AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470

AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470

Author: Security Weekly Productions August 3, 2026 Duration: 1:37:00

Interview with Andrew Dunbar, CISO at Shopify

After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world.

Andrew's Resources:

Interview with Kern Smith

Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding.

Segment Resources

Enterprise Security News

Finally, in the enterprise security news,

  1. Pre-black hat funding goes nuts
  2. we have 4 new cybersecurity unicorns!
  3. Cyera acquires Oasis for one BILLION dollars
  4. Lots of new product announcements with hacker summer camp next week
  5. Hugging Face got hacked by a competitor's agent and are cool with it?
  6. Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal
  7. Are open, local models the future of AI?
  8. AI isn't coming for your job
  9. lots of vendor reports
  10. bad cybersecurity takes are apparently mainstream memes now???

All that and more, on this episode of Enterprise Security Weekly.

Show Notes: https://securityweekly.com/esw-470


Dive into the ever-evolving world of digital defense with the Security Weekly Podcast Network (Video). Produced by Security Weekly Productions, this network isn't a single perspective but a comprehensive hub where different facets of cybersecurity come into focus through distinct, dedicated shows. You'll find episodes from series like Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News, all curated in one feed. This structure means that whether you're analyzing code, shaping corporate policy, or managing infrastructure, there's relevant content for you. The discussions move beyond headlines, offering practical analysis and expert insights that help make sense of complex threats and solutions. By blending technology deep dives with timely news commentary, this video podcast provides a multi-dimensional view of the field, suitable for professionals who need to stay informed and enthusiasts curious about how security shapes our digital lives. It’s a consistent resource for anyone looking to understand not just what is happening in cybersecurity, but why it matters and how to respond.
Author: Language: English Episodes: 50

Security Weekly Podcast Network (Video)
Podcast Episodes
Fixing Vulns Is Harder Than Finding Them - PSW #936 [not-audio_url] [/not-audio_url]

Duration: 2:02:34
In the news this week: InfraTrust and knowing what to patch Adversary in the middle triggered command injection Exploitarium again FreeRDP comes with free vulnerabilities AI breaking out of sandboxes on its own Wordpress…
1999 Called and It Wants It's Exploits Back - PSW #935 [not-audio_url] [/not-audio_url]

Duration: 2:11:49
This week, our technical segment covers a new open-source tool written by Paul (and Claude) that helps you keep your Linux systems up to date and assess supply chain risks. It's called "fettle" and is a pure Python imple…