New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

Kafdrop flaw allows data from Kafka clusters to be exposed Internet-wide

New York Tech Editorial Team by New York Tech Editorial Team
December 6, 2021
in Cybersecurity
0
Kafdrop flaw allows data from Kafka clusters to be exposed Internet-wide
Share on FacebookShare on Twitter

Researchers at Spectral discovered a security flaw in Kafdrop, a popular open-source UI and management interface for Apache Kafka clusters that has been downloaded more than 20 million times.

Kafdrop flaw

Kafdrop security flaw

Companies affected range from major global players to smaller organizations in healthcare, insurance, media, and IoT – basically anyone using Kafdrop with Apache Kafka, an open-source distributed event streaming platform, for high-performance data pipelines, streaming analytics, data integration, and mission-critical applications.

The Kafdrop flaw has allowed the data from Kafka clusters – everything from financial transactions to mission critical data – to be exposed Internet-wide by simply giving anyone a UI to make it easy to review live Kafka clusters, without authentication.

“We can’t name any of the companies whose clusters we discovered, as we don’t want to give threat actors the edge, but these flaws are exceptionally widespread,” said Dotan Nahum, CEO at Spectral. “Furthermore, since Kafka serves as a central data hub, threat actors with assistance from a flawed Kafdrop, can infiltrate and exfiltrate data and manage the cluster as they see fit. They can connect as a Kafka subscriber to cause further havoc across the entire network.”

Not only does the Kafdrop security flaw expose secrets in real-time traffic, but it also provides authentication tokens and other access details that allow hackers to reach the companies’ cloud providers, such as AWS, IBM, Oracle, and others, on which Kafka clusters are often deployed.

Kafdrop also provides insights into a cluster’s layout and topology, revealing hosts, topics, partitions, and consumers and enables sampling and download of live data as well as topic creation and removal.

“Misusing Kafdrop allows threat actors to access the nervous system of an entire company, revealing customer data, transactions, medical records, internal system traffic, etc. Immediate mitigation is critical,” said Nahum.

Addressing the Kafdrop flaw

Upon discovery of the flaw, Spectral immediately contributed an authentication code addition back into Kafdrop.

For companies who haven’t yet added the authentication code, they can address the Kafdrop flaw by either taking down their Kafdrop UIs or redeploying them behind an app server like Ngnix, using an active and configured authentication module.

Spectral recommends that in order for companies to protect themselves from such security mistakes leading to breaches, they should scan not only code, but also configuration, infrastructure and data horizontally across the complete SDLC.

Credit: Source link

Previous Post

“Get Your Free Omicron PCR test” is the latest Omicron phishing scam

Next Post

Watch Gang’s move to Cloud WMS

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Watch Gang’s move to Cloud WMS

Watch Gang’s move to Cloud WMS

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Clubhouse will soon let you pin links to the top of rooms

Clubhouse will soon let you pin links to the top of rooms

October 23, 2021
10 Raunchy Movies on Netflix You Won’t Regret Watching

10 Raunchy Movies on Netflix You Won’t Regret Watching

May 20, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
Inside the New York Team Building Across Social, Fintech and Gaming

Inside the New York Team Building Across Social, Fintech and Gaming

September 17, 2026
Asaf Wiener Challenges The Idea That Slowing AI Development Will Make Cybersecurity Safer

Asaf Wiener Challenges The Idea That Slowing AI Development Will Make Cybersecurity Safer

September 16, 2026
corporate practice of medicine

When Business Growth Starts to Influence Clinical Decisions

September 10, 2026
man using a computer

AI Is Easy to Try. Making It Work Is Harder.

September 9, 2026
Kesewi works to a two-word standard: think simple.

One Concept, One Yes: The Studio That Stopped Offering Options

September 8, 2026
FINQ’s Autonomous Ranking Engine Produces 23.51% and 23.83% Since Inception as the S&P 500 Returns 11.61%

FINQ’s Autonomous Ranking Engine Produces 23.51% and 23.83% Since Inception as the S&P 500 Returns 11.61%

September 7, 2026

Recommended

Inside the New York Team Building Across Social, Fintech and Gaming

Inside the New York Team Building Across Social, Fintech and Gaming

September 17, 2026
Asaf Wiener Challenges The Idea That Slowing AI Development Will Make Cybersecurity Safer

Asaf Wiener Challenges The Idea That Slowing AI Development Will Make Cybersecurity Safer

September 16, 2026
corporate practice of medicine

When Business Growth Starts to Influence Clinical Decisions

September 10, 2026
man using a computer

AI Is Easy to Try. Making It Work Is Harder.

September 9, 2026

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

AI AI QSRs AI security Allseated Automat-it AWS B2B marketing Business CISO CISO Whisperer Collaborations Companies To Watch Cybersecurity Enterprise AI Entrepreneur Fetcherr Finance FINQ Fintech Funding Announcement Hi Auto Impala Investing Investors investorsummit israelitech Leaders Mate Security Metaverse Mindset Minnesota omri hurwitz Perion PointFive PR QSR Real Estate start- up startupnation Startups Startups On Demand Tech Tech leaders Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media