Ethical Hacking News
Kiteworks, a leading software firm, has issued an urgent warning to its customers, advising them to shut down their systems for a period of nine hours over the weekend due to possible cyber attack. The company's Chief Information Security Officer, Frank Balonis, revealed that Kiteworks had received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some of its systems. The warning is a stark reminder of the ongoing threat landscape and the need for businesses to remain vigilant in the face of emerging cybersecurity threats.
Kiteworks, a leading software firm, has issued an urgent warning to its customers to shut down their systems for 9 hours due to credible threat intelligence from federal authorities. The threat actor, Clop, was found exploiting multiple zero-day vulnerabilities in its file transfer program in 2020 and 2021. Kiteworks has addressed all known vulnerabilities in its latest software release, 9.5.1, and recommends applying patches for optimal protection. Other subsidiaries of Kiteworks are not affected by the warning. The incident highlights the importance of staying up-to-date with security patches and taking proactive measures to protect against potential cyber threats.
In a move that has sent shockwaves through the cybersecurity community, Kiteworks, a leading software firm, has issued an urgent warning to its customers, advising them to shut down their systems for a period of nine hours over the weekend. The company's Chief Information Security Officer, Frank Balonis, revealed that Kiteworks had received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some of its systems.
According to Balonis, the threat intelligence was received on September 26, 2026, and was deemed credible by the company. In response, Kiteworks notified its customers directly and recommended a precautionary shutdown window while it continued to work with federal intelligence authorities to investigate the matter further. The company emphasized that the advisory was preventative in nature, rather than a response to a confirmed hack, and that it had not found any evidence that its customers' systems had been compromised.
The development was first reported by German news publication Heise, and Kiteworks has since revealed that it has addressed all known vulnerabilities in its latest software release, 9.5.1, recommending that customers apply the patches for optimal protection. Other subsidiaries of Kiteworks, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder, are not affected by the warning.
It is worth noting that the Clop threat actor, also known as UNC2546, was found exploiting multiple zero-day vulnerabilities in its file transfer program to conduct a data theft and extortion campaign targeting high-profile entities in late 2020 and early 2021. The fact that Kiteworks has received similar threat intelligence from federal authorities raises concerns about the potential for a similar attack.
Kiteworks has sent an email to all customers detailing the specific hours and the recommended nine-hour timeframe for the shutdown. The company's action is a stark reminder of the ongoing threat landscape and the need for businesses to remain vigilant in the face of emerging cybersecurity threats.
The incident serves as a cautionary tale for businesses and individuals alike, highlighting the importance of staying up-to-date with the latest security patches and taking proactive measures to protect themselves against potential cyber threats. As the threat landscape continues to evolve, it is essential for businesses to stay informed and take steps to mitigate potential risks.
In the meantime, Kiteworks will continue to work closely with federal intelligence authorities to investigate the matter and ensure the security of its systems and those of its customers. The company's proactive approach to cybersecurity is a testament to its commitment to protecting its customers and the broader cybersecurity community.
Related Information:
https://www.ethicalhackingnews.com/articles/Kiteworks-Issues-Urgent-Cybersecurity-Warning-9-Hour-Shutdown-Advised-Over-Possible-Cyber-Attack-ehn.shtml
https://thehackernews.com/2026/09/kiteworks-urges-customers-to-shut-down.html
Published: Sat Sep 26 05:52:33 2026 by llama3.2 3B Q4_K_M