Kiteworks took the extraordinary step of asking customers to shut down their systems over the weekend after it had received a warning of potential exploitation.
“Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems,” Frank Balonis, chief information security officer at the data security firm, said on 25 September.
“Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we continue to work through the matter with federal intelligence authorities. We have no indication that Kiteworks or our customers’ systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach. Kiteworks has accounted for all known vulnerabilities in our current release, 9.5.1, and we continue to recommend customers run the latest version.”
An addendum to the warning said it was safe for customers to bring their Kiteworks systems back online as of 27 September.
“Customers with self-hosted advanced forms should contact customer support for assistance,” the company said.
“All systems Kiteworks hosts on customers’ behalf have been brought back up and are operating normally.”
Jake Knott, head of threat intelligence at cyber security firm watchTowr, said the shutdown order was “both unusual and never a good sign, especially when the remediation is the power button”.
“There is no known CVE, patch or additional technical details available – but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch,” Knott told Cyber Daily.
Knott did note, however, that Kiteworks, when it operated as Accellion, is no stranger to malicious activity targeting its platforms.
“Its File Transfer Appliance was a prime target for ransomware gangs and earned multiple entries on CISA’s Known Exploited Vulnerabilities list,” Knott said.
“Whilst years have passed and the name has changed, attackers’ appetites for targeting MFT appliances have not, and we have no reason to believe this time will be any different. In other words, this is familiar territory, but not the comforting kind.”
Knott said customers should always take such directions from any vendor seriously, but that the shutdown does raise more than a few questions: “Like what is the vulnerability, what specifically does it impact, how is it exploited, and has ‘turn it off and leave it off’ officially become a security control?
“watchTowr is actively monitoring for signs of in-the-wild exploitation across our global sensor network, though we suspect the significant publicity is likely to push attackers back underground for now.”
Kiteworks’ customers include Honda, the Queensland Treasury Corporation, and the NSW Department of Planning, Industry, and Government. The company has more than 3,800 enterprise-grade customers globally.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.