US healthcare organizations are being warned of cyber-attack risks linked to older flaws in Apache Tomcat, which hosts electronic health records and many other systems. The vulnerabilities are regularly exploited but often overlooked, creating ongoing risk. Known issues include remote code execution, denial of service, and insecure deserialization. The healthcare sector is heavily dependent on Apache Tomcat which means it has become a prime target for cybercriminals.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.