Uploaded August 2026 | Updated September 2026, 2 weeks ago
Interview with Andrew Dunbar, CISO at Shopify
After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world.
Andrew's Resources:
- https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model
Interview with Kern Smith
Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding.
Segment Resources
- zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile
- Global Mobile Threat Report 2026: lp.zimperium.com/hubfs/MAPS_MTD/REPORT/GEN/Global Mobile Threat Report 2026.pdf
Enterprise Security News
Finally, in the enterprise security news,
1. Pre-black hat funding goes nuts
2. we have 4 new cybersecurity unicorns!
3. Cyera acquires Oasis for one BILLION dollars
4. Lots of new product announcements with hacker summer camp next week
5. Hugging Face got hacked by a competitor’s agent and are cool with it?
6. Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal
7. Are open, local models the future of AI?
8. AI isn’t coming for your job
9. lots of vendor reports
10. bad cybersecurity takes are apparently mainstream memes now???
All that and more, on this episode of Enterprise Security Weekly.
Visit securityweekly.com/esw for all the latest episodes!
Show Notes: securityweekly.com/esw-470
00:00:00 Welcome to ESW: Episode Preview and Host Introductions
00:04:24 Andrew Dunbar on Shopify's 13-Year AppSec Journey
00:07:33 Shopify's Trust Model and PCI Compliance Evolution
00:12:53 How AI Transforms Bug Bounty Programs and Vulnerability Research
00:20:54 Shopify's Approach to Building AI AppSec Harnesses
00:23:11 Managing LLM Token Efficiency and Model Redundancy
00:28:10 Kern Smith on Zimperium's Global Mobile Threat Report
00:31:48 How Mobile Security Evolves with Shifting Attack Vectors
00:34:39 Securing BYOD and Corporate Mobile Device Landscapes
00:40:11 The Rise of Social Engineering in Mobile Attacks
00:45:55 Vibe Coding and AI's Impact on App Security
00:54:53 Ensuring App Store Security with AI-Generated Code
01:00:21 Pre-Black Hat Funding and New Cybersecurity Unicorns
01:11:55 Analyzing the Most Valuable Security Acquisitions
01:14:12 Key Cybersecurity Acquisitions: Cyera, Permiso, Embrace
01:18:37 Microsoft and Bugcrowd's AI Vulnerability Tools
01:23:32 Apple's Push for On-Device AI and Hardware
01:27:07 The Hugging Face Hack and OpenAI's Controversial Response
01:33:38 Humorous Cybersecurity Ad Parody and Episode Outro
Interview with Andrew Dunbar, CISO at Shopify
After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world.
Andrew's Resources:
- https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model
Interview with Kern Smith
Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding.
Segment Resources
- zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile
- Global Mobile Threat Report 2026: lp.zimperium.com/hubfs/MAPS_MTD/REPORT/GEN/Global Mobile Threat Report 2026.pdf
Enterprise Security News
Finally, in the enterprise security news,
1. Pre-black hat funding goes nuts
2. we have 4 new cybersecurity unicorns!
3. Cyera acquires Oasis for one BILLION dollars
4. Lots of new product announcements with hacker summer camp next week
5. Hugging Face got hacked by a competitor’s agent and are cool with it?
6. Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal
7. Are open, local models the future of AI?
8. AI isn’t coming for your job
9. lots of vendor reports
10. bad cybersecurity takes are apparently mainstream memes now???
All that and more, on this episode of Enterprise Security Weekly.
Visit securityweekly.com/esw for all the latest episodes!
Show Notes: securityweekly.com/esw-470
00:00:00 Welcome to ESW: Episode Preview and Host Introductions
00:04:24 Andrew Dunbar on Shopify's 13-Year AppSec Journey
00:07:33 Shopify's Trust Model and PCI Compliance Evolution
00:12:53 How AI Transforms Bug Bounty Programs and Vulnerability Research
00:20:54 Shopify's Approach to Building AI AppSec Harnesses
00:23:11 Managing LLM Token Efficiency and Model Redundancy
00:28:10 Kern Smith on Zimperium's Global Mobile Threat Report
00:31:48 How Mobile Security Evolves with Shifting Attack Vectors
00:34:39 Securing BYOD and Corporate Mobile Device Landscapes
00:40:11 The Rise of Social Engineering in Mobile Attacks
00:45:55 Vibe Coding and AI's Impact on App Security
00:54:53 Ensuring App Store Security with AI-Generated Code
01:00:21 Pre-Black Hat Funding and New Cybersecurity Unicorns
01:11:55 Analyzing the Most Valuable Security Acquisitions
01:14:12 Key Cybersecurity Acquisitions: Cyera, Permiso, Embrace
01:18:37 Microsoft and Bugcrowd's AI Vulnerability Tools
01:23:32 Apple's Push for On-Device AI and Hardware
01:27:07 The Hugging Face Hack and OpenAI's Controversial Response
01:33:38 Humorous Cybersecurity Ad Parody and Episode Outro










