Frank Balonis, the company’s chief information security officer, confirmed the alert is strictly preventative. While the firm maintains that its current software, version 9.5.1, is free of known vulnerabilities, the warning specifically addresses the threat of previously unknown flaws. By advising a shutdown window throughout the weekend, Kiteworks intends to block attackers from gaining unauthorized access to sensitive datasets held by government, healthcare, and automotive clients.
Kiteworks Urges Customers to Offline Servers Over Imminent Attack Risk
Thousands of organizations using Kiteworks’ file-transfer platforms are facing an urgent security directive to disconnect their systems. The company issued the warning after receiving credible intelligence from law enforcement regarding a potential zero-day exploit, aimed at bypassing existing defenses before patches can be developed or deployed by the vendor.

Security researcher Kevin Beaumont identified at least a thousand internet-facing systems currently at risk. This proactive stance follows a significant history of security challenges for the company, formerly known as Accellion. In 2021, a series of exploits targeting their file-transfer tools allowed extortion gangs to siphon data from hundreds of organizations, leading to widespread ransom demands. Neither the FBI nor CISA has commented on the current intelligence, leaving the specific identity of the threat actors and the scope of the potential zero-day attack currently undisclosed.



Comments (0)
No comments yet. Be the first!