🎙️ Coffee, Chaos and ProdSec, Ep 45

Vulnerability counts just went logarithmic. Companies are pooling money to buy patches before the public even hears about them. And somebody's still trying to convince you a ten person team running an agent swarm is coming for your job.

This week Cameron and Kurt tear into the vulnerability management chaos AI kicked off in the last two months. Project Glasswing, Chainguard's Athena, and the Linux Foundation's coalition are finding tens of thousands of vulnerabilities and fixing almost none of them, Chainguard's leadership is now calling it negative days instead of zero days, and CVSS is buckling under volume nobody can triage manually anymore.

From the scan after versus intercept and harden debate nobody's actually solved, to the real cost of the fix verify round trip burning tokens on every loop, to whether teams of 40 really shrink to 10 people running orchestrated AI agents, this episode covers Application Security, Security Architecture, and DevSecOps reality with zero patience for the hype.

If you work in ProdSec, AppSec, or Cybersecurity and you're tired of hearing AI replaced your team before anyone's proven it, this one's for you.

☕ New episodes every Wednesday.

Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

Podden och tillhörande omslagsbild på den här sidan tillhör Cameron Walters and Kurt Hendle. Innehållet i podden är skapat av Cameron Walters and Kurt Hendle och inte av, eller tillsammans med, Poddtoppen.