Interview with Andrew Dunbar, CISO at Shopify
After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world.Andrew's Resources:Interview with Kern Smith
Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding.Segment ResourcesEnterprise Security News
Finally, in the enterprise security news,- Pre-black hat funding goes nuts
- we have 4 new cybersecurity unicorns!
- Cyera acquires Oasis for one BILLION dollars
- Lots of new product announcements with hacker summer camp next week
- Hugging Face got hacked by a competitor’s agent and are cool with it?
- Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal
- Are open, local models the future of AI?
- AI isn’t coming for your job
- lots of vendor reports
- bad cybersecurity takes are apparently mainstream memes now???
Andrew Dunbar is the Chief Information Security Officer at Shopify, where he has spent 13 years guiding the company’s journey to becoming one of the world’s most trusted commerce platforms. In his current role as CISO, Andrew leads global security efforts to protect millions of merchants .
He champions a dynamic, risk-based approach, advancing zero-trust principles and fostering an environment for safe innovation across the organization. Andrew also helped build Shopify’s bug bounty program into one of the industry’s top initiatives, partnering closely with external researchers to drive security and transparency.
Prior to Shopify, Andrew held cybersecurity roles at Global Affairs Canada. He holds a Bachelor’s in Software Engineering from Carleton University.
Kern Smith leads global solutions engineering at Zimperium, the mobile security company known for its AI-empowered protection against phishing (mishing), malware, app vulnerabilities, and device compromise. Previously, Kern served in technical account and pre-sales roles at AirWatch (later acquired by VMware) and as a Field Service Engineer at Siemens Medical Solutions.
Kern is a frequent industry voice on mobile threats, regularly quoted in press and interviewed on topics ranging from malware-as-a-service and SDK risk to BYOD blind spots and mobile fraud.
- If you’ve invested in threat intel and still can’t tie it to real risk reduction, you’re not alone. A lot of programs are collecting intel, but not operationalizing it across detection, response, or the business.So what’s actually working?At the Threat Intelligence Virtual Cybersecurity Summit on August 26th, you’ll hear how mature teams are turning intel into action and making it measurable.Security Weekly listeners can register for free at https://securityweekly.com/threatintel using the promo code: CSS26-SW
- InfoSec World brings cybersecurity professionals together across industries, from healthcare and financial services to government and the Fortune 500. Join the community in Orlando, October 12–14, for practical education, new perspectives, and cybersecurity research unveiled live. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.
Adrian Sanabria
- FUNDING/M&A, courtesy of the Security, Funded newsletter, issue #254 – Three [Unicorn] Moon
VIBE CHECK
What layer of the security stack is most valuable to acquire right now?
- 55% - Agent identity platforms
- 27% - Vulnerability prioritization platforms
- 9% - Data/observability platforms
- 9% - SecOps/detection platforms
FUNDING As predicted, here comes the flood of funding announcements as we approach Black Hat!
- Spur, a US-based IP intelligence and bot detection company, raised $200M from Insight Partners after growing bootstrapped for the past nine years.
- ThreatLocker, a US-based zero-trust security company, raises $190M in Series F funding, led by Elephant. This brings total funding to nearly $500M, and values the company at $1.6B. Unicorn Alert ????
- Cathedral, a United States-based autonomous red teaming platform for military cyber operations, raised a $160.0M Venture Round from Andreessen Horowitz and Sequoia Capital. Unicorn Alert ????
- Glow, an Israel-based AI-powered endpoint security platform, raised a $100.0M Series B from CyberStarts, Greenoaks, Redpoint, and Sequoia Capital. Unicorn Alert ????
- Neo Security (formerly Neo.ai), a United States-based AI-driven threat detection and automated response platform, raised a $75.0M Series A from Andreessen Horowitz and Bessemer Venture Partners.
- AegisAI (formerly AegisAI Security), a United States-based email security and incident response platform, raised a $36.0M Series A from Battery Ventures.
- Mate Security, an Israeli-based AI SOC startup, raised a $35M Series A led by Canaan Partners.
- Twenty Technologies, a United States-based offensive cyber warfare operations platform, raised a $30.0M Series B from Khosla Ventures. Unicorn Alert ????
- Hush Security, an Israeli-based AI identity startup raised a $30M Series A led by Akamai, Battery, and YL Ventures.
- Abstract Security, a United States-based security analytics and operations platform, raised a $25.0M Venture Round from AVP and Cheyenne Ventures.
- Empirical Security, a United States-based AI models for threat and vulnerability management programs, raised a $25.0M Series A from Brightmind Partners.
ACQUISITIONS
- Oasis Security, an NHI and agentic access governance platform, was acquired by Cyera for $1B, weeks after Cyera raised $600M at a $12B valuation. Oasis raised $120M in Series B funding in March 2026.
- Embrace, a United States-based user and data observability platform, was acquired by Palo Alto Networks for an undisclosed amount. Embrace had previously raised $77.0M in funding.
- NEW PRODUCTS: Root Evidence Launches Full Platform to Help Security Teams Stop Chasing Millions of Vulnerabilities and Start Preventing Financial Loss
- NEW PRODUCTS: Microsoft unveils new cyber model, agentic security tools to fight hackers
- NEW PRODUCTS: Savant Pathseeker
- BREACHES: Hugging Face’s AI Breach: Arsonists Selling Fire Insurance
There are a LOT of takes on this incident, but Kayne frames the situation really well and comes with all the receipts that OpenAI should have known better.
Other coverage on this
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
- Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
- Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week
- Hugging Face CEO shares his demands of OpenAI after 'rogue' agent hack: 'It deserves an unprecedented response'
- CSA has another quick turnaround on a report with recommendations for this situation. Like the Mythos-ready report, I'm not a huge fan
- Another pointless "pause the AI" campaign popped up in response to this hack, called: Pacing the Frontier
- And another pointless corporate partnership to protect common interests, led by NVIDIA
- Another piece from Kayne, where he marvels that OpenAI's lab can just hack competitors and get away with it (apparently)
- PRIVACY: US accuses American of allegedly wiping his phone using a ‘duress’ password during border search
If privacy features become a crime...
- ESSAYS: Apple Is the King of AI and Nobody Knows It
This is a bold prediction, but makes a lot of sense. The author argues that, once free models became good enough for most of the common use cases (which arguably just happened over the past 2-3 months), the market power shifted from expensive GPUs to powerful endpoints that can run them locally.
- AI NEWS: AI Isn’t Coming for Your Job Yet – and Maybe Never Will
I have strong feelings about this one.
- REPORTS: LLMs Are Getting Smarter, But Not Safer: Veracode 2026 GenAI Code Security Report Finds AI-Generated Code Security Has Stalled at 56% Pass Rate
- REPORTS: VulnCheck State of Exploitation 1H-2026
- REPORTS: Ransomware Is Accelerating, but It’s Not Because of AI
- VULN MGMT: I don’t give a shit about CVEs
- SQUIRREL: Ads in 2026 – “Cybersecurity”
Nailed it.
