OWASP Los Angeles Meetup Explores AI Agents in Mobile App and API Security

OWASP Los Angeles Meetup- How AI Agents Are Changing Mobile App and API Security
🕧 5 min

Explores Sustaining Defenses Against Recursive Self-Improvement (RSI) Agentic Attacks Such As Automated Scraping, API Stuffing, Inventory Hoarding and More.

As AI-powered agents become increasingly capable of adapting their behavior in real time, many current tactics used by app publishers and developers to defend mobile applications and APIs are becoming less effective or obsolete.

Also Read: IT Tech Pulse Exclusive Interview with Michael Jack Chief Revenue Officer and Co-Founder of Datadobi

The fundamental security question is shifting from simply asking whether traffic looks human to establishing whether the application making the request can be trusted. Too many organizations still rely on tactics that worked against circa 2025 threats

The OWASP Los Angeles chapter will bring cybersecurity and technology professionals together September 23, 2026, for an in-person examination of how organizations can secure their most popular connection to customers – their mobile apps – against increasingly sophisticated attacks and AI-driven automation.

Sponsored by Approov Limited, the meetup will feature Mark Mazur, Field CTO at Approov, presenting “How to Build Secure Mobile Apps in the Age of AI Agentics and API Attacks.” The event will take place from 5:30 to 8:30 p.m. PDT at 929 Colorado Ave. in Santa Monica, California.

AI agentic threats have raised the stakes for API security

Until recently, automated attacks typically ran on rigid scripts and depended on predictable behavior. AI-agentic attackers introduce a different challenge: the exploit’s ability to dynamically adapt their tactics without human oversight as they encounter defenses, and change how they interact with an application or API attack sequence. This autonomous evolution is referred to as a recursive self-improvement (RSI) attack.

These RSI attacks increase an organization’s susceptibility to data scraping, credential stuffing, inventory hoarding , and the discovery and exploitation of business logic vulnerabilities.

Moreover, as RSI threats mimic and become more indistinguishable from legitimate users, the effectiveness of behavioral detection defenses is declining.

Also Read: IT Tech Pulse Exclusive Interview with Ken Claffey Chief Executive Officer and President of VDURA

Mazur said: “The fundamental security question is shifting from simply asking whether traffic looks human to establishing whether the application making the request can be trusted. AI-driven automation is making behavioral defenses increasingly difficult to rely on by themselves. Too many organizations are still relying on tactics that worked against circa 2025 threats.”

Mazur will also share defenses such as cryptographic proof of authenticity and application-level trust in defending mobile apps and APIs against sophisticated automated abuse.

He has more than 20 years of experience architecting and scaling enterprise, mobile, web, AI and server software across cybersecurity, fintech, ad-tech, messaging and gaming.

Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.

  • Business Wire has been synonymous with well-known press release distribution for more than half a century. Owned by Berkshire Hathaway, it combines regulatory compliance expertise with a powerful media network, helping enterprises large and small share news that influences markets and decision-makers alike.

Recommended Reads :