Urgent.News

What's breaking now, across thousands of outlets.

Tech

Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack

The tech giant, which allows companies to send large datasets over the internet, said it received a "credible threat" from law enforcement about an imminent attack.

Kiteworks, a leading technology company specializing in secure file transfer tools, is warning its customers to shut down their systems due to an "imminent" threat of a potential cyberattack. The company, formerly known as Accellion, has informed its customer base about the impending attack, which could potentially occur as early as this weekend. This advisory was first reported exclusively by Heise, a German publication, and a copy of the email sent by Kiteworks to customers has been shared with TechCrunch.

The urgent notification stems from credible threat intelligence received from law enforcement, which suggests that a threat actor may target some of Kiteworks' systems for its customers. Despite this, Kiteworks has not disclosed the specific law enforcement agency that provided this information or the hacking group responsible for the threat. The FBI and the U.S. cybersecurity agency, CISA, have not responded to queries from TechCrunch regarding the Kiteworks alert.

To mitigate the threat, Kiteworks recommends that all customers update their systems to the latest software release, version 9.5.1, which contains patches for known vulnerabilities. The company urges customers to shut down their systems before the weekend, or sooner if possible, to protect against any potential zero-day attacks. These vulnerabilities, known as zero-days because they are unknown to the vendor, can be exploited before they are patched.

Security researcher Kevin Beaumont noted that there are at least a thousand internet-facing Kiteworks systems accessible online. This revelation has raised concerns about the potential number of customers affected by this threat. Kiteworks, which has a wide range of clientele spanning healthcare, technology, education, automotive, and government sectors, has faced cyberattacks in the past.

In 2021, prior to its rebranding, an extortion gang exploited a vulnerability in Kiteworks' file-transfer application to hack and steal data from hundreds of organizations. The hackers then threatened to release this confidential information publicly unless ransom was paid. As of now, Kiteworks maintains that it is not aware of any compromise to their systems, and this advisory is purely preventive.

Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techcrunch.com →

More in Tech

More from Friday 25 September →