Kiteworks Advises Customers to Shut Down Systems Amid Federal Cyberattack Warning

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Software company Kiteworks has issued a warning to its customers, advising them to shut down the company’s platform over the weekend due to concerns about potential cyberattacks. The advisory, first reported by German news outlet Heise, recommends a six-hour shutdown window on Saturday.

Frank Balonis, the Chief Information Security Officer at Kiteworks, stated that the company received credible threat intelligence from federal authorities indicating that a threat actor may attempt to target some Kiteworks systems. “Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter,” Balonis said.

He emphasized that there is currently no evidence of a compromise of Kiteworks systems, and the advisory is preventative rather than a response to a confirmed breach. All known vulnerabilities have been addressed in the latest software release, version 9.5.1, and customers are encouraged to run this version.

Kiteworks has not provided further details regarding whether the potential vulnerability has a Common Vulnerabilities and Exposures (CVE) identifier or which groups might be exploiting the platform. The company is known for its software that facilitates secure communication.

The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) have not commented on the situation. A Kiteworks customer support official mentioned that the email was sent out due to a potential “zero-day” vulnerability but did not elaborate further.

Kiteworks, previously known as Accellion, has a history of security incidents, including a significant breach in December 2020 when the Russian hacking group Clop exploited a zero-day vulnerability to steal data from numerous high-profile organizations, including the University of Colorado and Kroger.

Jake Knott, a senior official at cybersecurity firm watchTowr, expressed concern over Kiteworks’ recommendation for customers to shut down their servers, noting the unusual nature of such a request without a known CVE or patch. “Nobody requests that their entire customer base unplug production systems over the weekend because of a hunch,” he remarked, highlighting the ongoing risks associated with managed file transfer appliances.

For more details, see the full report by The Record.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CWME_REVIEW_REQUIRED

In mid-September 2026, Hurricane Polo began as a tropical disturbance off the Pacific coast of Mexico. By September 20, it had organized enough to...

Australia Investigates OpenAI After AI Agent Hacks Health Statistics Portal

Australia is investigating whether OpenAI broke the law after an agent hacked into its health statistics portal, marking the first widely known incident of...

Google Cloud Outlines Strategies for Hardening Code Pipelines and CI/CD Infrastructure

Strengthening Code Pipelines and CI/CD Infrastructure: Insights from Google Cloud As organizations increasingly rely on automated code pipelines and Continuous Integration/Continuous Deployment (CI/CD) systems, the...

AWS Enhances Security Against Exposed IAM Credentials with Updated Compromised Key Quarantine Policy

AWS has enhanced its security measures to mitigate risks associated with exposed Identity and Access Management (IAM) access keys through the updated AWSCompromisedKeyQuarantine managed...