Cameron Walters and Kurt Hendle
Coffee, Chaos and ProdSec
Coffee, Chaos & ProdSec is where cybersecurity meets caffeine-fueled chaos. Hosts Kurt (security architect and chaos tamer) and Cameron (ProdSec wrangler and DevSecOps junkie) dive into hacking, AppSec, supply chain failures, AI surprises, and the everyday madness of defending modern systems. With humor, sharp insight, real breach breakdowns, bad password confessions, and a few questionable impressions, they explore the messy reality of security and how teams survive it. New episodes Every Wednesday at 5 AM Eastern.
Author
Cameron Walters and Kurt Hendle
Category
Podcast website
Latest episode
Jul 8, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Ep 45 - Negative Days, AI Vuln Swarms, and Why Your Security Team Isn't Obsolete Yet 08.07.2026 1:00:49
🎙️ Coffee, Chaos and ProdSec , Ep 45 Vulnerability counts just went logarithmic. Companies are pooling money to buy patches before the public even hears about them. And somebody's still trying to convince you a ten person team running an agent swarm is coming for your job. This week Cameron and Kurt tear into the vulnerability management chaos AI kicked off in the last two months. Project Glas...
Ep 44 - AI Promised Value, Demo Passed, Production Called Its Bluff - The Proof Era 01.07.2026 1:00:19
🎙️ Coffee, Chaos and ProdSec , Ep 44 Your AI vendor has an amazing demo. Then it hits production and falls over. Then you're explaining to your CISO why the budget got torched in four months instead of twelve. This week Cameron and Kurt break down the proof era, the moment AI adoption stopped running on hype and started running on receipts. Uber burned a full year of AI budget by April and sti...
Ep 43 - Anthropic Said Fable 5 Was Too Dangerous Then Got Caught Lying 24.06.2026 57:43
🎙️ Coffee, Chaos and ProdSec , Ep 43 Anthropic spends months marketing Fable 5 as uniquely dangerous. The government believes them and shuts it down. Then Anthropic spends the next week explaining that actually, every other frontier model can do the same thing. This week Cameron and Kurt break down the Fable 5 and Mythos shutdown start to finish. The real timeline behind the export control directi...
Ep 42 - Identity Sprawl, VulnOps, and Nine Domains Later - Part 2 17.06.2026 59:40
🎙️ Coffee, Chaos and ProdSec , Ep 42 Five domains. One episode. No recaps for people who skipped Part 1. Cameron and Kurt close out the greenfield ProdSec build with Identity Security, Vulnerability Management, GRC, Product Security Incident Response, and AI Security. NHIs are outnumbering humans 40 to 1 and 78% of organizations have no formal policy for creating or removing AI identities. That is...
Ep 41 - No Budget, No Blueprint, No Lies - Building ProdSec From Scratch - Part 1 10.06.2026 1:08:20
🎙️ Coffee, Chaos and ProdSec , Ep 41 DevSecOps is dead. Cameron said it. Kurt didn't fully disagree. And that's just the first five minutes. This week Cameron and Kurt kick off a two-part series on building a ProdSec program from scratch, no inherited tool sprawl, no political debt, just a greenfield mandate and nine domains to figure out. But before the org chart gets drawn, they set the...
Ep 40 - GitHub Breach, Open Source Malware, Dev Machine Gold Mines ft. Paul McCarty and Jenn Gile 03.06.2026 1:04:53
🎙️ Coffee, Chaos and ProdSec , Ep 40 Less than 5% of CVEs are actually exploitable. One hundred percent of malicious packages are bad by design. So why is your entire AppSec budget chasing the first problem? This week Cameron and Kurt bring on Paul McCarty and Jenn Gile, co-founders of OpenSourceMalware, to break down why the open source malware problem is structurally different from vulnerability...
Ep 39 - Governing AI Agents and NHIs - Identity Is the Control Plane Full Stop 27.05.2026 1:01:20
🎙️ Coffee, Chaos and ProdSec , Ep 39 AI agents are in production. They have access. They're taking actions. And almost none of them have an owner. This week Cameron and Kurt come off a multi-day identity summit with a take they're both confident in: the industry is reaching for gateways, firewalls, and legacy IGA platforms to solve an AI security problem that is fundamentally an identity p...
Ep 38 - Governance Without Enforcement Is Theater and Shadow AI Knows It 20.05.2026 1:01:04
🎙️ Coffee, Chaos and ProdSec , Ep 38 Your org told everyone to use AI. The budget ran out. Someone found a better free tool. Boom, shadow AI just happened. This week Cameron and Kurt record on four hours of sleep fresh off two days in Austin talking AI and identity with practitioners, and somehow that makes this episode better. They get into where shadow AI actually lives across the corporate surf...
Ep 37 - Scattered Spider Called Your Help Desk and Your TPRM Annual Review Missed It 13.05.2026 56:53
🎙️ Coffee, Chaos and ProdSec , Ep 37 Your vendor filled out the questionnaire. They have a SOC 2. And they just got you popped. This week Cameron and Kurt get into the third-party risk management conversation that the industry keeps avoiding. Not the checkbox version, the one where Scattered Spider is social engineering your managed service provider's help desk and you're finding out about...
Ep 36 - Stop Blaming Mythos - The Defender Playbook Was Already Overdue 06.05.2026 1:01:50
🎙️ Coffee, Chaos and ProdSec, Ep 36 Your risk model is lying to you. Not maliciously. Just quietly, using assumptions that stopped being accurate before Mythos ever made the news. This week Cameron and Kurt get into the part nobody wants to say out loud: the AI threat acceleration has been building for over a year and most Application Security and Product Security programs are still running the ol...
Ep 35 - Mythos, the AI Exploit Printer, and Whether Security Is Actually Cooked ft. Caroline Wong 29.04.2026 59:41
🎙️ Coffee, Chaos and ProdSec , Ep 35 Anthropic dropped Mythos. 250 CISOs argued in a live document over a weekend. A crisis paper shipped Monday morning. And everyone's board started calling. This week Cameron , Kurt , and Caroline Wong get into what Mythos actually did differently from every model before it, whether Project Glasswing is coordinated disclosure or the most expensive press relea...
Ep 34 - SPVS 1.5 Is Live: AI Pipeline Security Controls ft. Farshad Abasi 22.04.2026 57:51
🎙️ Coffee, Chaos and ProdSec , Ep 34 AI is already in your pipeline. Your agents are making decisions. And most teams have no controls governing any of it. This week Cameron , Kurt , and returning guest Farshad Abasi crack open SPVS 1.5, the OWASP Secure Pipeline Verification Standard community feedback release that ships 132 AI and agentic pipeline security controls across 31 subcategories. From...
Ep 33 - Six OWASP AI Top 10s, Sixty Risks, Two Practitioners, One Consolidated List 15.04.2026 1:07:20
🎙️ Coffee, Chaos and ProdSec , Ep 33 OWASP published six AI security Top 10s in roughly two years. Six. That is not a framework strategy, that is a distress signal. This week Kurt and Cameron tear through all of them. LLM security, agentic applications, MCP, agentic skills, machine learning security, and the honorary sixth because AI agents have an identity problem and NHIs deserve a seat at the t...
Ep 32 - Password Resets, Dev Laptop Secrets, and the NHI Mess Nobody Wants to Own 08.04.2026 1:01:40
🎙️ Coffee, Chaos and ProdSec , Ep 32 Your org is still forcing 90-day password resets. NIST said stop years ago. Nobody wants to be the one who changes it. This week Cameron and Kurt get into three trust assumptions enterprise security programs are still running on in 2026 that nobody actually validated. Mandatory rotation that creates predictable mutations instead of stronger passwords, developer...
Ep 31 - OSS Malware, TeamPCP, and the Supply Chain Is Not a Solved Problem ft. Jenn Gile 01.04.2026 1:08:47
🎙️ Coffee, Chaos and ProdSec , Ep 31 Open source malware is not a harder version of CVE management. It is a completely different problem, and most orgs are running the wrong playbook. This week Cameron and Kurt are joined by Jenn Gile , co-founder of OpenSourceMalware.com and advisor at Endor Labs, and she comes prepared to take everyone to school. They dig into how attacks like TeamPCP actually w...
Ep 30 - ProdSec Buys the Tools, Vendors Cash the Checks, Coffee Fuels the Rage 25.03.2026 1:01:30
🎙️ Coffee, Chaos and ProdSec , Ep 30 Your security stack has too many tools. Your vendors swear everything works. And somehow nothing actually does. This week Cameron and Kurt get into the vendor fatigue problem that most ProdSec and Application Security teams are living with but nobody wants to say out loud. Overlapping tools, compounding pricing, AI addons bolted on at renewal, and alert noise s...
Ep 29 - AI, AppSec, and the Security Industry Reckoning ft. Absolute AppSec 18.03.2026 1:05:46
🎙️ Coffee, Chaos and ProdSec , Ep 29 The AppSec industry is having a moment, and not the good kind. So this week, Cameron and Kurt bring in Seth Law and Ken Johnson from the Absolute AppSec podcast to ask the questions most security teams are still avoiding. Is AppSec dead or just getting a new job title nobody's written yet? Is your AI policy a real security control or just legal cover? And w...
Ep 28 - What Are We Working On, What Can Go Wrong: A Threat Modeling Wake Up Call 11.03.2026 1:00:21
🎙️ Coffee, Chaos and ProdSec , Ep 28 Threat modeling has been around for 30 years. It shows up in every security framework. And most teams are still doing it wrong, too late, or not at all. So this week, Cameron and Kurt get into it. What threat modeling actually is, why the CI/CD pipeline is almost never in scope, and why a finding with no owner is not a mitigation. They cover the framework lands...
Ep 27 - Claude Code Security, The $152 Vuln, and the AppSec Reckoning Nobody Is Ready For 04.03.2026 1:14:08
🎙️ Coffee, Chaos and ProdSec, Ep 27 Anthropic dropped Claude Code Security and wiped $10 billion off cybersecurity stocks in a single afternoon. Some of that panic was justified. Most of it wasn't. This week Kurt, Cameron, and special guest Blake Beus, a software engineer turned AppSec dark sith lord, dig into what actually changed and what the industry is getting completely wrong about it. Th...
Ep 26 - The CISO Hot Seat - Trust, Survival, and What Nobody Says Out Loud 25.02.2026 1:02:15
🎙️ Coffee, Chaos and ProdSec, Ep 26 We put a CISO in the hot seat and told him no corporate answers allowed. This week Kurt and Cameron sit down with Billy Spears, a seasoned cybersecurity leader who has served in CISO, CIO, and CTO roles across public companies and national security environments. Billy came ready to be honest about what the role actually looks like when the dashboards are up at m...
Ep 25 - Stop Saying No, Start Proving Value, and Stop Letting AI Wreck Your Roadmap 18.02.2026 1:08:14
🎙️ Coffee, Chaos and ProdSec, Ep 25 Your roadmap looked great in January. It is February and AI just rewrote half of it for you. This week, Kurt and Cameron bring Chelise and Caroline Wong to the table for a four person roundtable on cybersecurity leadership and the messy reality of running a security program. They dig into why security teams keep getting called the Department of No, how AI is for...
Ep 24 - AI Security Reality Check, When Agents Ship Faster Than Policies 11.02.2026 59:33
🎙️ Coffee, Chaos and ProdSec, Ep 24 AI security is already happening in production, and most teams are governing systems after they're live, not during design. So this week, Kurt and Cameron sit down with special guest Tarak, a Co-Founder, Cloud Platform Builder, and Cyber AI Agents Architect, to break down what happens when AI agents ship faster than security policies can keep up. From shadow...
Ep 23 - Part 2 - AI Security Incident Response, Supply Chain Chaos, AI Training and the Compliance Wake Up Call 04.02.2026 57:02
🎙️ Coffee, Chaos and ProdSec, Ep 23 AI security keeps getting talked about, but incident response, supply chain risk, and people are still treated like someone else’s problem. So this week, Kurt and Cameron grab their mugs and spend the episode walking through what actually happens when AI systems misbehave, agents start acting outside expectations, and traditional security playbooks stop lining u...
Ep 22 - Part 1 - AI Security Foundations, Visibility, Governance, and the Risks Nobody Owns 28.01.2026 59:50
🎙️ Coffee, Chaos and ProdSec, Ep 22 AI is already inside your environment, whether you planned for it or not. So this week, Kurt and Cameron grab their mugs and talk through the AI security foundations that tend to break first, long before anyone calls it an incident. From gaining visibility into shadow AI and hidden agents, to setting up governance that does not drive usage underground, to buildi...
Ep 21 - Hoodies & Handshakes - The Human Side of Cybersecurity 21.01.2026 57:08
🎙️ Coffee, Chaos and ProdSec, Ep 21 Security teams love tools and checklists, but most failures start with people, pressure, and messy handoffs. So this week, Kurt and Cameron grab their mugs and break down what certifications do not teach, how human risk shows up in real incidents, and why security only works when it becomes a team sport. From rushed approvals and blurry ownership, to vulnerabili...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.