Cameron Walters and Kurt Hendle

Coffee, Chaos and ProdSec

Coffee, Chaos & ProdSec is where cybersecurity meets caffeine-fueled chaos. Hosts Kurt (security architect and chaos tamer) and Cameron (ProdSec wrangler and DevSecOps junkie) dive into hacking, AppSec, supply chain failures, AI surprises, and the everyday madness of defending modern systems. With humor, sharp insight, real breach breakdowns, bad password confessions, and a few questionable impressions, they explore the messy reality of security and how teams survive it. New episodes Every Wednesday at 5 AM Eastern.

Author

Cameron Walters and Kurt Hendle

Category

Technology

Podcast website

podcasters.spotify.com

Latest episode

Jul 8, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Ep 20 - API Security - Shadows, Zombies, and Other APIs We Pretend Don't Exist 14.01.2026

🎙️ Coffee, Chaos and ProdSec Ep 20 APIs are the backbone of modern apps, and attackers know it. This week, Kurt and Cameron break down the API security mess with stories from the trenches, practical fixes, and a few "how is this still happening" moments that'll make you check your own endpoints. From unauthenticated APIs sitting wide open to broken authorization bugs that let you cha...

Ep 19 - Cloud Security Chaos: When Identity, Kubernetes, APIs, and AI Collide 07.01.2026

🎙️ Coffee, Chaos and ProdSec, Ep 19 Cloud security keeps getting more complicated, but identity keeps getting ignored. So this week, Kurt and Cameron grab their coffee and dig into why identity failures are quietly powering most modern cloud incidents. From service accounts that never die, to Kubernetes clusters held together with cluster admin access and hope, to APIs nobody remembers exposing, t...

Ep 18 - Brace Yourself for 2026: AI-Powered Mayhem and Coffee-Fueled Product Security Predictions 31.12.2025

🎙️ Coffee, Chaos and ProdSec, Ep 18 2026 is getting closer, and security is already acting weird. So this week, Kurt and Cameron grab their mugs and talk through what they see coming next for Product Security and the teams trying to keep up. From AI agents showing up in the SOC, AppSec, DevSecOps, and GRC, to supply chain risks getting deeper and harder to see, this episode walks through the trend...

Ep 17 - Breaking Into Product Security, AppSec, DevSecOps, and Cloud Security Without a Degree 24.12.2025

🎙️ Coffee, Chaos and ProdSec, Ep 17 Breaking into cybersecurity without a degree feels impossible, yet people do it every single day. So this week, Cameron and Kurt grab their mugs and get real about how career changers actually break into Product Security, Application Security, DevSecOps, and Cloud Security when their background looks nothing like tech. Your hosts dive into the honest truth behin...

Ep 16 - Part 2 - Get Comfortable Being Vulnerable: When AI, Risk, and Reality Collide in AppSec 17.12.2025

🎙️ Coffee, Chaos and ProdSec - Ep 16 Last week we mapped the problem — now we break the system. Kurt and Cameron return with part two of our vulnerability deep dive, tackling CVSS chaos, broken tooling, exploding CVE volume, and how AI is about to overwhelm traditional prioritization models. From exposure validation turning 15,000 findings into 300 actionable items, to ASPM finally giving Product...

Ep 15 - Part 1 - Get Comfortable Being Vulnerable: The Chaos Behind Every CVE and Every Risk 10.12.2025

🎙️ Coffee, Chaos and ProdSec - Ep 15 Vulnerabilities are piling up faster than teams can read the reports, and vulnerability management is buckling under the weight. So this week, Kurt and Cameron grab their mugs and dig into why modern VM feels impossible, why severity scores mislead everyone, and how reachability and exploitability matter far more than giant spreadsheets of “critical” issues. Fr...

Ep 14 - DevSecOps Without the Buzzwords - What It Really Takes to Build Secure Software 03.12.2025

🎙️ Coffee, Chaos and ProdSec - Ep 14 DevSecOps gets thrown around in cybersecurity more than any other term, but almost no one agrees on what it actually means. So this week, Kurt and Cameron pour fresh mugs and unpack the real practices behind modern Application Security, Product Security, DevSecOps, and Software Supply Chain Security without the marketing fluff. From threat modeling and architec...

Ep 13 - Untangling Cloud Security - Foundations, Failures, and What Teams Miss 26.11.2025

🎙️ Coffee, Chaos & ProdSec – Ep 13 This week, Cameron and Kurt tackle the questions everyone claims to understand but absolutely argues about in every cloud meeting. What is the cloud really? Why is identity suddenly the perimeter? And how did Kubernetes quietly become everyone’s new production environment? We break down the real concerns behind cloud sprawl, misconfigurations, and identity ch...

Ep 12 - OWASP Top 10:2025 RC1 Breakdown - The Vulnerabilities That Refuse To Die 19.11.2025

🎙️ Coffee, Chaos & ProdSec - Ep 12 The OWASP Top 10:2025 RC1 is here, and it is already causing chaos. So this week, Kurt and Cameron grab their mugs and break down every category with real world stories, honest takes, and a few spicy opinions on why some vulnerabilities just will not go away. From Broken Access Control dominating the charts again, to Misconfigurations that keep haunting cloud...

Ep 11 – Google vs FFmpeg - The Open Source Meltdown 18.11.2025

🎙️ Coffee, Chaos & ProdSec – Episode 11 This week, Kurt and Cameron break down the showdown between Google’s Big Sleep AI and the FFmpeg maintainers keeping the internet’s media backbone running for free. A tiny bug in a 1995 video codec sparked a big debate about responsibility, AI-driven vulnerability hunting, and the growing strain on open source volunteers. We get into: • Why FFmpeg pushed...

Ep 10 - From Chaos to Controls - The Story Behind OWASP SPVS 15.11.2025

🎙️ Coffee, Chaos & ProdSec – Ep 10 This week, Cameron and Kurt sit down with the co-founders of the OWASP Secure Pipeline Verification Standard to unpack the real story behind SPVS and why the industry desperately needed a pipeline-focused security standard. From the early days of chaotic DevSecOps practices and scattered controls, to the moment the community rallied behind a structured, presc...

Ep 09 - Secrets in the Code - How Leaked Keys Can Sink a Ship 11.11.2025

🎙️ Coffee, Chaos and ProdSec, Ep 9 Ever pushed an API key at 2 a.m. and hoped nobody noticed? In this episode, we dig into one of the most preventable but devastating security failures: secrets in code. From leaked AWS keys and OAuth tokens to misconfigured GitHub Actions, we explore how small oversights can open the door to massive breaches, and why this problem keeps growing every year. We break...

Ep 08 - Hack the Stack - Inside the Chaos of Pen Testing 11.11.2025

🎙️ Coffee, Chaos and ProdSec, Ep 8 What really happens when you “hack the stack”? In this episode, we pull back the curtain on the messy, brilliant world of penetration testing, from corporate networks and VPNs to APIs, CI/CD pipelines, and live production systems. We explain what pen testing actually is, why it’s often misunderstood, and how the best testers balance creativity, curiosity, and cha...

Ep 07 - Access (Out of) Control - Tales of Permissions Gone Wild 11.11.2025

🎙️ Coffee, Chaos and ProdSec, Ep 7 Who left the keys under the mat? In this episode, we unlock the chaos behind broken access control, from S3 buckets of doom to interns with production privileges. We share real-world stories of “everyone’s an admin,” zombie accounts, and permission creep that turned harmless systems into ticking time bombs. Then we dig into why this keeps happening: messy RBAC mo...

Ep 06 - The Break Down - So You Wanna Be a ProdSec Pro? 11.11.2025

🎙️ Coffee, Chaos and ProdSec, Ep 6 Thinking about breaking into Product Security? In this episode, we lay out the roadmap, how to start, what to learn, and how to thrive once you land the role. We share our own origin stories, the detours we took to get here, and the lessons we learned the hard way along the way. Then we dig into the skills that matter, from threat modeling and secure design to co...

Ep 05 - War Stories - The Most Interesting Attacks We’ve Witnessed 11.11.2025

🎙️ Coffee, Chaos and ProdSec, Ep 5 Where were you when Log4j hit? In this episode, we revisit some of the wildest moments in modern AppSec and ProdSec history, from dependency chaos and credential leaks to the late-night incidents that taught us the most. We talk through real (and an0nym1z3d) stories that shaped how we think about risk, response, and resilience. We break down what actually happene...

Ep 04 - Peering into the Crystal Ball - Trends Shaping the Future of ProdSec 11.11.2025

🎙️ Coffee, Chaos and ProdSec, Ep 4 What’s next for Product Security? In this episode, we dust off the crystal ball and predict how the next wave of technology will reshape the field. From zero-downtime patching and ephemeral secrets to “observability as security,” we explore what’s real progress and what’s pure hype. We dive into DevSecOps trends like AI-driven automation, ASPM, minimal container...

Ep 03 - The Gauntlet - Top Challenges in Production Security Today 11.11.2025

🎙️ Coffee, Chaos and ProdSec, Ep 3 Why is ProdSec so challenging? In this episode, we run through the real-world gauntlet of modern production security, scaling secrets management, securing ephemeral infrastructure, and keeping pace with relentless deployment cycles. We dig into why these problems persist and what’s finally starting to work. From cloud misconfigurations and pipeline sprawl to deve...

Ep 02 - Passion Projects - What Gets Us Fired Up About ProdSec 11.11.2025

🎙️ Coffee, Chaos and ProdSec, Ep 2 What keeps security folks up at night, and what gets us out of bed in the morning? In this episode, we get personal about the parts of ProdSec that inspire, frustrate, and challenge us most. From building secure-by-default pipelines to chasing the thrill of catching bugs before they bite, we share what fuels our obsession with protecting products at scale. We com...

Ep 01 - What the Heck is ProdSec Anyway? 11.11.2025

What even is Product Security? In this kickoff episode, we break down what makes ProdSec the connective tissue between AppSec, DevSecOps, and engineering. We unpack why it exists, how it differs from other security domains, and why every modern product team needs it, even if they don’t realize it yet. Then we explore what real-world ProdSec looks like: from securing build pipelines and reviewing c...

Ep 00 - Coffee, Chaos & ProdSec: A Caffeinated Dive into Cybersecurity Mayhem 11.11.2025

🎙️ Coffee, Chaos & ProdSec - Trailer Ever wish cybersecurity came with caffeine, chaos, and a few laughs? Welcome to Coffee, Chaos & ProdSec, where your hosts Kurt (security architect and chaos tamer) and Cameron (ProdSec wrangler and reformed script kiddie) brew up weekly conversations on the wild world of modern security. From real-world breaches to bad password confessions, the duo dive...

Listen to the Coffee, Chaos and ProdSec podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.