Kiteworks Restores Service After Precautionary Shutdown Uncovers Critical Flaw
Kiteworks, a provider of secure file transfer and data-sharing tools, has told customers they can resume normal operations after taking systems offline over the weekend in response to what it described as "credible threat intelligence" from federal authorities. The company said continuous monitoring found no signs of abnormal activity by Sunday.
During the shutdown, Kiteworks discovered a previously unknown critical vulnerability in Advanced Forms, a secure data collection tool used by fewer than 1% of its customers (around 50 organisations). Its other products, including file collaboration, file transfer, email encryption and managed file transfer, were not affected. The company said it developed and deployed a fix during the shutdown window and has seen no evidence the flaw was exploited. All known issues are addressed in release 9.5.1, which Kiteworks recommends customers update to.
Company leaders said the decision to ask customers to take production systems offline was not made lightly, but reflected a preference for acting on credible warnings rather than waiting for proof of an attack. Kiteworks, formerly known as Accellion, rebranded in 2021 after a vulnerability in its legacy file transfer appliance was exploited by an extortion gang in a wave of attacks on file transfer products.