Kiteworks is urging some customers to temporarily shut down their systems after receiving what it described as credible threat intelligence from law enforcement. The company said a threat actor may attempt to target some Kiteworks systems used by customers.
Chief information security officer Frank Balonis told TechCrunch the shutdown recommendation was precautionary while Kiteworks and law enforcement partners assess the matter. He said the company was not aware of any compromise and that the advisory was not a response to a confirmed breach. Kiteworks did not identify the law enforcement agency or a suspected hacking group.
An email to customers, reported by German publication Heise and shared with TechCrunch, urged shutdown before the weekend to guard against potential zero-day attacks. Kiteworks said it could not confirm whether other routes for improper access existed. The company said it had fixed all known vulnerabilities in software release 9.5.1, which it recommends customers use.
The number of customers potentially affected is unclear. Kiteworks says it serves thousands of customers across sectors including healthcare, technology, education, automotive and government. Security researcher Kevin Beaumont pointed to at least 1,000 internet-facing Kiteworks systems.
Kiteworks, formerly Accellion, previously faced a mass hack before its rebrand in late 2021. A vulnerability in its file-transfer application enabled attackers to steal data from hundreds of organizations, according to the report.
Comments
0No comments yet. Be the first to comment.