Issue 230: OpenSea API breach, flaw in Atlas VPN, using API fuzzing
Brief
This week, we have news of a breach affecting users of the OpenSea NFR trading platform, requiring a key rotation; and disclosure of an API vulnerability in the Atlas VPN exposing user IP addresses. We also have an article from The New Stack on API fuzzing and its benefits and a guide on using Keycloak for RBAC in microservices.
Finally, Dana Epp makes it three issues in a row for a doubleheader of awesome guides, this time on prototype pollution and then AI testing in Postman.
Breach: OpenSea API users warned of breach
The popular NFT trading platform OpenSea has warned certain platform users to rotate their API keys. Although few details are provided in their official release, they suggest that one of their vendors may have experienced a security incident that led to the disclosure of OpenSea API keys.
