Description

Kiteworks temporarily urged customers to shut down their systems after receiving credible threat intelligence from federal authorities indicating that a threat actor may attempt to target some Kiteworks environments. The advisory was precautionary, with no confirmed compromise reported. Kiteworks has since lifted the shutdown recommendation and restored hosted environments. The warning centered on potential attack paths involving vulnerabilities that were not yet known to Kiteworks, meaning existing security controls or available patches could not necessarily address them. The company did not disclose a specific vulnerability, CVE identifier, exploitation method, or threat actor. Customers operating self-managed Kiteworks environments including on-premises deployments and installations hosted in AWS or Microsoft Azure were instructed to participate in a coordinated temporary shutdown. Kiteworks-hosted environments were handled by the company itself. Kiteworks stated that all known vulnerabilities had been addressed in release 9.5.1 and recommended customers remain on that version. The company emphasized that there was no evidence of compromise and described the shutdown as a preventive measure while it worked with federal authorities. The shutdown recommendation was subsequently lifted on September 27, allowing affected customers to bring systems back online.