Kiteworks Advises 6-Hour Server Shutdown Following Federal Intelligence Warning

Kiteworks issued an advisory prompted by credible threat intelligence from federal law enforcement indicating an imminent attack. The directive follows a warning from federal law enforcement agencies regarding a potential imminent cyberattack targeting the platform’s infrastructure.

The recommended shutdown window was scheduled for 02:00 to 08:00 UTC on September 26. In regional terms, this translated to 04:00 to 10:00 CET. As of the morning of September 26, no specific Common Vulnerabilities and Exposures (CVE) ID has been assigned to the potential threat.

A conceptual graphic of global network nodes pausing activity.
The shutdown window was coordinated across UTC and CET time zones to mitigate potential risks.

According to reports regarding the federal intelligence warning, the advisory is part of a proactive defense strategy. Administrators who have completed the shutdown window are advised to verify their systems are running software version 9.5.1, which Kiteworks identifies as the current build that addresses all known vulnerabilities. It is also standard security practice following such alerts for IT teams to review access logs for any unusual activity that may have occurred in the hours leading up to the shutdown.

The emergency advisory is limited specifically to Kiteworks-branded servers. Several subsidiaries and associated platforms remain unaffected by this particular threat landscape. These include:

  • Zivver and DRACOON
  • totemo and ownCloud
  • WAMNET and Maytech
  • Bonfy.ai and 123FormBuilder

The high-alert stance from Kiteworks may be influenced by the company’s historical challenges with large-scale exploitation. Formerly known as Accellion, the firm faced a significant series of breaches in 2021 involving its legacy File Transfer Appliance (FTA) software. That event, which compromised numerous high-profile corporate and government entities, likely informs the vendor’s current decision to employ extreme caution when faced with unconfirmed but credible zero-day reports.

Until a patch or specific CVE is released, maintaining the recommended 9.5.1 software version remains the primary defensive baseline for Kiteworks environments.

More From Category

More Stories Today