AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470 @SecurityWeekly
AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470  @SecurityWeekly
Uploaded August 2026 | Updated September 2026, 2 weeks ago
Interview with Andrew Dunbar, CISO at Shopify

After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world.

Andrew's Resources:

- https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model

Interview with Kern Smith

Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding.

Segment Resources

- zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile
- Global Mobile Threat Report 2026: lp.zimperium.com/hubfs/MAPS_MTD/REPORT/GEN/Global Mobile Threat Report 2026.pdf

Enterprise Security News

Finally, in the enterprise security news,

1. Pre-black hat funding goes nuts
2. we have 4 new cybersecurity unicorns!
3. Cyera acquires Oasis for one BILLION dollars
4. Lots of new product announcements with hacker summer camp next week
5. Hugging Face got hacked by a competitor’s agent and are cool with it?
6. Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal
7. Are open, local models the future of AI?
8. AI isn’t coming for your job
9. lots of vendor reports
10. bad cybersecurity takes are apparently mainstream memes now???

All that and more, on this episode of Enterprise Security Weekly.

Visit securityweekly.com/esw for all the latest episodes!

Show Notes: securityweekly.com/esw-470

00:00:00 Welcome to ESW: Episode Preview and Host Introductions
00:04:24 Andrew Dunbar on Shopify's 13-Year AppSec Journey
00:07:33 Shopify's Trust Model and PCI Compliance Evolution
00:12:53 How AI Transforms Bug Bounty Programs and Vulnerability Research
00:20:54 Shopify's Approach to Building AI AppSec Harnesses
00:23:11 Managing LLM Token Efficiency and Model Redundancy
00:28:10 Kern Smith on Zimperium's Global Mobile Threat Report
00:31:48 How Mobile Security Evolves with Shifting Attack Vectors
00:34:39 Securing BYOD and Corporate Mobile Device Landscapes
00:40:11 The Rise of Social Engineering in Mobile Attacks
00:45:55 Vibe Coding and AI's Impact on App Security
00:54:53 Ensuring App Store Security with AI-Generated Code
01:00:21 Pre-Black Hat Funding and New Cybersecurity Unicorns
01:11:55 Analyzing the Most Valuable Security Acquisitions
01:14:12 Key Cybersecurity Acquisitions: Cyera, Permiso, Embrace
01:18:37 Microsoft and Bugcrowd's AI Vulnerability Tools
01:23:32 Apple's Push for On-Device AI and Hardware
01:27:07 The Hugging Face Hack and OpenAI's Controversial Response
01:33:38 Humorous Cybersecurity Ad Parody and Episode Outro
AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470Three interviews: system fragility, operational clarity, and Identity for AI agents - ESW #471Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394AI Security Tools Need to TalkWhy Streaming Apps Protect ContentDefense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390Security Tools Are Breaking SOCsAI Becomes The Supply ChainThe Hidden Risk of Patch PrioritiesAI Agents Escaped the Evaluation EnvironmentAI Is Reviving Anomaly DetectionSmart Toilets: Health Insights or Data Concerns?
Security Weekly - A CRA Resource |

AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER