Kiteworks: Shut Down Servers Over Imminent Cyber Threat — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Kiteworks is urging customers to shut down their servers before the weekend after receiving "credible threat intelligence from law enforcement" that a threat actor may attempt to target its systems, according to CISO Frank Balonis.
- Balonis said the advisory is preventative rather than a response to a confirmed breach, and that Kiteworks has fixed all known vulnerabilities in its latest software release, version 9.5.1.
- Kiteworks told customers in an email first reported by German publication Heise that it is concerned about exploitation of unknown zero-day flaws it has not had time to patch, recommending a shutdown window "to protect against any potential zero-day attacks."
- Kiteworks did not identify which law enforcement agency notified it or which hacking group may be behind the threat; the FBI and CISA did not respond to requests for comment.
- Kiteworks says it has thousands of customers across healthcare, technology, education, automotive, and government, and security researcher Kevin Beaumont identified at least 1,000 internet-facing Kiteworks systems online.
- Kiteworks, formerly known as Accellion, was previously hit through a vulnerability in its file-transfer application that allowed an extortion gang to mass-hack and steal data from hundreds of organizations.
Why it matters: At least 1,000 internet-facing Kiteworks systems serve thousands of customers across healthcare, government, and other sensitive sectors, all of which are being told to preemptively shut down over zero-day flaws Kiteworks cannot yet patch. The company's Accellion-era track record — a prior mass hack that stole data from hundreds of organizations — gives this weekend advisory a weight that goes well beyond a routine vulnerability bulletin.
Ask SkimNews




