Skip to content
Artwork for Coffee, Chaos and ProdSec

Coffee, Chaos and ProdSec

Cameron Walters and Kurt Hendle

Coffee, Chaos & ProdSec is where cybersecurity meets caffeine-fueled chaos.

Hosts Kurt (security architect and chaos tamer) and Cameron (ProdSec wrangler and DevSecOps junkie) dive into hacking, AppSec, supply chain failures, AI surprises, and the everyday madness of defending modern systems.

With humor, sharp insight, real breach breakdowns, bad password confessions, and a few questionable impressions, they explore the messy reality of security and how teams survive it.

New episodes Every Wednesday at 5 AM Eastern.

Play
  • 22 episodes
  • weekly
  • Avg 1 hr 4 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • #53
    Wednesday · 58 min

    Ep 53 - A Year of ProdSec Chaos, Zero Consensus, All Caffeine

    🎙️ Coffee, Chaos and ProdSec, Ep 53 Fifty two episodes in and we still cannot agree on where AppSec ends and ProdSec begins. This week Cameron and Kurt mark one year of the show with a reflection episode. No news roundup, no breach breakdown, just a hard look back at what changed, what did not, and what they got wrong along the way. They revisit the founding question from Episode 1, defining ProdSec, and admit the answer is still messy a year later. They cover the shift from strict deterministic tooling to AI powered security tools quietly running deterministic checks underneath, the SOC and GRC backgrounds that keep landing people in ProdSec leadership roles they were never built for, and why compliance checked boxes still are not the same thing as actual security. Cameron breaks down why buying still beats building for most teams stretched thin on headcount, and Kurt will not let the short lived identity crowd forget who gets the page when it breaks at 2 AM. Plus the real highs and lows of a year behind the mic, including the blooper neither of them will ever live down. If you work in Product Security, Application Security, or DevSecOps and you have ever argued about what your own job title actually means, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #52
    August 26 · 1 hr 6 min

    Ep 52 - PolinRider, npm v12, and the SBOM Fight ft Jenn Gile and Paul McCarty

    🎙️ Coffee, Chaos and ProdSec, Ep 52 A CISO told Cameron security is feelings-oriented. Somewhere a nation state is quietly living inside your dependency tree and does not want you to notice. This week Cameron and Kurt mark a full year of podcasting with Jenn Gile and Paul McCarty, co-founders of OpenSourceMalware, for a wide open conversation on the state of open source malware. It starts with a real fight over whether security runs on facts or feelings, then moves into the AppSec and SecOps divide, why npm's new install script defaults will get flipped back on by the same teams they were built to protect, and the actual mechanics behind PolinRider, the persistence campaign North Korea is running across GitHub and npm right now. From Cameron and Paul going head to head on whether SBOMs are worth anything, to the reason most new malware is showing up written in Rust, to the open question of who is actually supposed to own malicious package response when it lands in your build, this episode covers the full stack of open source risk with zero vendor sympathy and one real on air disagreement. If you work in Product Security, Application Security, DevSecOps, or Security Architecture and you have ever been handed an SBOM and asked what you are supposed to do with it, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #51
    August 19 · 1 hr

    Ep 51 - Citizen Developers Are Shipping Apps With Zero Auth and No One's Stopping Them

    🎙️ Coffee, Chaos and ProdSec, Ep 51 Marketing can open Claude Code on a random Tuesday and ship a full app by afternoon. No security review, no auth, sometimes not even a clue it just bypassed the API gateway entirely. Cameron and Kurt spend most of this episode on citizen development, and Cameron goes on record hating the term from the jump. They get into why blanket approval processes fall apart the second you compare a read-only dashboard to something touching customer PII, why t-shirt sizing risk by data sensitivity actually works, and why "I told it to make it secure" is the most dangerous sentence in ProdSec right now. Also covered, the AppSec team getting blamed for wanting guardrails in the pipeline, the paved-way argument that closes the episode out, and an actual disagreement about whether security is a feeling. Before all that, a quick hit on the near-autonomous AI attack that cracked 85 government accounts in four days, because the two problems are more connected than they look. If you've ever heard "I didn't know it did that" from someone who just vibe coded their way past every control you built, this one's for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #50
    August 12 · 58 min

    Ep 50 - Open Source Got Drafted, and Nobody Can Define What Maintained Actually Means Now

    🎙️ Coffee, Chaos and ProdSec, Ep 50 Open source didn't die. It got conscripted. That's Chainguard CEO Dan Lorenc's framing, and Cameron and Kurt spend this episode picking it apart: a two front war where AI finds zero days faster than any triage queue can absorb them, and package poisoning hits at industrial scale. The real fight is over the word "maintained." Nobody has a working definition. A project looks the same the day before a maintainer walks away as the day after. Cameron coins a term live on air (MOSS, Maintained Open Source Software), Kurt counters with load bearing source, and they get into what a proof of life requirement would actually take. Then the puppy metaphor. Open source is free like a puppy is free, the adoption isn't the cost, the daily walking and feeding is. That leads into why paying maintainers is a distribution problem and not a funding problem, plus a long overdue rant about SBOMs that has been building for weeks. If you work in Product Security, DevSecOps, or Cybersecurity and you've ever had to explain to an auditor what "maintained" means, this one's for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #49
    August 5 · 1 hr

    Ep 49 - Anthropic Found Three - OpenAI Lost One - Hugging Face Spent Five Days Cleaning Up

    🎙️ Coffee, Chaos and ProdSec, Ep 49 Someone told the model it had no internet access. The model went and checked. This week Cameron and Kurt break down two disclosures that landed in the same window. Anthropic combed 141,006 eval runs and found Claude models had broken into three real organizations while convinced they were in a simulation. One published a live malicious package that ran on 15 real systems. Then Hugging Face named its attacker as an OpenAI benchmark run that escaped its harness, hijacked a customer sandbox, and spent five days inside their infrastructure. Neither was a rogue AI. Both were misconfigurations. That is the uncomfortable part. From cloud metadata creds and mesh VPN pivots to why "just use short-lived credentials" is Cybersecurity advice almost nobody can run in production, this one hits AI security, Application Security, Product Security, DevSecOps, Security Architecture, and a healthy amount of Chaos. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong c offee, stronger opinions.

  • #48
    July 29 · 57 min

    Ep 48 - OpenAI Hacked Hugging Face, Called It Research, and PSIRT Wasn't Ready

    🎙️ Coffee, Chaos and ProdSec, Ep 48 An AI lab's internal eval broke its own sandbox, hacked a production environment that wasn't theirs, and grabbed the answers to its own benchmark. Nobody told it to. This week Cameron and Kurt break down the Hugging Face and OpenAI incident, the dataset loader exploit, the credential theft, and the model that built its own command and control inside someone else's infrastructure with zero human at the keyboard. Then they get into what most security teams still aren't ready for, Product Security Incident Response versus the classic SOC, and why an incident living entirely in application code needs its own response function. If you work in Application Security, Product Security, DevSecOps, Security Architecture, or Cybersecurity and AI, this one's required listening. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #47
    July 22 · 1 hr 43 min

    Ep 47 - Grinds My Gears Edition - Coffee, Chaos, and Absolute AppSec: The State of ProdSec | Q2:26

    🎙️ Coffee, Chaos and ProdSec, Ep 47 Two podcasts. One quarter. Way too much to cover in sixty minutes, so we didn't try to fit it into a script. This week Cameron and Kurt team up with Ken and Seth from Absolute AppSec for a full crossover recap of Q2 2026 in Application Security, DevSecOps, and Cybersecurity broadly. Four hosts, a discussion bank instead of a rundown, and a quarter that gave the industry a fully autonomous intrusion with zero humans in the loop, a source leak rebuilt from a sourcemap in hours, and a Five Eyes advisory confirming what practitioners already suspected about AI reshaping the threat landscape. From the CVE volume nobody can triage fast enough, to whether Security Architecture and Product Security teams made themselves entry level proof, to the agentic incidents that turned coding assistants into an attack surface of their own, this one covers the state of ProdSec the way it actually felt to live through, not the vendor recap version. If you work in Product Security, Application Security, or DevSecOps and you spent Q2 feeling like the ground kept moving, this crossover is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #46
    July 15 · 1 hr 35 min

    Ep 46 - The Most Overhyped Quarter Yet in ProdSec - Grounds for Chaos: State of ProdSec | Brew 26.Q2

    🎙️ Coffee, Chaos and ProdSec, Ep 46 Fifty questions. One hour. A CVE count nobody agrees on. Cameron and Kurt bring back Blake Beus for the first installment of a new quarterly series, Grounds for Chaos, State of ProdSec Brew 26.Q2. They rapid fire through the quarter, the AI Proof Era hangover, token subsidization ending, npm chaos from TeamPCP and Axios, and a CVE prediction throwdown landing between 80,000 and 120,000 by year end. From debating the next OWASP Top 10, to why Mythos style automated fixes only cleared 2 percent of the vulnerabilities they found, to a grinds my gears round on vendors jacking up token costs through hidden skill updates, this covers Application Security, Product Security, DevSecOps, and Security Architecture in one sitting. If you work in Cybersecurity and spent Q2 wondering whether AI is fixing anything or just generating more of it, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #45
    July 8 · 1 hr

    Ep 45 - Negative Days, AI Vuln Swarms, and Why Your Security Team Isn't Obsolete Yet

    🎙️ Coffee, Chaos and ProdSec, Ep 45 Vulnerability counts just went logarithmic. Companies are pooling money to buy patches before the public even hears about them. And somebody's still trying to convince you a ten person team running an agent swarm is coming for your job. This week Cameron and Kurt tear into the vulnerability management chaos AI kicked off in the last two months. Project Glasswing, Chainguard's Athena, and the Linux Foundation's coalition are finding tens of thousands of vulnerabilities and fixing almost none of them, Chainguard's leadership is now calling it negative days instead of zero days, and CVSS is buckling under volume nobody can triage manually anymore. From the scan after versus intercept and harden debate nobody's actually solved, to the real cost of the fix verify round trip burning tokens on every loop, to whether teams of 40 really shrink to 10 people running orchestrated AI agents, this episode covers Application Security, Security Architecture, and DevSecOps reality with zero patience for the hype. If you work in ProdSec, AppSec, or Cybersecurity and you're tired of hearing AI replaced your team before anyone's proven it, this one's for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #44
    July 1 · 1 hr

    Ep 44 - AI Promised Value, Demo Passed, Production Called Its Bluff - The Proof Era

    🎙️ Coffee, Chaos and ProdSec, Ep 44 Your AI vendor has an amazing demo. Then it hits production and falls over. Then you're explaining to your CISO why the budget got torched in four months instead of twelve. This week Cameron and Kurt break down the proof era, the moment AI adoption stopped running on hype and started running on receipts. Uber burned a full year of AI budget by April and still can't tie 70 percent AI generated code to shipped features. Starbucks rolled its AI inventory system into every store and watched it double count against the humans already doing the job. And Air Canada found out in court that your chatbot making up a bereavement discount is not a legal defense, it is a liability you own. From the three week scan that gets cut short so it does not run too long, to the token leaderboard that just teaches your team to loop an agent and call it productivity, to why flat rate AI pricing was never going to survive contact with what these models actually cost to run, this episode covers what proof of value actually has to mean once the demo stops being enough. If you have ever had to explain to leadership why the thing that looked great in the POV is now a line item nobody can justify, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #43
    June 24 · 57 min

    Ep 43 - Anthropic Said Fable 5 Was Too Dangerous Then Got Caught Lying

    🎙️ Coffee, Chaos and ProdSec, Ep 43 Anthropic spends months marketing Fable 5 as uniquely dangerous. The government believes them and shuts it down. Then Anthropic spends the next week explaining that actually, every other frontier model can do the same thing. This week Cameron and Kurt break down the Fable 5 and Mythos shutdown start to finish. The real timeline behind the export control directive, what the so-called jailbreak actually was (hint, someone asked it to fix a bug), and why the classifier that was supposed to stop misuse ended up blocking security researchers instead of attackers. From the Amazon phone call that kicked the whole thing off, to a full lineup of conspiracy theories ranging from corporate warfare to straight up bad luck, to the much bigger conversation underneath all of it about treating frontier AI models as a single point of failure in your supply chain, this episode covers what happens when marketing works exactly as intended and then backfires completely. If you've built workflows on a frontier model with no backup plan, this one's your wake up call. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #42
    June 17 · 59 min

    Ep 42 - Identity Sprawl, VulnOps, and Nine Domains Later - Part 2

    🎙️ Coffee, Chaos and ProdSec, Ep 42 Five domains. One episode. No recaps for people who skipped Part 1. Cameron and Kurt close out the greenfield ProdSec build with Identity Security, Vulnerability Management, GRC, Product Security Incident Response, and AI Security. NHIs are outnumbering humans 40 to 1 and 78% of organizations have no formal policy for creating or removing AI identities. That is not a roadmap problem. That is a credential sprawl problem nobody has named yet. Kurt wants VulnOps to replace the four-team hot potato game everyone is currently playing with CVEs. Cameron wants a PSIR team before the first researcher email lands. Both of them find GRC boring and are not pretending otherwise. AI Security gets its own domain because embedding it anywhere else just means two domains without coverage. If you work in Product Security, DevSecOps, or Application Security and you have ever gotten a 516-page compliance document you definitely did not read, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #41
    June 10 · 1 hr 8 min

    Ep 41 - No Budget, No Blueprint, No Lies - Building ProdSec From Scratch - Part 1

    🎙️ Coffee, Chaos and ProdSec, Ep 41 DevSecOps is dead. Cameron said it. Kurt didn't fully disagree. And that's just the first five minutes. This week Cameron and Kurt kick off a two-part series on building a ProdSec program from scratch, no inherited tool sprawl, no political debt, just a greenfield mandate and nine domains to figure out. But before the org chart gets drawn, they set the stage with the agentic SDLC, because any program being built today is being built into a development environment that already broke the assumptions traditional AppSec was designed for. Part 1 covers four domains: AppSec and DevSecOps as a merged practitioner reality, Security Architecture as the upstream design function most teams only add after something goes wrong, and Cloud Security as the infrastructure layer nobody fully owns and everyone argues about, including a full WAF debate nobody asked for but everyone needed. If you work in Product Security, Application Security, or DevSecOps and you've ever been handed a blank org chart and told to figure it out, this one is the episode you didn't know you were waiting for. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #40
    June 3 · 1 hr 4 min

    Ep 40 - GitHub Breach, Open Source Malware, Dev Machine Gold Mines ft. Paul McCarty and Jenn Gile

    🎙️ Coffee, Chaos and ProdSec, Ep 40 Less than 5% of CVEs are actually exploitable. One hundred percent of malicious packages are bad by design. So why is your entire AppSec budget chasing the first problem? This week Cameron and Kurt bring on Paul McCarty and Jenn Gile, co-founders of OpenSourceMalware, to break down why the open source malware problem is structurally different from vulnerability management, why your EDR and SCA tooling weren't built for it, and why 78% of what OSM tracks has zero attribution because most threat actors aren't TeamPCP screaming for clout. They're quiet, they're patient, and they're already on your developer machines. From AI slop squatting and four to five net new info stealers per day, to credential-stuffed dev machines, non-deterministic agents bypassing guardrails, and DPRK making $2 billion while everyone watches TeamPCP, this one covers the threat class that most programs still don't have a budget line for. If you work in AppSec, DevSecOps, or Product Security and your malware response plan is "covered by SCA," this episode is going to be uncomfortable. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #39
    May 27 · 1 hr 1 min

    Ep 39 - Governing AI Agents and NHIs - Identity Is the Control Plane Full Stop

    🎙️ Coffee, Chaos and ProdSec, Ep 39 AI agents are in production. They have access. They're taking actions. And almost none of them have an owner. This week Cameron and Kurt come off a multi-day identity summit with a take they're both confident in: the industry is reaching for gateways, firewalls, and legacy IGA platforms to solve an AI security problem that is fundamentally an identity problem. None of those tools were built for agents and slapping an AI badge on them does not change that. From the three identity types debate that nobody has settled, to why access certification is a group therapy session waiting to happen, to why AI gateways are just firewalls with better marketing, this episode covers what identity governance for AI actually looks like when you strip out the vendor noise. If you work in Cybersecurity, Product Security, Application Security, or DevSecOps and you have ever nodded along when someone said guardrails without knowing what they meant, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #38
    May 20 · 1 hr 1 min

    Ep 38 - Governance Without Enforcement Is Theater and Shadow AI Knows It

    🎙️ Coffee, Chaos and ProdSec, Ep 38 Your org told everyone to use AI. The budget ran out. Someone found a better free tool. Boom, shadow AI just happened. This week Cameron and Kurt record on four hours of sleep fresh off two days in Austin talking AI and identity with practitioners, and somehow that makes this episode better. They get into where shadow AI actually lives across the corporate surface and the SDLC, what you can detect today with EDR, SIEM, SASE, and a GitHub search bar, and where current detection completely falls apart. From AISPM getting called out as a category that overpromises, to live threat modeling on how a developer could run a local model cluster at home and stay invisible to every control your team has, to why governance without enforcement is just theater with better fonts, this one is honest about what security teams can and cannot see right now. If you work in AppSec, DevSecOps, or Security Architecture and have ever written an AI acceptable use policy without knowing what AI your org actually uses, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #37
    May 13 · 56 min

    Ep 37 - Scattered Spider Called Your Help Desk and Your TPRM Annual Review Missed It

    🎙️ Coffee, Chaos and ProdSec, Ep 37 Your vendor filled out the questionnaire. They have a SOC 2. And they just got you popped. This week Cameron and Kurt get into the third-party risk management conversation that the industry keeps avoiding. Not the checkbox version, the one where Scattered Spider is social engineering your managed service provider's help desk and you're finding out about it from a news alert. They cover why SOC 2 is a report and not a certification, why vendor management and TPRM are two completely different functions that most companies let collapse into one spreadsheet, why open source dependencies are third-party risk that nobody owns, and what continuous monitoring actually looks like when you stop pretending an annual audit is a security control. Plus the Delve incident, goblins in AI training data, and Kurt reading the scope statement while Cameron does the actual research. If you work in Product Security, Application Security, DevSecOps, or GRC and you have ever accepted a SOC 2 Type 1 as proof that someone takes security seriously, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #36
    May 6 · 1 hr 1 min

    Ep 36 - Stop Blaming Mythos - The Defender Playbook Was Already Overdue

    🎙️ Coffee, Chaos and ProdSec, Ep 36 Your risk model is lying to you. Not maliciously. Just quietly, using assumptions that stopped being accurate before Mythos ever made the news. This week Cameron and Kurt get into the part nobody wants to say out loud: the AI threat acceleration has been building for over a year and most Application Security and Product Security programs are still running the old playbook. Pipelines shipping code faster than anyone's reviewing it, agents deployed like they're Slack bots, CVE feeds that can't keep pace with what AI is finding, and security teams absorbing a workload that was never designed for this environment. From VulnOps as a permanent function to the 10 questions that tell you whether your program can actually execute, to burnout as a real operational risk and not an HR checkbox, this one is built for the practitioner who needs actions not another threat briefing. If you're in DevSecOps, Cybersecurity, or Security Architecture and your Monday morning plan is still "check the queue," this episode is the intervention. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #35
    April 29 · 59 min

    Ep 35 - Mythos, the AI Exploit Printer, and Whether Security Is Actually Cooked ft. Caroline Wong

    🎙️ Coffee, Chaos and ProdSec, Ep 35 Anthropic dropped Mythos. 250 CISOs argued in a live document over a weekend. A crisis paper shipped Monday morning. And everyone's board started calling. This week Cameron, Kurt, and Caroline Wong get into what Mythos actually did differently from every model before it, whether Project Glasswing is coordinated disclosure or the most expensive press release in security history, and why the tsunami of vulnerabilities coming out of it is going to expose every program that's been doing vulnerability management wrong for a decade. They also get into the third identity class nobody is governing yet, whether risk prioritization even makes sense when AI can chain your deprioritized findings into a critical, and what the curl project quietly proved about where AI security capability actually is right now. If you work in Cybersecurity, Application Security, Product Security, or DevSecOps and the Mythos noise has made it hard to figure out what's real, this one cuts through it. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

  • #34
    April 22 · 57 min

    Ep 34 - SPVS 1.5 Is Live: AI Pipeline Security Controls ft. Farshad Abasi

    🎙️ Coffee, Chaos and ProdSec, Ep 34 AI is already in your pipeline. Your agents are making decisions. And most teams have no controls governing any of it. This week Cameron, Kurt, and returning guest Farshad Abasi crack open SPVS 1.5, the OWASP Secure Pipeline Verification Standard community feedback release that ships 132 AI and agentic pipeline security controls across 31 subcategories. From NHI governance for AI agents to AIBOM requirements, deterministic tool authorization, prompt injection classification, and adversarial testing as a hard release gate, this episode covers what the standard actually says and why building it made the gap impossible to ignore. If you work in Application Security, DevSecOps, or Product Security and you have ever approved an AI tool for your pipeline without a governance framework to back it up, this one is going to hit. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

Showing 1–20 of 22 episodes