Blogs by Mark Mazur
Mark Mazur
Field CTO of Approov
Mark Mazur is an accomplished Chief Technology Officer and Field CTO with over 20 years of experience architecting and scaling enterprise, mobile, web, AI, and server software. He has a proven track record of driving technology strategy for high-growth startups and mature organizations across cybersecurity, fintech, ad-tech, messaging, and gaming. Currently serving as the Field CTO at Approov Mobile Security, Mark specializes in mobile app security, API abuse prevention, and zero-trust bot protection. Previously, as CTO at Grow Credit Inc., he led a globally distributed, rapid Agile engineering team of 20+ engineers to deploy a containerized microservice platform and multiple partner integrations serving over 100K active users. Over his distinguished career, he has built robust MVPs, optimized infrastructure, and partnered with CEOs to create massive investor value for companies including TextPlus, Mobilityware, November Media, and NorthBay Solutions.
Posts on
- Mobile API Security (202)
- Mobile App Authentication (93)
- Mobile App Development (85)
- Mobile App Security (82)
- Mobile Security (75)
- Threats (74)
- API Abuse (64)
- Integration (56)
- API Keys (53)
- MitM (49)
- Bots (43)
- Business (38)
- Certificate Pinning (35)
- Reverse Engineering (31)
- App Attestation (30)
- Quickstart (26)
- Backend (25)
- Android Security (24)
- TLS (22)
- Repackaged Apps (20)
- Mobile Finance (19)
- Scrapers (18)
- iOS (18)
- RASP (15)
- Connected Car (14)
- Zero Trust (13)
- Mobile Health (12)
- Gaming and Gambling (11)
- News (10)
- Run-time Secrets Protection (10)
- ReactNative (9)
- Third Party APIs (8)
- Fake Accounts (7)
- Huawei (7)
- Retail (7)
- API Gateway (6)
- Account Hijacking (6)
- Apple (6)
- Compliance & Privacy (6)
- Zero Secret (6)
- Code Obfuscation (5)
- Cybersecurity (5)
- Google (5)
- OAuth2 (5)
- Reverse Proxy (5)
- Agentic AI (4)
- App Store (4)
- Cloud (4)
- Cross-Platform (4)
- OWASP (4)
- Runtime Application Self-Protection (4)
- Web Security (4)
- Aggregators (3)
- Data Security (3)
- E-Commerce (3)
- Mobile App Distribution (3)
- Mobile Banking (3)
- SafetyNet (3)
- Token-Based API Access (3)
- gRPC (3)
- Frida (2)
- Frontend (2)
- Mobile Payment Security (2)
- Pentesting (2)
- SDLC (2)
- AI Scraping (1)
- App Shielding (1)
- CNIL (1)
- Credential Stuffing (1)
- DeviceCheck (1)
- Google Play (1)
- Government (1)
- Runtime Secrets Protection (1)
- SDK (1)
- Supply-chain (1)
Popular Posts
- Limitations of Google Play Integrity API vs. Approov Mobile Security
- Revealing the Limitations of Apple DeviceCheck and Apple App Attest
- How to Bypass Certificate Pinning with Frida on an Android App
- Securing APIs with Approov and Cloudflare: A Comprehensive Guide
- How to Extract an API Key from a Mobile App by Static Binary Analysis
- Are You Human, Robot or Just Impatient?
- MitM Attacks on Android Apps: A Step-by-Step Guide Using Emulators
- Bypassing Certificate Pinning
- 5 Threats to Mobile Games and 5 Essential Security Measures
- Secure Your Mobile App from Geo-Spoofing with Robust API Integration
- Three Actions You Should Take Right Now to Stop Mobile MitM Attacks
- Limitations of Hardware-Backed Key Attestation in Mobile Security
- Limitations of Huawei HarmonyOS Safety Detect: What You Need to Know
- How to Ride the Bus for Free (Hackers Need Not Apply)
- How to Prevent Credential Stuffing Attacks on Mobile Apps
