Kiteworks urges temporary server shutdown after attack warning
Kiteworks told customers to take servers offline after authorities warned of possible targeting, with no compromise confirmed.
Kiteworks, formerly Accellion, told customers worldwide to shut down file-transfer servers after authorities warned that a threat actor may target some deployments over the weekend of September 26. Sources differ on the warning and the duration: TechCrunch and GBHackers cited law enforcement, while The Record, BleepingComputer, and The Hacker News cited federal intelligence or federal authorities; most described a six-hour window that BleepingComputer placed at 4:00 a.m. to 10:00 a.m. Central Europe and GBHackers at 02:00 to 08:00 UTC, including systems not exposed to the internet, but The Hacker News said nine hours. CISO Frank Balonis said the company knows of no compromise and called the step preventative, and known bugs are said to be fixed in release 9.5.1, with no CVE, actor, technique, or exploiting group named. Communications cited a possible unknown zero-day, including a support official who told Heise the warning involved a potential zero-day, though BleepingComputer reported that neither the company nor the quoted notice confirmed a zero-day or exploitation. The Hacker News added that subsidiaries including Zivver, DRACOON, and ownCloud are unaffected; Kevin Beaumont noted at least a thousand internet-facing systems, and earlier coverage recalled Clop’s Accellion attacks as 2020 (The Record) or 2020-2021 (The Hacker News), with TechCrunch placing a related mass-extortion incident before the late-2021 rebrand.
- Kiteworks, formerly Accellion, urged customers worldwide to shut down file-transfer servers after authorities warned a threat actor might target some deployments over the weekend of September 26.
- Most reports describe a six-hour shutdown—BleepingComputer said 4:00 a.m. to 10:00 a.m. Central Europe and GBHackers said 02:00 to 08:00 UTC, including systems not exposed to the internet—while The Hacker News said nine hours.
- Sources differ on the warning: TechCrunch and GBHackers cited law enforcement; The Record, BleepingComputer, and The Hacker News cited federal intelligence or federal authorities.
- CISO Frank Balonis said the company knows of no compromise and called the shutdown preventative.
- Known vulnerabilities are said to be fixed in release 9.5.1; no CVE, actor, technique, or exploiting group has been named.
- Customer and support comments raised a possible unknown zero-day, including a support official who told Heise of a potential zero-day, but BleepingComputer said neither the company nor the quoted notice confirmed a zero-day or exploitation.
- The Hacker News said subsidiaries including Zivver, DRACOON, and ownCloud are unaffected; Kevin Beaumont noted at least a thousand internet-facing systems.
- On earlier incidents, The Record said Clop used a zero-day in 2020, The Hacker News said Clop exploited Accellion zero-days in 2020-2021, and TechCrunch said a pre-late-2021 Accellion flaw enabled mass data theft and extortion.
Coverage timelineoldest first · each row is one article
- · 1d agoKiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack
TechCrunch · Security· 74
Kiteworks told customers to shut down file-transfer servers after law enforcement warned of an imminent attack.
- · 1d agoKiteworks urges customers to stop using platform after warning from federal intelligence agencies
The Record· 82
Kiteworks told customers to shut systems down after federal intel warned of possible targeting.
- · 1d agoKiteworks urges 6-hour server shutdown over potential zero-day attacks
BleepingComputer· 76