Over 1.3M Services Exposed on Kafka's Default Port, Only 9,112 Fingerprinted as Kafka
A cybersecurity analysis conducted on 23 September 2026 using ZoomEye revealed a stark gap between two measurements of Apache Kafka's internet-facing presence: 9,112 assets matched a Kafka-specific fingerprint, while 1,377,501 services were found listening on port 9092, Kafka's default broker port. The disparity exists because the fingerprint query identifies confirmed Kafka deployments, whereas the port query captures all services on that port regardless of product. Researchers warn that neither figure reveals whether authentication or authorization is enforced, meaning a secured and an unsecured cluster appear identical from the outside. Unauthenticated Kafka brokers can expose sensitive event payloads — including personal data, internal service names, and credentials — to anyone able to connect. Security teams are advised to restrict broker port access to trusted applications, enforce authentication at the broker level, and enable audit logging to support post-incident investigation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in