If you self-manage Kiteworks, the file-transfer platform formerly known as Accellion, the company asked you to take it offline this weekend: 10pm Friday to 4am Saturday on the east coast, 4am to 10am in Central Europe, even for servers not reachable from the internet. The size depends on which Kiteworks statement you read: six hours in the customer email Heise obtained, nine in the company’s press release. Hosted systems were shut down by Kiteworks itself; self-managed installs did the hands.
The stated cause is law-enforcement threat intelligence. “Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems,” CISO Frank Balonis said, describing the advisory as preventative rather than a response to a confirmed breach: no compromise is known, and all known vulnerabilities are fixed in the current release, 9.5.1. Support put it more plainly to Heise: protection against any potential zero-day attacks.
No CVE, no patch, no details, and no word on which agency warned it or which group is behind the threat. watchTowr’s Jake Knott called it highly unusual: nobody asks an entire customer base to unplug production systems over a weekend because of a hunch. File-transfer appliances are where the extortion crews have lived: this company’s Accellion FTA appliance was the target of a mass Clop campaign in 2020 and 2021, and Clop’s work since runs through GoAnywhere, MOVEit, Cleo and Serv-U.
The window has passed. As of Saturday morning, no incident report, no CVE and no patch had followed the advisory. If you run Kiteworks yourself, the practical instruction is the boring one. Stay on 9.5.1 and watch the security updates page.
Source: Kiteworks’ precautionary shutdown advisory; the email was first reported by Heise.