Kiteworks has lifted its precautionary request for customers to shut down their systems after patching a critical vulnerability. The company said it found no evidence of compromise or suspicious activity during the shutdown period.
Kiteworks issued the shutdown recommendation on Saturday after receiving a warning from federal intelligence authorities about a potentially imminent cyberattack. On Monday, it brought all hosted customer systems back online. In an update, the company said the recommendation was lifted for all customers as of September 27 and that customers who had not restarted could bring their systems back online.
The company also patched a critical vulnerability in an unnamed feature used by less than 1% of its customers. It advised customers with self-hosted Kiteworks Advanced Forms to contact support. Kiteworks said it deployed a fix during the shutdown window, added a protective layer across all environments, and had no indication the flaw was exploited. Other Kiteworks products were unaffected.
Kiteworks has not disclosed further details about the vulnerability or assigned it a CVE ID. The company, formerly known as Accellion, operates a Private Content Network that combines enterprise email, file sharing, Managed File Transfer, APIs, and web forms. Its Private Data Network has more than 100 million end-users.
Comments
0No comments yet. Be the first to comment.