Back
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
SiTech AI Team2 წთ. საკითხავი

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks, the American software vendor formerly known as Accellion, asked customers to shut down their systems for a precautionary nine-hour window after federal intelligence authorities warned of a possible cyber attack.

Kiteworks, the American file-transfer software vendor formerly known as Accellion, has asked customers to shut down their systems for a precautionary nine-hour window over the weekend after receiving threat intelligence about a possible imminent cyber attack.

What the company said

"Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief Information Security Officer (CISO) at Kiteworks. He added that the company notified customers directly and recommended the shutdown window "out of an abundance of caution", while it continues to work through the matter with federal intelligence authorities.

The company said it has found no evidence that customer systems were compromised, stressing that the advisory is preventative rather than a response to a confirmed hack. Kiteworks did not disclose which agency passed on the intelligence, or who may be behind a potential attack. The development was first reported by the German news outlet Heise.

Patches and subsidiaries

According to the company, all known vulnerabilities have been addressed in its latest software release, version 9.5.1, and customers are advised to apply the patches. Kiteworks also sent an email to all customers detailing the specific hours of the recommended nine-hour timeframe. Other Kiteworks subsidiaries, among them Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai and 123FormBuilder, are not affected.

Why the warning draws attention

The advisory lands on a company with a difficult history in enterprise file transfer. In late 2020 and early 2021, the Clop extortion group, also tracked as UNC2546, exploited multiple zero-day vulnerabilities in Accellion's file transfer program in a data theft and extortion campaign that targeted high-profile entities. Kiteworks is the former Accellion.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.