Coffee, Chaos and ProdSec

Cameron Walters and Kurt Hendle
undefined
Dec 3, 2025 • 1h 10min

Ep 14 - DevSecOps Without the Buzzwords - What It Really Takes to Build Secure Software

🎙️ Coffee, Chaos and ProdSec - Ep 14DevSecOps gets thrown around in cybersecurity more than any other term, but almost no one agrees on what it actually means.So this week, Kurt and Cameron pour fresh mugs and unpack the real practices behind modern Application Security, Product Security, DevSecOps, and Software Supply Chain Security without the marketing fluff.From threat modeling and architecture reviews, to CI/CD guardrails, identity patterns, SBOMs, pipeline automation, and why DAST still refuses to fit anywhere, this episode digs into how security can integrate into the entire software lifecycle without slowing teams down.Cameron and Kurt break down why DevSecOps is more culture than tooling, how design flaws start long before code, what AI is about to break next, and why “shift everywhere” beats “shift left” every time. If you work in cybersecurity or just enjoy hearing two security leaders question reality over caffeine, this one is your new weekly ritual.☕ New episodes every Wednesday.Coffee, Chaos & ProdSec — strong coffee, stronger opinions.
undefined
Nov 26, 2025 • 1h 4min

Ep 13 - Untangling Cloud Security - Foundations, Failures, and What Teams Miss

🎙️ Coffee, Chaos & ProdSec – Ep 13 This week, Cameron and Kurt tackle the questions everyone claims to understand but absolutely argues about in every cloud meeting. What is the cloud really? Why is identity suddenly the perimeter? And how did Kubernetes quietly become everyone’s new production environment?We break down the real concerns behind cloud sprawl, misconfigurations, and identity chaos, plus why CSPM, CWPP, CASB, DSPM, and a dozen other acronyms all matter more than people want to admit.We get into: Why cloud security shifted to identity first The real risk of skipping CSPM Protecting Kubernetes without tears API chaos and data exposure The tech stack modern teams actually need☕ New episodes every Wednesday. Coffee, Chaos & ProdSec — strong coffee, stronger opinions.
undefined
Nov 19, 2025 • 1h 5min

Ep 12 - OWASP Top 10:2025 RC1 Breakdown - The Vulnerabilities That Refuse To Die

🎙️ Coffee, Chaos & ProdSec - Ep 12The OWASP Top 10:2025 RC1 is here, and it is already causing chaos. So this week, Kurt and Cameron grab their mugs and break down every category with real world stories, honest takes, and a few spicy opinions on why some vulnerabilities just will not go away.From Broken Access Control dominating the charts again, to Misconfigurations that keep haunting cloud teams, to classic Injection failures refusing to stay in the past, this episode digs into the patterns behind the list and what they reveal about the state of modern security.Your hosts explore how design flaws emerge long before code is written, why authentication failures keep showing up in new forms, and how logging gaps continue to blind even mature orgs. It is a guided tour through the list with humor, insight, and the occasional “I cannot believe this still happens” moment.If you work in AppSec, Product Security, DevSecOps, or you simply enjoy hearing two security leaders question reality over a cup of coffee, this episode is your new weekly ritual.☕ New episodes every Wednesday. Tune in, patch your brain, and embrace the beautiful mess of the OWASP Top 10:2025 RC1.
undefined
Nov 18, 2025 • 59min

Ep 11 – Google vs FFmpeg - The Open Source Meltdown

🎙️ Coffee, Chaos & ProdSec – Episode 11This week, Kurt and Cameron break down the showdown between Google’s Big Sleep AI and the FFmpeg maintainers keeping the internet’s media backbone running for free.A tiny bug in a 1995 video codec sparked a big debate about responsibility, AI-driven vulnerability hunting, and the growing strain on open source volunteers.We get into: • Why FFmpeg pushed back with “just submit a patch” • How AI is flooding OSS projects with vulnerabilities • The reality of trillion-dollar companies relying on unpaid labor • What needs to change before more maintainers walk awayGrab your coffee and settle in as we unpack one of the biggest open source stories of the year.☕ New episodes every Wednesday.Coffee, Chaos & ProdSec — strong coffee, stronger opinions.
undefined
Nov 15, 2025 • 50min

Ep 10 - From Chaos to Controls - The Story Behind OWASP SPVS

🎙️ Coffee, Chaos & ProdSec – Ep 10 This week, Cameron and Kurt sit down with the co-founders of the OWASP Secure Pipeline Verification Standard to unpack the real story behind SPVS and why the industry desperately needed a pipeline-focused security standard.From the early days of chaotic DevSecOps practices and scattered controls, to the moment the community rallied behind a structured, prescriptive approach, this episode dives into how SPVS came to life and the problems it set out to fix. Your hosts explore the gaps between policy and practice, why pipelines became the new enterprise battleground, and how SPVS is changing the way teams think about CI and CD security.You will hear candid insights on the earliest design debates, the tradeoffs that shaped the framework, and the push to create something both practical and auditable. It is a conversation that connects the dots between pipeline pain, cultural friction, and the growing need for predictable, verifiable controls in modern software delivery.If you work in AppSec, Product Security, DevSecOps, platform engineering, or you are simply curious about how community standards evolve, this episode offers a rare look inside the origin, intent, and future of SPVS.☕ New episodes every Wednesday.Grab your coffee, settle in, and follow along as we explore how pipeline chaos turned into pipeline clarity.
undefined
Nov 11, 2025 • 55min

Ep 09 - Secrets in the Code - How Leaked Keys Can Sink a Ship

🎙️ Coffee, Chaos and ProdSec, Ep 9Ever pushed an API key at 2 a.m. and hoped nobody noticed? In this episode, we dig into one of the most preventable but devastating security failures: secrets in code. From leaked AWS keys and OAuth tokens to misconfigured GitHub Actions, we explore how small oversights can open the door to massive breaches, and why this problem keeps growing every year.We break down real-world incidents like hardcoded admin credentials and recent supply-chain compromises, showing how each one spiraled from simple mistake to global impact. Then we look at the systemic reasons it keeps happening, velocity over hygiene, CI/CD complexity, and the myth that “encrypted” equals “secure.”Grab your mug and join us as we share practical fixes that actually work, from automated scanning and vault integration to culture-level change. Because in the end, secrets management isn’t a feature, it’s survival.☕ New episodes every Wednesday.Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.
undefined
Nov 11, 2025 • 1h 12min

Ep 08 - Hack the Stack - Inside the Chaos of Pen Testing

🎙️ Coffee, Chaos and ProdSec, Ep 8What really happens when you “hack the stack”? In this episode, we pull back the curtain on the messy, brilliant world of penetration testing, from corporate networks and VPNs to APIs, CI/CD pipelines, and live production systems. We explain what pen testing actually is, why it’s often misunderstood, and how the best testers balance creativity, curiosity, and chaos.Then we get real about motivations and mishaps: compliance checkboxes, reports that gather dust, and the occasional “oops, we broke prod” moment. We trade war stories, debate bug bounties vs. red teams, and unpack how AI, automation, and continuous testing are changing the game, without replacing the human hacker’s instinct.Grab your mug and join us for unfiltered stories, hot takes, and hard-won lessons from the field. Whether you’re a tester, a builder, or just pen-test-curious, this episode proves that breaking things (ethically) is still one of the best ways to learn.☕ New episodes every Wednesday.Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.
undefined
Nov 11, 2025 • 58min

Ep 07 - Access (Out of) Control - Tales of Permissions Gone Wild

🎙️ Coffee, Chaos and ProdSec, Ep 7Who left the keys under the mat? In this episode, we unlock the chaos behind broken access control, from S3 buckets of doom to interns with production privileges. We share real-world stories of “everyone’s an admin,” zombie accounts, and permission creep that turned harmless systems into ticking time bombs.Then we dig into why this keeps happening: messy RBAC models, cultural blind spots, and the endless tug-of-war between convenience and control. We explore how organizations can move from reactive fixes to proactive design with automation, ephemeral access, and meaningful reviews that actually improve security instead of blocking work.Grab your mug and join us as we expose the comedy (and tragedy) of bad permissions, share practical ways to lock things down without locking people out, and remind you, with great access comes great responsibility.☕ New episodes every Wednesday.Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.
undefined
Nov 11, 2025 • 1h 3min

Ep 06 - The Break Down - So You Wanna Be a ProdSec Pro?

🎙️ Coffee, Chaos and ProdSec, Ep 6Thinking about breaking into Product Security? In this episode, we lay out the roadmap, how to start, what to learn, and how to thrive once you land the role. We share our own origin stories, the detours we took to get here, and the lessons we learned the hard way along the way.Then we dig into the skills that matter, from threat modeling and secure design to communication, empathy, and influence. We discuss favorite tools, common misconceptions, and how to build credibility through side projects, open source, or community involvement, even before you’ve got “ProdSec” in your title.Grab your mug and take notes as we spill the (coffee) beans on how to stand out, get hired, and survive your first ProdSec gig, chaos, caffeine, and all.☕ New episodes every Wednesday.Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.
undefined
Nov 11, 2025 • 55min

Ep 05 - War Stories - The Most Interesting Attacks We’ve Witnessed

🎙️ Coffee, Chaos and ProdSec, Ep 5Where were you when Log4j hit? In this episode, we revisit some of the wildest moments in modern AppSec and ProdSec history, from dependency chaos and credential leaks to the late-night incidents that taught us the most. We talk through real (and an0nym1z3d) stories that shaped how we think about risk, response, and resilience.We break down what actually happened during infamous security meltdowns, how teams reacted under pressure, and the surprising lessons that came out of the panic. Expect everything from supply-chain shenanigans to “secrets in code” horror stories, plus a few industry rants in our “What Grinds My Gears” segment.Grab your coffee and settle in for the ultimate mix of humor, humility, and hard-won wisdom, because every breach comes with a story worth telling.☕ New episodes every Wednesday.Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app