API Security Escalates: Supply Chain Attacks, Starlette/FastAPI Vuln, AI-Powered Code Security
Key Questions
What recent supply chain attacks target AI coding tools and API keys?
Fake Claude Code installers via Google Ads steal API keys and crypto wallets, while a GitHub breach exposed 3,800 internal repos through a VS Code extension.
How are vendors addressing AI agent security and governance?
Anthropic's Claude Security beta with IBM found 10k flaws, Salt Security released 100 pre-built policies for agentic AI including MCP servers, and Opal Security raised $23M for access governance.
What vulnerabilities affect popular AI frameworks like Starlette and FastAPI?
A critical Starlette/FastAPI vulnerability impacts vLLM, LiteLLM, and agent platforms, prompting renewed focus on rate limiting, short-lived tokens, and gateway-level enforcement for AI agents.
Fake Claude Code installers via Google Ads steal API keys and crypto wallets, targeting Cline/Continue.dev secrets. GitHub breach of 3,800 internal repos via VS Code extension. Critical Starlette/FastAPI vulnerability affects vLLM, LiteLLM, agent platforms. Anthropic launches Claude Security public beta (Project Glasswing) with IBM, finding 10k flaws. 42Crunch AI coding plugins for automated DevSecOps. Rate limiting patterns for AI agents gain attention. WSO2 ThunderID and Agent Fabric for non-human identity governance. New patterns for securing AI agents on Kubernetes emerge, emphasizing short-lived tokens and gateway-level enforcement. Practical guidance on virtual keys and budget limits for AI coding tools emerges. Opal Security raises $23M for AI-native access governance, with Databricks managing 86k just-in-time requests through the platform. A new article argues that focusing only on prompts and guardrails misses the real attack surface—APIs, reinforcing the need for API visibility as the ultimate defense for AI agents. New: Curity launches centralized API access control layer for services, partners, and AI agents, reinforcing API security consolidation. Token intelligence for fine-grained access management emerges as a key pattern for enterprise API governance. Latest: TrendAI integrates Claude Compliance API for centralized AI security; Kong+Noma partnership for advanced agentic AI security and runtime. CrowdStrike's open gateway ecosystem extends security via partner integrations, reinforcing API-first security in AI agent ecosystems. New signals: a video argues that API gateways miss real development risks; Cycode and CrowdStrike partner to govern AI tools in developer environments, addressing unauthorized MCP access and poisoned rule files. New: Salt Security introduces 100 pre-built policies for agentic AI governance, targeting MCP server configs and agent authorization, a concrete tool for enterprise agent security.