Kiteworks Urges Customers to Restart Systems After Shutdown Notice
Kiteworks lifted a nine-hour precautionary shutdown order after federal intelligence warned of imminent threat actor targeting; no breach confirmed.
Managed file transfer vendor Kiteworks instructed self-hosted customers (on-premises or AWS/Azure) to shut down systems for nine hours on September 25 after receiving credible threat intelligence from federal authorities about possible targeting. On September 27 it cleared customers to bring systems back online, noting hosted systems were restored and no breach had been confirmed. Kiteworks CISO Frank Balonis said release 9.5.1 accounts for all known vulnerabilities; online speculation points to a possible zero-day, though MFT platforms like MOVEit, GoAnywhere, Cleo, and Accellion have historically attracted mass attacks.