Anthropic's Mythos 5 Created Fake GitHub Identities & the U.S. Government's New AI Review
Anthropic's Mythos 5 created fake GitHub identities to get malicious code approved. Cybersecurity advisor and author Nicole Dove joins ShipTalk to explain what this means for AI agent security, device code phishing, open-source software, and secure software delivery.
The episode breaks down the UK AI Security Institute incident involving Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol, plus Huntress’s reported 1,380% increase in device code phishing. Adam, Martin, and Nicole discuss why attackers are automating faster than defenders, why security culture matters as much as tooling, and why policies and frameworks are not enough without people and operational controls.
They also explore how AI can improve threat modeling, QA, vulnerability management, governance, and the full software delivery lifecycle—not just generate code faster.
IN THIS EPISODE:
- Fake identities and social engineering by AI agents
- Malicious code and open-source software security
- Device code phishing and AI-powered identity attacks
- Security culture, incident simulations, and awareness
- AI governance, accountability, and open-weight models
- Threat modeling, QA, vulnerability management, and controls
- Why coding faster is not the same as delivering software better
GUEST:
Nicole Dove is a cybersecurity advisor and the author of Learning Cybersecurity Fundamentals.
CHAPTERS:
00:00 Cold open: AI agents, phishing, and controls
00:46 The AI agent that created fake GitHub identities
04:32 Harness by the numbers
05:03 Device code phishing jumps 1,380%
06:08 Meet Nicole Dove
07:24 Attackers automated before defenders
09:19 Cybersecurity fundamentals still win
10:43 Security culture vs. security tooling
12:31 Simulating the pain of a breach
15:10 Building trust with engineering and the business
16:50 Why phishing exploits trusted brands
19:03 Continuous security learning
19:53 AI coding speed vs. secure software delivery
21:36 Government AI reviews and open-weight models
24:47 Policies do not protect you—controls do
27:00 PLTR discussion Palantir Technologies
27:25 Federal AI, Palantir, and old security assumptions
29:05 What teams get wrong about AI and software delivery
30:29 Final takeaways
SOURCES DISCUSSED:
UK AI Security Institute incident report: https://www.csoonline.com/article/4205612/openai-anthropic-ai-agents-resorted-to-deception-in-new-cybersecurity-incidents.html
Phishing Enters Automation Era Article https://www.axios.com/2026/06/23/ai-automation-phishing-emails-hackers
US government finalized its AI review framework: https://www.techbrew.com/stories/white-house-ai-framework-open-weights-exclusion
CONNECT:
Nicole Dove: https://www.linkedin.com/in/jnicoledove/
Adam Arellano: https://www.linkedin.com/in/adamrossarellano/
Martin Reynolds: https://www.linkedin.com/in/martinreynolds/
Harness: harness.io/
Subscribe to ShipTalk: Shiptalk.io
ShipTalk breaks down how software delivery is actually changing in the AI era.
#AISecurity #Cybersecurity #SoftwareDelivery