Skip to content
HeyJared

Coffee, Chaos and ProdSec

Coffee, Chaos & ProdSec is where cybersecurity meets caffeine-fueled chaos.Hosts Kurt (security architect and chaos tamer) and Cameron (ProdSec wrangler and DevSecOps junkie) dive into hacking, AppSec, supply chain failures, AI surprises, and the everyday madness of defending…

Podcast · By Cameron Walters & Kurt Hendle · English · Official site

Indexed episodes, last 90 days
10
Latest publication
Sep 9, 2026
Audience
Checking…
Earliest in this view
Jul 8, 2026

Latest episodes

  1. Episode · Sep 9, 2026

    Ep 54 - Zero Day, Zero Patience, Admin Tokens in Three Days Flat (opens the original)

    Episode notes

    Read excerpt

    🎙️ Coffee, Chaos and ProdSec , Ep 54 An artifact registry handed out admin access to anyone who asked. A print server got popped before the vendor even knew it had a bug. And somehow the vulnerability management metric everyone still quotes doesn't mean what people think it means anymore. This week Cameron and Kurt tear through two back-to-back critical CVEs, a JFrog Artifactory auth bypass that went from patch to admin token minting in three days, and a PaperCut NG/MF chain that was already bei

  2. Episode · Sep 2, 2026

    Ep 53 - A Year of ProdSec Chaos, Zero Consensus, All Caffeine (opens the original)

    Episode notes

    Read excerpt

    🎙️ Coffee, Chaos and ProdSec , Ep 53 Fifty two episodes in and we still cannot agree on where AppSec ends and ProdSec begins. This week Cameron and Kurt mark one year of the show with a reflection episode. No news roundup, no breach breakdown, just a hard look back at what changed, what did not, and what they got wrong along the way. They revisit the founding question from Episode 1, defining ProdSec, and admit the answer is still messy a year later. They cover the shift from strict deterministi

  3. Episode · Aug 26, 2026

    Ep 52 - PolinRider, npm v12, and the SBOM Fight ft Jenn Gile and Paul McCarty (opens the original)

    Episode notes

    Read excerpt

    🎙️ Coffee, Chaos and ProdSec , Ep 52 A CISO told Cameron security is feelings-oriented. Somewhere a nation state is quietly living inside your dependency tree and does not want you to notice. This week Cameron and Kurt mark a full year of podcasting with Jenn Gile and Paul McCarty, co-founders of OpenSourceMalware, for a wide open conversation on the state of open source malware. It starts with a real fight over whether security runs on facts or feelings, then moves into the AppSec and SecOps di

  4. Episode · Aug 19, 2026

    Ep 51 - Citizen Developers Are Shipping Apps With Zero Auth and No One's Stopping Them (opens the original)

    Episode notes

    Read excerpt

    🎙️ Coffee, Chaos and ProdSec , Ep 51 Marketing can open Claude Code on a random Tuesday and ship a full app by afternoon. No security review, no auth, sometimes not even a clue it just bypassed the API gateway entirely. Cameron and Kurt spend most of this episode on citizen development, and Cameron goes on record hating the term from the jump. They get into why blanket approval processes fall apart the second you compare a read-only dashboard to something touching customer PII, why t-shirt sizin

  5. Episode · Aug 12, 2026

    Ep 50 - Open Source Got Drafted, and Nobody Can Define What Maintained Actually Means Now (opens the original)

    Episode notes

    Read excerpt

    🎙️ Coffee, Chaos and ProdSec , Ep 50 Open source didn't die. It got conscripted. That's Chainguard CEO Dan Lorenc's framing, and Cameron and Kurt spend this episode picking it apart: a two front war where AI finds zero days faster than any triage queue can absorb them, and package poisoning hits at industrial scale. The real fight is over the word "maintained." Nobody has a working definition. A project looks the same the day before a maintainer walks away as the day after. Cameron coins a term

Publishing over time

Last 90 days. Choose a month to open its work.

Recurring subjects

Named in the text we hold. One piece can cover several.

Audience

No verified audience measurement yet.

About this data

Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.

Identity or attribution wrong? Suggest a correction.

See coverage about Coffee, Chaos and ProdSec