Issue 289: SolarWinds RCE, Supply-Chain API Exposure, SQL Injection, and Identity for APIs in the Age of Agentic AI
Brief
This week, we look at how familiar API security failures — authentication bypasses, missing input validation allowing old school attacks like SQL injections — continue to surface across enterprise platforms and critical infrastructure.
From exposed supply-chain APIs to identity-layer weaknesses and unauthenticated RCEs, the pattern is clear: basic API controls still break in production.
We also explore the new identity challenges that emerge with API infrastructures being increasingly consumed by agentic AI ecosystems and how evolving identity standards aim to bring stronger, transaction-scoped controls to answer these challenges.
Lastly, yours truly, is co-presenting a webinar on the hot topic of securing Agentic AI with Omdia’s Chief Analyst, Rik Turner. I hope to see you there.
