Kiteworks lifts shutdown advisory after ‘credible threat intelligence’ from federal authorities
Kiteworks resumed operations after patching a critical, previously unknown Advanced Forms vulnerability found during a weekend precautionary shutdown; no exploitation evidence.
Kiteworks told customers to resume normal operations after a weekend-long precautionary shutdown prompted by credible threat intelligence from federal authorities. During the shutdown it discovered and patched a previously unknown critical vulnerability in Advanced Forms, a data collection tool used by fewer than 1% of customers, roughly 50 organizations. Fixes are in release 9.5.1, continuous monitoring showed no abnormal activity, and the company says it has no indication the flaw was exploited. Kiteworks, formerly Accellion, rebranded after a legacy file transfer appliance flaw let an extortion gang breach hundreds of organizations.
- Precautionary weekend shutdown prompted by credible federal threat intelligence of an imminent attack
- Previously unknown critical vulnerability found in Advanced Forms, used by about 50 organizations
- Fix deployed in release 9.5.1; no evidence of exploitation
- Company shared threat intelligence with partners including Mandiant
Full article628 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The company said it found and patched a previously unknown critical vulnerability in one product during the weekend shutdown, and has no indication it was exploited.
Listen to this article
0:00
Learn more.
Kiteworks, a provider of secure file transfer and data-sharing tools, told customers Monday they could resume normal operations after a weekend-long precautionary shutdown prompted by what it called “credible threat intelligence” from federal authorities.
The recommendation, issued last week, advised customers to take production systems offline ahead of a potential imminent attack. The company also shut down the environments it hosts on customers’ behalf. By Sunday, Kiteworks said continuous monitoring showed no abnormal activity.
“Telling customers to take production systems offline is not a decision any vendor makes lightly, and we knew exactly what we were asking of them,” Chief Information Security Officer Frank Balonis said in the company’s statement. “We made it anyway, because when the choice is between certainty and convenience, customer data is not something we are willing to gamble with.”
During the shutdown, Kiteworks discovered a previously unknown critical vulnerability in Advanced Forms, a secure data collection tool used by fewer than 1% of its customers, a group the company said comprises approximately 50 organizations. The company said its other products, including file collaboration, file transfer, email encryption and managed file transfer, were unaffected.
Kiteworks said it developed and deployed a fix during the window and has no indication the vulnerability was ever exploited. All known vulnerabilities are addressed in release 9.5.1, which the company recommends customers run.
Company CEO Jonathan Yaron said in a release that being proactive about the threat was top of mind.
“Our customers gave up their weekend on our recommendation, at short notice and at difficult hours, and many of their teams worked through the night alongside ours,” Yaron said. “The industry standard is to wait for proof of an attack. We would rather be proactive on credible warning than wait for certainty and be too late. That is the standard we intend to keep.”
Kiteworks, a California-based company formerly known as Accellion, rebranded in October 2021 after a vulnerability in its legacy file transfer appliance allowed an extortion gang to breach hundreds of organizations. That campaign was part of a broader wave of attacks on file transfer products.
Kiteworks declined to identify which federal authorities provided the intelligence or which hacking group prompted the warning. The company said it worked with federal intelligence authorities throughout the weekend and shared threat intelligence with industry partners, including Mandiant.
Latest Podcasts
Government
Supreme Court permits states to use SAVE database for citizenship checks
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
New bill would create federal investigative body for AI-driven hacks
Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges
Technology
Threats
Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
Ryuk ransomware operator sentenced to 2 years in prison