API Security Escalates: Supply Chain Attacks, Starlette/FastAPI Vuln, AI-Powered Code Security
Key Questions
What recent supply chain attacks targeted AI developer tools?
Fake Claude Code installers via Google Ads stole API keys and crypto wallets, while a GitHub breach exposed 3,800 internal repos through a VS Code extension.
How are companies addressing API security for AI agents?
Salt Security released 100 pre-built policies for agentic AI governance, while Cyberhaven and others integrate compliance APIs from ChatGPT Enterprise and Claude.
What vulnerabilities affect popular AI frameworks?
A critical Starlette/FastAPI vulnerability impacts vLLM, LiteLLM, and many agent platforms, prompting urgent patching across the ecosystem.
How do partnerships enhance AI API security?
Harness and Kong expanded their partnership for automated AI discovery and gateway security, while Fastly collaborates with Experian for agent verification at the edge.
What frameworks help control API sprawl in AI environments?
Analyses show 45% of AI code introduces vulnerabilities and 10-20% shadow APIs, recommending SDLC-based governance and strict access scoping for non-human identities.
Critical API security flaw in reasoning models: weaker models can decode stronger models' encrypted reasoning from session logs, exposing API keys and secrets; cross-user replay attack on published agent logs. Weak API controls in agentic AI era highlighted with $2.3M wire fraud example; need for use-intent logging and deterministic execution boundaries. Other developments: Fastly/Experian Human to Agent Binding; Cyberhaven ChatGPT Enterprise/Claude Compliance; Harness/Kong partnership; Salt Security 100 policies; Tines 3B secure AI coding; Cequence Agentic Zero Trust; Harness agentic security with Google Cloud Apigee; new security framework for AI agents and MCP servers; Microsoft reduces NuGet API keys to 30 days; transparency logs for API authorization; leaked n8n API tokens; fake AI tools on GitHub; Google secure API access pilot; Cequence at NTT DOCOMO. Anthropic's Claude Code watermark easily bypassed by simple developer tools, highlighting fragility of AI output DRM. F5 launches Agentic-Ready AI Gateway with security and governance features. Non-human identity security guide for AI agents provides framework for ownership, least privilege, and lifecycle control.