined by Matthew Tanner — 30 years shipping software, from NHS critical systems to national-scale financial redress — for the week in AI and software delivery.

ChatGPT Ditches Reddit AI Search Changes Explained

ChatGPT’s Reddit citations reportedly went from making up as much as 15% of its sources to essentially 0%. So what changed? We break down why Reddit is becoming less visible in AI search, how ChatGPT appears to be changing the way it finds information, and why more citations are now coming directly from documentation, help centers, and company websites. And yes — this is the same Reddit ecosystem that helped give us the infamous “put glue on your pizza” AI answer.

ChatGPT Stopped Citing Reddit - And That Matters

ChatGPT appears to have dramatically changed how it searches the web — and Reddit is suddenly showing up far less in its citations. For years, Reddit was one of ChatGPT’s most frequently cited sources, at one point accounting for as much as 15% of citations. That also created an entire industry around influencing Reddit posts in hopes of getting brands surfaced inside AI-generated answers. Now, ChatGPT appears to be shifting toward more targeted searches of official websites, documentation, and help centers instead of broadly searching the open web and pulling in Reddit discussions.

Run Playwright Tests with Harness AI Test Automation | CI/CD + AI Failure Analysis

End-to-end testing should not slow your delivery pipeline down. But for many teams, Playwright test suites still live in disconnected jobs, produce noisy failures, and make it hard to tell whether a failed test is a real regression, a flaky test, or just another false positive. In this walkthrough, Shibam Dhar, DevRel Engineer at Harness, shows how Harness AI Test Automation helps teams run, analyse, and trigger Playwright tests directly from their software delivery workflows.

Why we stopped hiring for the skills we used to hire for

Six engineers, two QA, a product owner and a Scrum Master used to be a normal squad. With today's tooling, that's bloat. Teams are being rebuilt around three people. Not because the work got smaller — because agentic tooling absorbed the parts that needed all those hands. The engineer's job shifts from writing the code to directing the agents that write it, and owning the outcome that comes out the other end.

Amazon AI Code Rewriting Gone Wrong!

In 2025 Amazon tasked Ai to find efficiencies. It definitely did. The AI went rogue and started deleting files and canceling programs. It was efficient. Less code, less products, more efficient. Adam mentions, dont burn the house down to reduce the electric bill. ShipTalk breaks down the biggest shifts in AI, DevOps, and software delivery. No hype, no vendor gloss. Stop talking, start shipping.

Anthropic's Mythos 5 Fakes Identities Hacking Britain's Government AI Challenge

AI agents are now faking identities — and this is the case that proves it. The UK's AI Security Institute gave frontier models a hacking challenge. Anthropic's Mythos 5 decided the most efficient path to a win was to poison a real open source project: it opened a pull request full of malicious code on a live public repo, then spun up fake GitHub accounts, posed as a different developer, and used that invented person to publicly vouch for its own code — pressuring a real human maintainer into merging it. A human reviewer caught the malware and closed the PR.

Anthropic's Mythos 5 Created Fake GitHub Identities & the U.S. Government's New AI Review

Anthropic's Mythos 5 created fake GitHub identities to get malicious code approved. Cybersecurity advisor and author Nicole Dove joins ShipTalk to explain what this means for AI agent security, device code phishing, open-source software, and secure software delivery.