

Coffee, Chaos and ProdSec
Cameron Walters and Kurt Hendle
Coffee, Chaos & ProdSec is where cybersecurity meets caffeine-fueled chaos.
Hosts Kurt (security architect and chaos tamer) and Cameron (ProdSec wrangler and DevSecOps junkie) dive into hacking, AppSec, supply chain failures, AI surprises, and the everyday madness of defending modern systems.
With humor, sharp insight, real breach breakdowns, bad password confessions, and a few questionable impressions, they explore the messy reality of security and how teams survive it.
New episodes Every Wednesday at 5 AM Eastern.
Hosts Kurt (security architect and chaos tamer) and Cameron (ProdSec wrangler and DevSecOps junkie) dive into hacking, AppSec, supply chain failures, AI surprises, and the everyday madness of defending modern systems.
With humor, sharp insight, real breach breakdowns, bad password confessions, and a few questionable impressions, they explore the messy reality of security and how teams survive it.
New episodes Every Wednesday at 5 AM Eastern.
Episodes
Mentioned books

Feb 11, 2026 • 60min
Ep 24 - AI Security Reality Check, When Agents Ship Faster Than Policies
They unpack how AI agents outpace security policies and create shadow AI across teams. Conversation covers provenance gaps that break incident response and automation that buries real breaches. They debate retrofitting security vs building controls into platforms and how identity chaining can escalate privileges. Practical talk on scaling security with internal agents, spec-driven prompts, and reusable secure platform patterns.

Feb 4, 2026 • 57min
Ep 23 - Part 2 - AI Security Incident Response, Supply Chain Chaos, AI Training and the Compliance Wake Up Call
They dig into why traditional incident response and SOC playbooks fail when AI acts unpredictably. They explore prompt injection, data leakage, and gaps in visibility and DLP. They debate automated containment, managing agent blast radius, and risks from vendors enabling AI by default. They also cover AI supply chain questions, the limits of AIBOM ideas, and the need for tailored AI training and compliance readiness.

Jan 28, 2026 • 60min
Ep 22 - Part 1 - AI Security Foundations, Visibility, Governance, and the Risks Nobody Owns
They dig into discovering shadow AI and hidden agents before policies are written. Conversation covers practical visibility tools and low-cost ways to detect unsanctioned AI. They talk about building enabling governance, fast approval flows, and cross-functional councils. The hosts explore AI agent identities, token risks, browser DLP limits, and how to inventory and monitor rapidly changing AI tools.

Jan 21, 2026 • 57min
Ep 21 - Hoodies & Handshakes - The Human Side of Cybersecurity
🎙️ Coffee, Chaos and ProdSec, Ep 21Security teams love tools and checklists, but most failures start with people, pressure, and messy handoffs.So this week, Kurt and Cameron grab their mugs and break down what certifications do not teach, how human risk shows up in real incidents, and why security only works when it becomes a team sport.From rushed approvals and blurry ownership, to vulnerability management that turns into prioritization fights, to governance that looks solid until change hits, this episode follows the work where it actually breaks.Your hosts dig into why execution beats perfection, how context matters more than compliance, and where AI speeds up both delivery and abuse while teams are still trying to keep up. It is practical, a little chaotic, and full of moments that feel like “yeah, that tracks.”If you work in Cybersecurity, Application Security, Product Security, DevSecOps, Software Supply Chain Security, or you are trying to scale security without losing your mind, this episode is for you.☕ New episodes every Wednesday.Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

Jan 14, 2026 • 51min
Ep 20 - API Security - Shadows, Zombies, and Other APIs We Pretend Don't Exist
They tour API security nightmares like unauthenticated endpoints and broken authorization that let attackers roam freely. The conversation digs into shadow and zombie APIs nobody remembers and why inventories keep failing. They unpack AI-driven scanners, MCP/LLM broker risks, and the limits of traditional DAST. Practical fixes and urgency around inventory, docs, and continuous testing come up throughout.

Jan 7, 2026 • 1h 4min
Ep 19 - Cloud Security Chaos: When Identity, Kubernetes, APIs, and AI Collide
🎙️ Coffee, Chaos and ProdSec, Ep 19Cloud security keeps getting more complicated, but identity keeps getting ignored.So this week, Kurt and Cameron grab their coffee and dig into why identity failures are quietly powering most modern cloud incidents.From service accounts that never die, to Kubernetes clusters held together with cluster admin access and hope, to APIs nobody remembers exposing, this episode walks through the real reasons cloud security keeps falling apart at scale.They talk through why teams still treat workload identities like humans, how Kubernetes creates a false sense of safety, why API sprawl and logging pipelines leak more data than people realize, and where AI actually helps versus where it just adds noise and false confidence.There’s no vendor pitch here. Just honest conversations about tradeoffs, broken assumptions, and the gap between cloud security best practices and what actually survives in production.If you work in Cybersecurity, Application Security, Product Security, DevSecOps, Software Supply Chain Security, or you’re trying to make sense of cloud chaos without the buzzwords, this one’s for you.☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

Dec 31, 2025 • 1h 7min
Ep 18 - Brace Yourself for 2026: AI-Powered Mayhem and Coffee-Fueled Product Security Predictions
🎙️ Coffee, Chaos and ProdSec, Ep 18 2026 is getting closer, and security is already acting weird. So this week, Kurt and Cameron grab their mugs and talk through what they see coming next for Product Security and the teams trying to keep up.From AI agents showing up in the SOC, AppSec, DevSecOps, and GRC, to supply chain risks getting deeper and harder to see, this episode walks through the trends that are starting to take shape right now. The kind that change how work actually gets done, not just how tools are marketed.They unpack how AI is speeding up code, reviews, and attacks at the same time, why remediation speed is becoming the real bottleneck, and how identity, cloud, and infrastructure are turning into the main battlegrounds. There are strong opinions, a few laughs, and plenty of moments where the future feels exciting and a little uncomfortable.If you work in Cybersecurity, Application Security, Product Security, DevSecOps, or Software Supply Chain Security, this episode is a look at 2026 through the lens of people who live this stuff every day. All powered by coffee and curiosity.☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinio

Dec 24, 2025 • 1h 12min
Ep 17 - Breaking Into Product Security, AppSec, DevSecOps, and Cloud Security Without a Degree
🎙️ Coffee, Chaos and ProdSec, Ep 17Breaking into cybersecurity without a degree feels impossible, yet people do it every single day. So this week, Cameron and Kurt grab their mugs and get real about how career changers actually break into Product Security, Application Security, DevSecOps, and Cloud Security when their background looks nothing like tech.Your hosts dive into the honest truth behind this path, the rejection, the gatekeeping, and the internal drive it takes to push through. They explore how personal brand becomes your signal in a noisy market, how a strong pivot story makes people want to invest in you, why networking still matters more than any certification, and which technical skills help you stand out early. They even dig into how AI has become a learning accelerator for anyone who knows how to use it with intention.If you are trying to make the jump into security or you want to help someone who is, this episode gives you a roadmap instead of a motivational slogan.☕ New episodes every Wednesday. Coffee, Chaos and ProdSec, strong coffee, stronger opinions.

Dec 17, 2025 • 1h 7min
Ep 16 - Part 2 - Get Comfortable Being Vulnerable: When AI, Risk, and Reality Collide in AppSec
🎙️ Coffee, Chaos and ProdSec - Ep 16Last week we mapped the problem — now we break the system. Kurt and Cameron return with part two of our vulnerability deep dive, tackling CVSS chaos, broken tooling, exploding CVE volume, and how AI is about to overwhelm traditional prioritization models.From exposure validation turning 15,000 findings into 300 actionable items, to ASPM finally giving Product Security teams real visibility, to PCI-DSS forcing companies to patch issues that don’t matter, this episode explores where vulnerability management is heading and what “good” will need to look like next.If you care about Cybersecurity, DevSecOps, Software Supply Chain Security, or how AI will reshape the VM landscape, this one is your next caffeine boost.☕ New episodes every Wednesday.Coffee, Chaos & ProdSec — strong coffee, stronger opinions.

Dec 10, 2025 • 1h 12min
Ep 15 - Part 1 - Get Comfortable Being Vulnerable: The Chaos Behind Every CVE and Every Risk
🎙️ Coffee, Chaos and ProdSec - Ep 15Vulnerabilities are piling up faster than teams can read the reports, and vulnerability management is buckling under the weight. So this week, Kurt and Cameron grab their mugs and dig into why modern VM feels impossible, why severity scores mislead everyone, and how reachability and exploitability matter far more than giant spreadsheets of “critical” issues.From CVSS confusion to EPSS and CISA KEV reshaping prioritization, to AI accelerating discovery and noise, this episode unpacks how we got here and why most organizations are fixing the wrong things.If you work in Cybersecurity, Application Security, Product Security, DevSecOps, or you simply enjoy hearing two leaders question the entire VM ecosystem, this one is for you.☕ New episodes every Wednesday.Coffee, Chaos & ProdSec — strong coffee, stronger opinions.


