
Ep 54 - Zero Day, Zero Patience, Admin Tokens in Three Days Flat
Om avsnittet
đïž Coffee, Chaos and ProdSec, Ep 54
An artifact registry handed out admin access to anyone who asked. A print server got popped before the vendor even knew it had a bug. And somehow the vulnerability management metric everyone still quotes doesn't mean what people think it means anymore.
This week Cameron and Kurt tear through two back-to-back critical CVEs, a JFrog Artifactory auth bypass that went from patch to admin token minting in three days, and a PaperCut NG/MF chain that was already being exploited before PaperCut had a name for it. From there they get into Uber open sourcing its Agentic Detection and Response system, the approval fatigue math that breaks human-in-the-loop at scale, and why credential leakage quietly beat prompt injection as the real problem nobody saw coming.
The back half is the DryRun Security piece both hosts read twice before recording. Ken Johnson's argument that chasing Mythos-level parity is a floor, not a strategy, kicks off a real debate about detection versus prevention, the three competing definitions of Mythos ready, and why defenders already hold context attackers can't touch.
If you work in Application Security, Product Security, DevSecOps, or Security Architecture and you're tired of the phrase secure by default meaning nothing, this one's for you.
â New episodes every Wednesday.
Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.
Fler avsnitt
Visa alla avsnitt av Coffee, Chaos and ProdSecCoffee, Chaos and ProdSec med Cameron Walters and Kurt Hendle finns tillgÀnglig pÄ flera plattformar. Informationen pÄ denna sida kommer frÄn offentliga podd-flöden.