Kiteworks Tells Customers to Shut Down Systems Amid Zero-Day Threat Warning
Software company Kiteworks has warned customers of a potential cyberattack, recommending they shut down their systems for a six-hour window over the weekend as a precaution. The warning, first reported by German outlet Heise, followed what Kiteworks CISO Frank Balonis described as credible threat intelligence from federal intelligence authorities indicating a threat actor may attempt to target Kiteworks systems.
Balonis said the company is not aware of any confirmed compromise and described the advisory as preventative rather than a response to an actual breach. He added that known vulnerabilities have been addressed in the current release, version 9.5.1, and urged customers to update. A Kiteworks support representative reportedly told Heise the warning was linked to a possible zero-day vulnerability, though the company has not confirmed this or responded to questions about a CVE identifier or who might be behind the threat.
Kiteworks, formerly known as Accellion, has a history with this type of incident: in 2020 the Russian hacking group Clop exploited a zero-day vulnerability in its file transfer tool to steal data from major organisations including a US university, a state auditor's office, and several large corporations. Security researchers say the unusual step of asking customers to power down servers entirely underscores the seriousness of the current threat.