Coffee, Chaos and ProdSec

Ep 39 - Governing AI Agents and NHIs - Identity Is the Control Plane Full Stop

1 h 1 min · 27. Mai 2026
Episode Ep 39 - Governing AI Agents and NHIs - Identity Is the Control Plane Full Stop Cover

Beschreibung

🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 39 AI agents are in production. They have access. They're taking actions. And almost none of them have an owner. This week Cameron [https://www.linkedin.com/in/cameronww7]and Kurt [https://www.linkedin.com/in/kurthendle]come off a multi-day identity summit with a take they're both confident in: the industry is reaching for gateways, firewalls, and legacy IGA platforms to solve an AI security problem that is fundamentally an identity problem. None of those tools were built for agents and slapping an AI badge on them does not change that. From the three identity types debate that nobody has settled, to why access certification is a group therapy session waiting to happen, to why AI gateways are just firewalls with better marketing, this episode covers what identity governance for AI actually looks like when you strip out the vendor noise. If you work in Cybersecurity, Product Security, Application Security, or DevSecOps and you have ever nodded along when someone said guardrails without knowing what they meant, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

Kommentare

0

Sei die erste Person, die kommentiert

Melde dich jetzt an und werde Teil der Coffee, Chaos and ProdSec-Community!

Loslegen

2 Monate für 1 €

Dann 4,99 € / Monat · Jederzeit kündbar.

  • Podcasts nur bei Podimo
  • 20 Stunden Hörbücher / Monat
  • Alle kostenlosen Podcasts

Alle Folgen

42 Folgen

Episode Ep 41 - No Budget, No Blueprint, No Lies - Building ProdSec From Scratch - Part 1 Cover

Ep 41 - No Budget, No Blueprint, No Lies - Building ProdSec From Scratch - Part 1

🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 41 DevSecOps is dead. Cameron [https://www.linkedin.com/in/cameronww7]said it. Kurt [https://www.linkedin.com/in/kurthendle]didn't fully disagree. And that's just the first five minutes. This week Cameron and Kurt kick off a two-part series on building a ProdSec program from scratch, no inherited tool sprawl, no political debt, just a greenfield mandate and nine domains to figure out. But before the org chart gets drawn, they set the stage with the agentic SDLC, because any program being built today is being built into a development environment that already broke the assumptions traditional AppSec was designed for. Part 1 covers four domains: AppSec and DevSecOps as a merged practitioner reality, Security Architecture as the upstream design function most teams only add after something goes wrong, and Cloud Security as the infrastructure layer nobody fully owns and everyone argues about, including a full WAF debate nobody asked for but everyone needed. If you work in Product Security, Application Security, or DevSecOps and you've ever been handed a blank org chart and told to figure it out, this one is the episode you didn't know you were waiting for. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

10. Juni 20261 h 8 min
Episode Ep 40 - GitHub Breach, Open Source Malware, Dev Machine Gold Mines ft. Paul McCarty and Jenn Gile Cover

Ep 40 - GitHub Breach, Open Source Malware, Dev Machine Gold Mines ft. Paul McCarty and Jenn Gile

🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 40 Less than 5% of CVEs are actually exploitable. One hundred percent of malicious packages are bad by design. So why is your entire AppSec budget chasing the first problem? This week Cameron [https://www.linkedin.com/in/cameronww7]and Kurt [https://www.linkedin.com/in/kurthendle] bring on Paul McCarty and Jenn Gile, co-founders of OpenSourceMalware, to break down why the open source malware problem is structurally different from vulnerability management, why your EDR and SCA tooling weren't built for it, and why 78% of what OSM tracks has zero attribution because most threat actors aren't TeamPCP screaming for clout. They're quiet, they're patient, and they're already on your developer machines. From AI slop squatting and four to five net new info stealers per day, to credential-stuffed dev machines, non-deterministic agents bypassing guardrails, and DPRK making $2 billion while everyone watches TeamPCP, this one covers the threat class that most programs still don't have a budget line for. If you work in AppSec, DevSecOps, or Product Security and your malware response plan is "covered by SCA," this episode is going to be uncomfortable. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

3. Juni 20261 h 4 min
Episode Ep 39 - Governing AI Agents and NHIs - Identity Is the Control Plane Full Stop Cover

Ep 39 - Governing AI Agents and NHIs - Identity Is the Control Plane Full Stop

🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 39 AI agents are in production. They have access. They're taking actions. And almost none of them have an owner. This week Cameron [https://www.linkedin.com/in/cameronww7]and Kurt [https://www.linkedin.com/in/kurthendle]come off a multi-day identity summit with a take they're both confident in: the industry is reaching for gateways, firewalls, and legacy IGA platforms to solve an AI security problem that is fundamentally an identity problem. None of those tools were built for agents and slapping an AI badge on them does not change that. From the three identity types debate that nobody has settled, to why access certification is a group therapy session waiting to happen, to why AI gateways are just firewalls with better marketing, this episode covers what identity governance for AI actually looks like when you strip out the vendor noise. If you work in Cybersecurity, Product Security, Application Security, or DevSecOps and you have ever nodded along when someone said guardrails without knowing what they meant, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

27. Mai 20261 h 1 min
Episode Ep 38 - Governance Without Enforcement Is Theater and Shadow AI Knows It Cover

Ep 38 - Governance Without Enforcement Is Theater and Shadow AI Knows It

🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 38 Your org told everyone to use AI. The budget ran out. Someone found a better free tool. Boom, shadow AI just happened. This week Cameron [https://www.linkedin.com/in/cameronww7]and Kurt [https://www.linkedin.com/in/kurthendle] record on four hours of sleep fresh off two days in Austin talking AI and identity with practitioners, and somehow that makes this episode better. They get into where shadow AI actually lives across the corporate surface and the SDLC, what you can detect today with EDR, SIEM, SASE, and a GitHub search bar, and where current detection completely falls apart. From AISPM getting called out as a category that overpromises, to live threat modeling on how a developer could run a local model cluster at home and stay invisible to every control your team has, to why governance without enforcement is just theater with better fonts, this one is honest about what security teams can and cannot see right now. If you work in AppSec, DevSecOps, or Security Architecture and have ever written an AI acceptable use policy without knowing what AI your org actually uses, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

20. Mai 20261 h 1 min
Episode Ep 37 - Scattered Spider Called Your Help Desk and Your TPRM Annual Review Missed It Cover

Ep 37 - Scattered Spider Called Your Help Desk and Your TPRM Annual Review Missed It

🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 37 Your vendor filled out the questionnaire. They have a SOC 2. And they just got you popped. This week Cameron [https://www.linkedin.com/in/cameronww7]and Kurt [https://www.linkedin.com/in/kurthendle]get into the third-party risk management conversation that the industry keeps avoiding. Not the checkbox version, the one where Scattered Spider is social engineering your managed service provider's help desk and you're finding out about it from a news alert. They cover why SOC 2 is a report and not a certification, why vendor management and TPRM are two completely different functions that most companies let collapse into one spreadsheet, why open source dependencies are third-party risk that nobody owns, and what continuous monitoring actually looks like when you stop pretending an annual audit is a security control. Plus the Delve incident, goblins in AI training data, and Kurt reading the scope statement while Cameron does the actual research. If you work in Product Security, Application Security, DevSecOps, or GRC and you have ever accepted a SOC 2 Type 1 as proof that someone takes security seriously, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

13. Mai 202656 min