

OWASP LA September In Person Meetup - Mark Mazur
TOPIC: How to Build Secure Mobile Apps in the Age of AI Agentics and API attacks
ABSTRACT: The intersection of API Abuse and AI Agentic Attacks represents the bleeding edge of modern cybersecurity threats.
Traditional bots follow rigid scripts (e.g., brute-forcing a login). AI Agentic attackers, however, use Large Language Models (LLMs) and autonomous agents to dynamically adapt. If an AI agent hits a rate limit, it automatically rotates IPs. If it encounters an unexpected API response, it rewrites its own script to bypass the new logic. They are incredibly effective at scraping data, hoarding inventory, performing credential stuffing, and discovering business logic flaws at machine speed.
To defeat AI agents and sophisticated API abuse, you cannot rely on behavioral analysis alone (like Web Application Firewalls), because AI is getting too good at mimicking human behavior. Instead, you must rely on cryptographic proof of authenticity. more....
Thanks to our SPONSOR: Approov
SPEAKER BIO: Mark Mazur is an accomplished Chief Technology Officer and Field CTO with over 20 years of experience architecting and scaling enterprise, mobile, web, AI, and server software. He has a proven track record of driving technology strategy for high-growth startups and mature organizations across cybersecurity, fintech, ad-tech, messaging, and gaming.
Currently serving as the Field CTO at Approov Mobile Security, Mark specializes in mobile app security, API abuse prevention, and zero-trust bot protection. Previously, as CTO at Grow Credit Inc., he led a globally distributed, rapid Agile engineering team of 20+ engineers to deploy a containerized microservice platform and multiple partner integrations serving over 100K active users. Over his distinguished career, he has built robust MVPs, optimized infrastructure, and partnered with CEOs to create massive investor value for companies including TextPlus, Mobilityware, November Media, and NorthBay Solutions.
CODE OF CONDUCT
OWASP is committed to providing a welcoming and inclusive environment for everyone. Please review the OWASP Conference and Event Anti-Harassment Policy:
https://owasp.org/www-policy/operational/conferences-events.html#conference-and-event-anti-harassment-policy
Sponsorship Opportunities
Sponsorship opportunities are available for future OWASP Los Angeles events. Vendors interested in sponsoring may contact:
sponsorship.la@owasp.org