The Apache Software Foundation (ASF) has addressed a vulnerability in Kafka Connect that could enable remote code execution (RCE) attacks. The flaw was spotted by bug bounty hunter Jari Jääskelä, who received a $5,000 reward. To exploit the vulnerability, an attacker would need access to a Kafka Connect worker and be able to create or modify worker connectors. More than 80% of Fortune 100 firms use the Kafka platform.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.