This week on Absolute AppSec’s very special 327th episode, Seth (@sethlaw) and Ken (@cktricky) are joined by the hosts from the Coffee, Chaos, and ProdSec podcast: Kurt and Cameron. Sponsored by GuardSquare, the primary focus is on the Application Security Posture Management (ASPM) consolidation. The discussion deepens into prioritization strategies amid a massive, AI-driven surge in vulnerability research that threatens to double annual CVE counts. They also examine the critical line separating standard software bugs from intentionally malicious open-source packages that target developer endpoint systems. To find this episode, go to https://www.youtube.com/@AbsoluteAppSec/streams. You can find Absolute AppSec and Coffee, Chaos, and ProdSec wherever you get your podcasts. 

Cameron Walters is Director of Application Security & Security Engineering at Teradata, a specialized DevSecOps advisor, and the co-host of Coffee, Chaos, and ProdSec. He focuses heavily on the operational realities of building scalable application security programs. He is recognized in the industry for his hands-on experience in managing software registries, mitigating open-source supply chain risk, and spearheading custom, impact-based vulnerability management frameworks that fit an organization's actual business needs. 

Kurt is Chief Security Architect at Teradata and the other half of the Coffee, Chaos, and ProdSec podcast. Affectionately known as the “chaos tamer” of the duo, Kurt specializes in security architecture, system engineering, and managing the systemic vulnerabilities that threaten modern production environments. On his show, he brings deep architectural expertise to complex discussions surrounding cloud security infrastructure, Kubernetes vulnerabilities, and mapping reachable attack paths. 

“And if you look at all the major ASP [...] platforms that do scanning, they all started out as maybe like SCA or they were a SAS scanner. And then they bolted on, acquired something else, grabbed an open source, something [...] which means they're going to have really one good product and then a bunch of like mediocre attach ons that are going to feel like [...] janky [...] Frankenstein platform[s]."

Cameron

The application security landscape is moving fast, and cutting through the industry hype requires a firm grasp on the reality of Application Security Posture Management (ASPM) consolidation. While the industry pushes hard for a “single pane of glass" to aggregate static testing, supply chain risk, and overall posture, the experts question whether these platforms genuinely reduce developer friction or simply package the same data noise into a more expensive window. Cameron highlights the frustration of managing bloated, Frankenstein-esque platforms stitched together by messy corporate acquisitions, while Seth offers a pragmatic consulting view, noting that most organizations lack the security buy-in or engineering resources to customize these dashboards effectively. Ken questions whether ASPM was ever truly designed for developers to begin with, though the panel agrees that, when structured around product components, it can help teams pivot away from rigid, legacy CVSS scores toward true risk management informed by runtime context and asset impact analysis.

“My big problem, and this is what grinds my gears about all of this, is AppSec is becoming the SOC. We are the incident responders for all this. Our SOC peers have usually [...] zero interest in understanding what AppSec slash ProdSec does. They're just all taught and really informed on the corporate side."

Cameron

A critical blind spot in current security programs is the tendency to evaluate accidental code flaws and intentionally malicious open-source software compromises under the exact same vulnerability lens. While standard CVEs require programmatic patching, active supply chain malware represents a deliberate, hostile attempt to hijack developer workstations and easily bypasses basic registry restrictions. Ken notes that prioritizing external-facing assets over internal systems is essential to limiting blast radius, but this hyper-complex threat landscape has left product security teams isolated. Because traditional corporate SOC analysts are trained to monitor corporate infrastructure rather than first-party software-layer logs, AppSec and ProdSec teams are routinely dragged out of bed at two in the morning to serve as incident responders. To fix this, Seth and the group advocate for a clear shift in organizational maturity: creating specialized product incident response teams integrated directly within the SOC.

Rounding out the discussion, the hosts take a critical look at the sudden explosion of niche OWASP Top Ten frameworks and the sobering operational realities of generative AI. While there is a clear push for frameworks targeting developer endpoint risks, internal data reveals that foundational flaws like excessive privileges and prompt injections still heavily dominate actual production environments. Reflecting on the chaos of advanced automation, Ken and Seth critique the fear-uncertainty-doubt (FUD) marketing of tools that claim to autonomously secure repositories, warning leaders against the Three-Week Demo Trap, in which enterprise token consumption costs quickly exceed $5,000 per day. Ultimately, the panel notes that soaring API costs, restrictive rate limits, and unpredictable model restrictions are finally pushing mature organizations past the peak of the AI hype cycle and toward hosting capable, open-weight models locally.

Think about your mobile app’s source code. Once it hits the app store, it’s out in the wild. And without the right protection, decompiling is easy for malicious actors looking to steal your IP or tamper with your software.

That’s where Guardsquare comes in. Guardsquare provides the highest level of mobile app security for Android and iOS applications and SDKs. Their advanced tools integrate seamlessly into your CI/CD pipeline. We're talking polymorphic multi-layered code hardening techniques and automated runtime application self-protection, paired with mobile application security testing and real-time threat monitoring, to deliver the highest level of mobile app security without compromise.

Don't leave your hard work exposed. Secure your mobile applications today. Go to guardsquare.com to learn more.

At the start of this episode, someone asked how many pairs of Crocs we have. Do t-shirts count? Grab yours here:

Basics are back. CrocsSocks4EVER.

To hear about our next crossover episode with Coffee, Chaos, and Prodsec, come hang in our Slack; just send us a note to join the channel. Sit down, relax, and stay a while.

Stay Secure,

Seth & Ken

https://www.youtube.com/watch?v=yRckeeg8-5U&t=416s– Episode #316 w/ Coffee, Chaos, and ProdSec - Agentic Development Lifecycle - Hosts Ken Johnson and Seth Law participate in a crossover with Kurt Hendle and Cameron Walters from the Coffee, Chaos, and ProdSec podcast to discuss the radical transformation of security roles in an AI-driven landscape. The guests share origin stories rooted in gaming and "mischievous" curiosity, which evolved into deep careers in security architecture and engineering.

https://youtube.com/watch?v=oZF6rgKKB44 – Episode #324 - Three Week Trap, Malicious Extensions - Ken reviews his own blog post regarding the "three-week demo trap", detailing critical, ignored requirements for AI products—such as evaluation, statistical reproducibility, and token cost economics—noting that executing enterprise testing via frontier models can easily exceed $5,000 a day.

https://youtu.be/watch?v=DEYR7pZXJyk – Episode #230 - False Positives vs. Negatives, Scaling Vuln Management - Discussions on AI-generated recommendations and how it can be useful, but also turn out poorly. Finally, introductions on large-scale vulnerability management at GitHub and how organizations struggle to fix issues identified through multiple streams.

Absolute AppSec Happenings

The Bug Bounty Singularity – In their blog post, Joseph Thacker and JD describe building an autonomous AI hacking agent using Claude 4.6, which they dubbed the "Bug Bounty Singularity." Over five months, the bot discovered 126 vulnerabilities—including critical partner platform takeovers and data leaks—by employing persistent reasoning loops ("ralph loops") and an orchestration system to balance broad reconnaissance with deep analysis.

Are bug bounties cooked? – Drawing a parallel to the "Quartz Crisis" in watchmaking, Luke Stephens argues that while AI has automated bug discovery—increasing bug supply and threatening to drop bounty values—bug bounties are not cooked. The value of diverse human insight remains crucial. However, he warns that the rising cost of advanced AI tokens risks pricing out disadvantaged talent, potentially turning hacking from an accessible, merit-based discipline into an elite playground.

Upcoming Events

Where in the world are Seth and Ken?

August 1-4, 2026 - AI-Enhanced Secure Code Review: Black Hat Edition - BlackHat USA, Las Vegas - Seth and Ken are bringing a four-day exclusive course to Black Hat. This is an update on the exclusive version of the course offered at Black Hat Europe. Early bird pricing is ongoing, so it’s a great opportunity to get a truly in-depth understanding of Secure-Code Review and how it can be empowered through LLM-tooling. Seth and Ken have innovated industry-leading trainings in both of these topics, so this four-day course promises to provide a lot of valuable insight.

August 10-11, 2026 - Agentic AppSec: Harnessing LLMs - DEF CON Training, Las Vegas - Comprehensive course designed for developers and cybersecurity professionals seeking to harness the power of Agentic AI and Large Language Models (LLMs) to enhance software security and development practices.

Keep Reading