Protect.Computer
NEWS

Kiteworks Patches Critical Flaw After Precautionary Shutdown

· 1 min read · Got hacked Data hijack
Kiteworks Patches Critical Flaw After Precautionary Shutdown

Kiteworks, the secure file-sharing vendor formerly known as Accellion, has lifted a precautionary advisory that asked customers worldwide to temporarily shut down their servers. The request went out on Saturday after federal intelligence authorities warned of a potentially imminent cyberattack. By Monday the company had brought all hosted customer systems back online, saying continuous monitoring showed no abnormal activity and that it has no indication any Kiteworks or customer system was compromised. As of September 27 the shutdown recommendation is lifted for all customers.

During the window, Kiteworks developed and deployed a fix for a critical vulnerability in an unnamed feature used by less than 1% of customers, and added an extra protective layer across all environments. The company says it has no indication the flaw was ever exploited and that all other products were unaffected. It has not shared technical details or assigned a CVE. The stakes explain the caution: file-sharing platforms hold sensitive documents and are frequent targets of data-theft extortion, and the Clop gang previously exploited Accellion’s legacy File Transfer Appliance in zero-day attacks that hit dozens of organizations. Shadowserver counts nearly 400 internet-exposed Kiteworks instances (234 in the US), though it cannot say how many are honeypots or already patched.

How to check if you’re affected

Affected products are limited to self-hosted deployments of Kiteworks Advanced Forms; Kiteworks says customers on that product should contact support for assistance, while hosted customers were handled by the vendor. If you run a self-hosted Kiteworks system, confirm which version you are on and that the vendor’s fix and additional protection are applied, and confirm with support whether Advanced Forms is enabled on your instance. Because no CVE or technical indicators have been published, review access and audit logs around September 26 to 27 for unusual activity and keep the system off the open internet where possible.

Sources

Related reading