Coffee, Chaos and ProdSec

Ep 34 - SPVS 1.5 Is Live: AI Pipeline Security Controls ft. Farshad Abasi

57 min · 22. apr. 2026
episode Ep 34 - SPVS 1.5 Is Live: AI Pipeline Security Controls ft. Farshad Abasi cover

Description

🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 34 AI is already in your pipeline. Your agents are making decisions. And most teams have no controls governing any of it. This week Cameron [https://www.linkedin.com/in/cameronww7], Kurt [https://www.linkedin.com/in/kurthendle], and returning guest Farshad Abasi crack open SPVS 1.5, the OWASP Secure Pipeline Verification Standard community feedback release that ships 132 AI and agentic pipeline security controls across 31 subcategories. From NHI governance for AI agents to AIBOM requirements, deterministic tool authorization, prompt injection classification, and adversarial testing as a hard release gate, this episode covers what the standard actually says and why building it made the gap impossible to ignore. If you work in Application Security, DevSecOps, or Product Security and you have ever approved an AI tool for your pipeline without a governance framework to back it up, this one is going to hit. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec] -> strong coffee, stronger opinions.

Comments

0

Be the first to comment

Sign up now and become a member of the Coffee, Chaos and ProdSec community!

Get Started

1 month for 9 kr.

Then 99 kr. / month · Cancel anytime.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

42 episodes

episode Ep 41 - No Budget, No Blueprint, No Lies - Building ProdSec From Scratch - Part 1 artwork

Ep 41 - No Budget, No Blueprint, No Lies - Building ProdSec From Scratch - Part 1

🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 41 DevSecOps is dead. Cameron [https://www.linkedin.com/in/cameronww7]said it. Kurt [https://www.linkedin.com/in/kurthendle]didn't fully disagree. And that's just the first five minutes. This week Cameron and Kurt kick off a two-part series on building a ProdSec program from scratch, no inherited tool sprawl, no political debt, just a greenfield mandate and nine domains to figure out. But before the org chart gets drawn, they set the stage with the agentic SDLC, because any program being built today is being built into a development environment that already broke the assumptions traditional AppSec was designed for. Part 1 covers four domains: AppSec and DevSecOps as a merged practitioner reality, Security Architecture as the upstream design function most teams only add after something goes wrong, and Cloud Security as the infrastructure layer nobody fully owns and everyone argues about, including a full WAF debate nobody asked for but everyone needed. If you work in Product Security, Application Security, or DevSecOps and you've ever been handed a blank org chart and told to figure it out, this one is the episode you didn't know you were waiting for. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

Yesterday1 h 8 min
episode Ep 40 - GitHub Breach, Open Source Malware, Dev Machine Gold Mines ft. Paul McCarty and Jenn Gile artwork

Ep 40 - GitHub Breach, Open Source Malware, Dev Machine Gold Mines ft. Paul McCarty and Jenn Gile

🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 40 Less than 5% of CVEs are actually exploitable. One hundred percent of malicious packages are bad by design. So why is your entire AppSec budget chasing the first problem? This week Cameron [https://www.linkedin.com/in/cameronww7]and Kurt [https://www.linkedin.com/in/kurthendle] bring on Paul McCarty and Jenn Gile, co-founders of OpenSourceMalware, to break down why the open source malware problem is structurally different from vulnerability management, why your EDR and SCA tooling weren't built for it, and why 78% of what OSM tracks has zero attribution because most threat actors aren't TeamPCP screaming for clout. They're quiet, they're patient, and they're already on your developer machines. From AI slop squatting and four to five net new info stealers per day, to credential-stuffed dev machines, non-deterministic agents bypassing guardrails, and DPRK making $2 billion while everyone watches TeamPCP, this one covers the threat class that most programs still don't have a budget line for. If you work in AppSec, DevSecOps, or Product Security and your malware response plan is "covered by SCA," this episode is going to be uncomfortable. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

3. juni 20261 h 4 min
episode Ep 39 - Governing AI Agents and NHIs - Identity Is the Control Plane Full Stop artwork

Ep 39 - Governing AI Agents and NHIs - Identity Is the Control Plane Full Stop

🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 39 AI agents are in production. They have access. They're taking actions. And almost none of them have an owner. This week Cameron [https://www.linkedin.com/in/cameronww7]and Kurt [https://www.linkedin.com/in/kurthendle]come off a multi-day identity summit with a take they're both confident in: the industry is reaching for gateways, firewalls, and legacy IGA platforms to solve an AI security problem that is fundamentally an identity problem. None of those tools were built for agents and slapping an AI badge on them does not change that. From the three identity types debate that nobody has settled, to why access certification is a group therapy session waiting to happen, to why AI gateways are just firewalls with better marketing, this episode covers what identity governance for AI actually looks like when you strip out the vendor noise. If you work in Cybersecurity, Product Security, Application Security, or DevSecOps and you have ever nodded along when someone said guardrails without knowing what they meant, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

27. maj 20261 h 1 min
episode Ep 38 - Governance Without Enforcement Is Theater and Shadow AI Knows It artwork

Ep 38 - Governance Without Enforcement Is Theater and Shadow AI Knows It

🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 38 Your org told everyone to use AI. The budget ran out. Someone found a better free tool. Boom, shadow AI just happened. This week Cameron [https://www.linkedin.com/in/cameronww7]and Kurt [https://www.linkedin.com/in/kurthendle] record on four hours of sleep fresh off two days in Austin talking AI and identity with practitioners, and somehow that makes this episode better. They get into where shadow AI actually lives across the corporate surface and the SDLC, what you can detect today with EDR, SIEM, SASE, and a GitHub search bar, and where current detection completely falls apart. From AISPM getting called out as a category that overpromises, to live threat modeling on how a developer could run a local model cluster at home and stay invisible to every control your team has, to why governance without enforcement is just theater with better fonts, this one is honest about what security teams can and cannot see right now. If you work in AppSec, DevSecOps, or Security Architecture and have ever written an AI acceptable use policy without knowing what AI your org actually uses, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

20. maj 20261 h 1 min
episode Ep 37 - Scattered Spider Called Your Help Desk and Your TPRM Annual Review Missed It artwork

Ep 37 - Scattered Spider Called Your Help Desk and Your TPRM Annual Review Missed It

🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 37 Your vendor filled out the questionnaire. They have a SOC 2. And they just got you popped. This week Cameron [https://www.linkedin.com/in/cameronww7]and Kurt [https://www.linkedin.com/in/kurthendle]get into the third-party risk management conversation that the industry keeps avoiding. Not the checkbox version, the one where Scattered Spider is social engineering your managed service provider's help desk and you're finding out about it from a news alert. They cover why SOC 2 is a report and not a certification, why vendor management and TPRM are two completely different functions that most companies let collapse into one spreadsheet, why open source dependencies are third-party risk that nobody owns, and what continuous monitoring actually looks like when you stop pretending an annual audit is a security control. Plus the Delve incident, goblins in AI training data, and Kurt reading the scope statement while Cameron does the actual research. If you work in Product Security, Application Security, DevSecOps, or GRC and you have ever accepted a SOC 2 Type 1 as proof that someone takes security seriously, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

13. maj 202656 min