Kiteworks Lifts Precautionary Shutdown Advisory After Patching Critical Vulnerability
American technology company Kiteworks has lifted a precautionary advisory asking customers to shut down their systems after patching a critical vulnerability.
Formerly known as Accellion, Kiteworks operates a private content network (PCN) that unifies corporate email, file sharing, managed file transfer (MFT), APIs, and web forms on a single platform.
Kiteworks serves thousands of global enterprises and government agencies. Its private data network has more than 100 million end users.
Kiteworks systems brought back online
On Saturday, the secure file-sharing software company asked customers around the world to temporarily shut down their servers after receiving a warning from federal intelligence officials about an impending cyberattack.
Kiteworks brought all hosted customer systems back online on Monday after finding no evidence of compromise or suspicious activity.
“Continued monitoring during the period has not shown any unusual activity, and the company has no indication that Kiteworks or its customers’ systems have been compromised,” Kiteworks said.
“As of September 27th, the shutdown recommendation has been lifted for all customers. If you have not already restarted, you can bring your Kiteworks systems back online,” the company added in an update to the original advisory.
Critical vulnerability patched
Kiteworks also patched a critical vulnerability in an unnamed feature used by less than 1% of its customers. The company advised customers using self-hosted Kiteworks Advanced Forms to contact support for assistance.
“While Kiteworks developed and deployed patches during the period and applied additional layers of protection to all environments, there is no evidence that the vulnerability was exploited. All other Kiteworks products were unaffected,” the company said.
Kiteworks has not shared additional details about the vulnerability and has not yet assigned it a CVE ID, which would make the issue easier to track.
About 400 Kiteworks instances exposed online
Monitoring by the Shadowserver Foundation found approximately 400 Kiteworks instances accessible via the internet.
Most of the exposed instances—234—were located in the United States. However, Shadowserver did not provide information about how many were honeypots or whether the systems had already been patched.

File-sharing platforms remain attractive targets
Cybercriminal organizations often target vulnerable file-sharing platforms for data theft because they store sensitive documents.
For example, the Clop extortion gang has a long history of exploiting vulnerabilities in enterprise file-sharing platforms. When the company was still known as Accellion, Clop targeted its legacy Kiteworks File Transfer Appliance (FTA) software in zero-day attacks.
Accellion said at the time that 300 customers were using the 20-year-old legacy FTA software. Fewer than 100 were compromised, and fewer than 20 were believed to have “suffered significant data theft.”
Clop’s hacking campaign triggered a series of data breaches affecting high-profile organizations that used Accellion FTA to transfer sensitive files. Those organizations included cybersecurity firm Qualys, energy giant Shell, the Reserve Bank of New Zealand, supermarket giant Kroger, Singtel, the Australian Securities and Investments Commission (ASIC), the WA State Audit Office, and several universities.
Five Eyes members issued a joint security advisory about the attacks and subsequent extortion attempts in February 2021. The advisory warned Accellion customers to block internet access to vulnerable servers and update their systems to prevent the attacks.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



