Kiteworks Urges Customers to Shut Down Servers for 6 Hours Amid Potential Cyberattack
Secure file-sharing software provider Kiteworks is urging customers worldwide to temporarily shut down their servers for six hours on Saturday after receiving a threat intelligence alert about a possible impending cyberattack.
According to the German technical publication Heise, Kiteworks CISO Frank Balonis sent customers an email warning that the company had “received credible threat information from law enforcement indicating that an attack on Kiteworks’ systems may be imminent this weekend.”
“We strongly recommend that you shut down your Kiteworks system for 6 hours,” the notice reportedly states.
Kiteworks recommends a worldwide six-hour shutdown
Heise reported that the recommended shutdown period applies to customers worldwide, covering time zones from Australian Eastern Standard Time (AEST) to Pacific Daylight Time (PDT).
In Central Europe, customers were instructed to shut down their Kiteworks systems from 4 a.m. to 10 a.m. on Saturday, September 26. In New York, the recommended shutdown period runs from 10 p.m. Friday to 4 a.m. Saturday.
Kiteworks reportedly recommends taking servers offline before the scheduled period begins. The company also advises customers to shut down their systems even if they cannot be accessed directly from the internet.
Kiteworks confirmed the warning to BleepingComputer, saying it had received information from federal authorities that threat actors may be attempting to target some customer systems.
“Kiteworks has received credible threat intelligence from federal intelligence officials indicating that threat actors may be attempting to target some of our customers’ Kiteworks systems,” the company told BleepingComputer.
“Out of an abundance of caution, we have notified our customers directly and recommended a precautionary shutdown period while we and our law enforcement partners address this issue.”
No confirmed breach, Kiteworks says
Kiteworks emphasized that the warning is preventive and does not follow a confirmed breach.
“We are not aware of any breaches of Kiteworks systems and this advisory is preventive rather than in response to a confirmed breach,” the company said.
“All known vulnerabilities have been resolved in the current release, 9.5.1, and we recommend that customers continue to run the latest version.”
Potential zero-day attack concerns
Although Kiteworks has not confirmed that attackers are exploiting an unknown vulnerability, Heise reported that Kiteworks customer support described the shutdown recommendation as a measure to protect customers from potential zero-day attacks.
“We are asking you to shut down your servers to protect against potential zero-day attacks,” Kiteworks support told Heise when the publication contacted the company about the warning.
However, neither the statement provided to BleepingComputer nor the customer notification cited by Heise confirms that a zero-day vulnerability has been discovered or exploited.
Instead, Kiteworks said all currently known vulnerabilities have been fixed in version 9.5.1 and described the shutdown as a precautionary measure based on information received from authorities.
Why Kiteworks customers may be targeted
Kiteworks develops secure file transfer and communications products used by government agencies, financial institutions, and businesses.
Secure file-sharing platforms often store sensitive documents, making them valuable targets for cybercriminals conducting extortion attacks through data theft.
Although the actors involved in the potential attacks have not been identified, the Clop extortion gang has a long history of targeting enterprise platforms, including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, in data theft attacks.
The US State Department is currently offering a $10 million reward for information linking attacks by cybercrime organizations to foreign governments.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



