Coffee, Chaos and ProdSec
Coffee, Chaos & ProdSec is where cybersecurity meets caffeine-fueled chaos.Hosts Kurt (security architect and chaos tamer) and Cameron (ProdSec wrangler and DevSecOps junkie) dive into hacking, AppSec, supply chain failures, AI surprises, and the everyday madness of defending…
- Indexed episodes, last 90 days
- 10
- Latest publication
- Sep 9, 2026
- Audience
- Checking…
- Earliest in this view
- Jul 8, 2026
Latest episodes
Ep 54 - Zero Day, Zero Patience, Admin Tokens in Three Days Flat (opens the original)
Read excerpt
🎙️ Coffee, Chaos and ProdSec , Ep 54 An artifact registry handed out admin access to anyone who asked. A print server got popped before the vendor even knew it had a bug. And somehow the vulnerability management metric everyone still quotes doesn't mean what people think it means anymore. This week Cameron and Kurt tear through two back-to-back critical CVEs, a JFrog Artifactory auth bypass that went from patch to admin token minting in three days, and a PaperCut NG/MF chain that was already bei
Ep 53 - A Year of ProdSec Chaos, Zero Consensus, All Caffeine (opens the original)
Read excerpt
🎙️ Coffee, Chaos and ProdSec , Ep 53 Fifty two episodes in and we still cannot agree on where AppSec ends and ProdSec begins. This week Cameron and Kurt mark one year of the show with a reflection episode. No news roundup, no breach breakdown, just a hard look back at what changed, what did not, and what they got wrong along the way. They revisit the founding question from Episode 1, defining ProdSec, and admit the answer is still messy a year later. They cover the shift from strict deterministi
Ep 52 - PolinRider, npm v12, and the SBOM Fight ft Jenn Gile and Paul McCarty (opens the original)
Read excerpt
🎙️ Coffee, Chaos and ProdSec , Ep 52 A CISO told Cameron security is feelings-oriented. Somewhere a nation state is quietly living inside your dependency tree and does not want you to notice. This week Cameron and Kurt mark a full year of podcasting with Jenn Gile and Paul McCarty, co-founders of OpenSourceMalware, for a wide open conversation on the state of open source malware. It starts with a real fight over whether security runs on facts or feelings, then moves into the AppSec and SecOps di
Ep 51 - Citizen Developers Are Shipping Apps With Zero Auth and No One's Stopping Them (opens the original)
Read excerpt
🎙️ Coffee, Chaos and ProdSec , Ep 51 Marketing can open Claude Code on a random Tuesday and ship a full app by afternoon. No security review, no auth, sometimes not even a clue it just bypassed the API gateway entirely. Cameron and Kurt spend most of this episode on citizen development, and Cameron goes on record hating the term from the jump. They get into why blanket approval processes fall apart the second you compare a read-only dashboard to something touching customer PII, why t-shirt sizin
Ep 50 - Open Source Got Drafted, and Nobody Can Define What Maintained Actually Means Now (opens the original)
Read excerpt
🎙️ Coffee, Chaos and ProdSec , Ep 50 Open source didn't die. It got conscripted. That's Chainguard CEO Dan Lorenc's framing, and Cameron and Kurt spend this episode picking it apart: a two front war where AI finds zero days faster than any triage queue can absorb them, and package poisoning hits at industrial scale. The real fight is over the word "maintained." Nobody has a working definition. A project looks the same the day before a maintainer walks away as the day after. Cameron coins a term
Publishing over time
Last 90 days. Choose a month to open its work.
Recurring subjects
Named in the text we hold. One piece can cover several.
Audience
No verified audience measurement yet.
About this data
Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.
Identity or attribution wrong? Suggest a correction.