Issue 203: Optus data breach, API security guide, AuthN/AuthZ vulnerabilities
Brief
This week, the main news is coverage of the huge data breach affecting the Australian telecommunications company Optus, with APIs as a likely root cause. We also have articles on API security, authentication and authorization vulnerabilities, and how Docker REST API exposure can present risks.
Breach: APIs at the root of Optus data breach?
The big news over the last two weeks has been the data breach at the Australian telco Optus. At least 2. 1m Optus account holders had at least one form of ID exposed, with at least 150,000 passports and 50,000 Medicare numbers stolen. Although full details are unknown at the time of writing, initial reports indicate that unauthenticated API endpoints may have been at the root of the breach.
