Kiteworks Warned Customers to Shut Down Servers Over Potential Zero-Day Attack
Kiteworks told self-managed customers to shut down servers over a possible zero-day, then lifted the warning.
On September 25, 2026, Kiteworks warned customers after federal authorities shared intelligence about a possible imminent attack and asked self-managed on-premises, AWS, and Azure deployments to go offline temporarily. The company called the step preventative, said it had no evidence of compromise, and stated that known vulnerabilities were addressed in version 9.5.1. It did not name an actor or attack path, though Heise reported support staff described protection against possible zero-days. On September 27 Kiteworks lifted the shutdown recommendation, restored hosted systems, and said subsidiaries including Zivver, DRACOON, and ownCloud were unaffected.
- Preventative shutdown followed federal intelligence about a possible attack
- Kiteworks reported no evidence of compromise
- Self-managed on-premises, AWS, and Azure deployments were covered
- Shutdown advice was lifted on September 27, 2026
- Customers were urged to run version 9.5.1
Full article594 words · extracted from cybersecuritynews.com · click to collapse
Kiteworks warned customers to temporarily shut down their servers after receiving credible threat intelligence that a threat actor could target some Kiteworks systems.
The company said the measure was preventative, stressed that it had no evidence of a compromise, and later lifted the shutdown recommendation for all customers.
The San Mateo, California-based secure data exchange provider issued the advisory on September 25 after federal intelligence authorities shared information about a possible imminent cyberattack.
Kiteworks asked organizations running self-managed deployments to take their systems offline during a precautionary shutdown window in their local time zones. The warning applied to Kiteworks systems deployed on premises and in customer-managed AWS and Microsoft Azure environments.
Kiteworks said it would shut down and later restore systems it hosts for customers, meaning hosted customers did not need to take action during the planned window.
Kiteworks Warns Customers Over Zero-Day Attack
Frank Balonis, Kiteworks chief information security officer, said the company received intelligence indicating that a threat actor may attempt to target certain Kiteworks customer systems.
He said the organization notified customers directly and coordinated with federal authorities while reviewing the threat. Kiteworks did not disclose the suspected attack path, the threat actor behind the activity, or the intelligence source.
However, reporting from Heise indicated that Kiteworks support staff described the action as a protective step against possible zero-day attacks.
A zero-day flaw is a previously unknown vulnerability for which a vendor may not yet have a patch or public mitigation. The company emphasized that the shutdown notice did not follow a confirmed breach.
Kiteworks said it did not indicate that its own infrastructure or customer environments had been compromised. It also said it had addressed all known vulnerabilities in its current release, version 9.5.1. It urged custom to ensure they were running that version.
The incident highlights the difficult decisions software vendors and enterprise defenders face when threat intelligence points to a credible but unconfirmed risk.
In many cases, a temporary outage can be less damaging than allowing attackers time to exploit an unknown weakness in systems that handle sensitive data transfers, managed file transfer workflows, email, and enterprise collaboration.
Enterprises and government organizations use Kiteworks products to manage sensitive data exchanges. The platform is designed to control, track, and protect private information moving between users, business partners, cloud services, and internal environments.
Because such systems can handle large volumes of confidential files, they can be attractive targets for ransomware groups, data-extortion operations, and espionage actors.
Kiteworks updated its advisory on September 27 and said customers could bring their systems back online if they had not already restarted them.
The company said it had restored all Kiteworks-hosted systems, and they were operating normally. Customers using self-hosted Advanced Forms were instructed to contact technical support for assistance before or during restoration.
The company also clarified that the threat did not affect its other subsidiaries, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder.
For security teams, the event reinforces the need to maintain vendor software at supported releases, monitor vendor advisories closely, document shutdown and recovery procedures, and preserve logs for post-event review.
Even when no compromise is confirmed, organizations should check for unusual authentication activity, unexpected administrative changes, suspicious file transfers, and network connections involving affected systems.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.