Kiteworks patches critical flaw, brings customer systems online
Kiteworks patched a critical flaw and lifted a global shutdown advisory after finding no compromise.
Kiteworks, formerly Accellion, told customers on Saturday to shut down servers after a federal intelligence warning of a potentially imminent cyberattack. It later restored hosted systems, reported no abnormal activity or compromise, and lifted the shutdown recommendation as of September 27. The company patched a critical flaw in an unnamed feature used by less than 1% of customers, including self-hosted Advanced Forms, and said it has no indication of exploitation and has not assigned a CVE. Shadowserver observed nearly 400 internet-exposed instances, 234 in the United States; Clop previously exploited legacy Accellion FTA in 2021.
- Federal intelligence warned of a potentially imminent attack, prompting a weekend shutdown.
- Kiteworks found no compromise and lifted the shutdown as of September 27.
- Patched critical flaw is in a feature used by under 1% of customers.
- No CVE assigned; Shadowserver sees nearly 400 exposed instances, 234 in the US.
- Clop previously exploited legacy Accellion FTA in 2021 zero-day extortion.
Full article550 words · extracted from bleepingcomputer.com · click to collapse

American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability.
Formerly known as Accellion, it operates a Private Content Network (PCN) that integrates enterprise email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform.
Kiteworks provides services to thousands of global corporations and government agencies, and its Private Data Network has over 100 million end-users.
The secure file-sharing software company urged customers worldwide on Saturday to temporarily shut down their servers after receiving a warning of a potentially imminent cyberattack from federal intelligence authorities.
On Monday, the company brought all hosted customer systems back online after finding no evidence of compromise and no suspicious activity.
"Continuous monitoring throughout the period showed no abnormal activity, and the company has no indication that any Kiteworks or customer system was compromised," Kiteworks said.
"As of September 27th, the shutdown recommendation is now lifted for all customers. If you have not already restarted, you may bring your Kiteworks system back online," the company added in an update to the original advisory.
Kiteworks has also patched a critical vulnerability in an unnamed feature used by less than 1% of all customers and advised those with self-hosted Kiteworks Advanced Forms to contact support for further assistance.
"Kiteworks developed and deployed a fix during the window, applied an additional protective layer across all environments, and has no indication the vulnerability was ever exploited. All other Kiteworks products were unaffected," it noted.
The company has yet to share additional details on the fixed vulnerability and has not yet assigned a CVE ID for easy tracking.
Threat watchdog Shadowserver has spotted nearly 400 Kiteworks instances accessible over the Internet, most of them (234) from the United States, but provides no information on how many are honeypots or have already been patched.

Because they store sensitive documents, cybercrime gangs often target vulnerable file-sharing platforms in data-theft extortion attacks.
For instance, the Clop extortion gang, which has a long history of exploiting vulnerabilities in enterprise file-sharing platforms, also targeted a legacy Kiteworks File Transfer Appliance (FTA) software in zero-day attacks when the company was still known as Accellion.
Accellion said at the time that 300 customers used the 20-year-old legacy FTA software, with fewer than 100 of them breached and fewer than two dozen victims appeared "to have suffered significant data theft."
That Clop hacking campaign led to a stream of data breaches impacting many high-profile entities that used the Accellion FTA software to transfer sensitive files, including cybersecurity firm Qualys, energy giant Shell, the Reserve Bank of New Zealand, supermarket giant Kroger, Singtel, the Australian Securities and Investments Commission (ASIC), the Office of the Washington State Auditor, and multiple universities.
Five Eyes members also issued a joint security advisory in February 2021 about these attacks and subsequent extortion attempts, warning Accellion customers to block Internet access to vulnerable servers and update them to block the attacks.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.