Kiteworks eases shutdown after isolating security flaw
Kiteworks has withdrawn its broad precautionary shutdown recommendation for most customers after an emergency security review isolated a critical vulnerability to its Advanced Forms product, while installations using that feature were advised to remain offline pending a fix. The secure file-transfer and private-data communications company had asked customers worldwide to take systems offline…
Kiteworks has lifted its precautionary shutdown recommendation for most customers following an emergency security review that isolated a critical vulnerability in its Advanced Forms product. Customers utilizing this feature were advised to remain offline until a fix is implemented. The file-transfer and private-data communications company had initially asked customers worldwide to take systems offline over the weekend following credible intelligence from federal authorities suggesting a threat actor might target Kiteworks deployments.
No evidence of compromise was found, and the vulnerability was confined to the Advanced Forms product, which is enabled for fewer than 1% of customers, representing under 50 organizations. Customers not using this feature were allowed to restart their systems. Advanced Forms users were given separate guidance to keep affected systems offline while the company developed and deployed a remedy.
The shutdown window was initially nine hours but was adjusted based on customers' local time zones. The vulnerability, known as a zero-day attack, had not been exploited, and Kiteworks' continuous monitoring detected no anomalous activity associated with it. The company has not disclosed the threat actor or the precise attack technique, and it remains unclear if the present threat intelligence is connected to a previous campaign in 2020-2021.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.