Kiteworks lifts shutdown advice after fixing critical flaw
Kiteworks has told customers they can bring their systems back online after the company fixed a critical vulnerability. Over the weekend it had asked them to take servers offline as a precaution.
The US company says it found no signs that any Kiteworks or customer system was compromised during the shutdown window. It also says there is no indication the flaw was exploited.
A weekend shutdown request
Kiteworks was previously known as Accellion. It sells what it calls a Private Content Network (PCN), a single platform that combines enterprise email, file sharing, Managed File Transfer (MFT), APIs and web forms. Its customers include thousands of global corporations and government agencies. The company says its Private Data Network serves more than 100 million end users.
On Saturday, Kiteworks asked customers around the world to temporarily shut down their servers. The company said it had received a warning from federal intelligence authorities about a potentially imminent cyberattack.
The request was unusual. Vendors rarely ask customers to switch off production systems, and taking a file-sharing platform offline interrupts document exchange for the organizations that rely on it.
On Monday, Kiteworks brought all hosted customer systems back online. It said monitoring had shown nothing suspicious.
"Continuous monitoring throughout the period showed no abnormal activity, and the company has no indication that any Kiteworks or customer system was compromised," the company said.
An update to the original advisory confirmed the recommendation had been withdrawn. "As of September 27th, the shutdown recommendation is now lifted for all customers. If you have not already restarted, you may bring your Kiteworks system back online," Kiteworks wrote.
A fix for a little-used feature
According to Kiteworks, the critical vulnerability sits in a feature used by less than 1% of its customers. The company did not name the feature. It did advise customers running self-hosted Kiteworks Advanced Forms to contact support for help.
"Kiteworks developed and deployed a fix during the window, applied an additional protective layer across all environments, and has no indication the vulnerability was ever exploited. All other Kiteworks products were unaffected," the company said.
Kiteworks has not published technical details about the flaw. No CVE ID has been assigned yet, so defenders cannot track the issue through the usual vulnerability databases for now.
Shadowserver, a nonprofit that scans the internet for exposed and vulnerable systems, has found close to 400 Kiteworks instances reachable online. Most of them, 234, are in the United States. Shadowserver did not say how many of these are honeypots or have already been patched.
File transfer tools remain a favorite target
Kiteworks moved quickly for a reason. File-sharing and file transfer platforms hold large amounts of sensitive documents, so cybercrime gangs often go after vulnerable deployments in data-theft extortion attacks.
The company has been through this before. When it was still called Accellion, the Clop extortion gang used zero-day flaws to attack its legacy File Transfer Appliance (FTA) software. Clop has a long record of exploiting enterprise file-sharing products.
At the time, Accellion said 300 customers were using the 20-year-old FTA product. Fewer than 100 were breached, and fewer than two dozen appeared "to have suffered significant data theft."
The fallout was still wide. Organizations that used Accellion FTA to move sensitive files disclosed breaches over the following period. They included cybersecurity firm Qualys, energy company Shell, the Reserve Bank of New Zealand, US supermarket chain Kroger, Singtel, the Australian Securities and Investments Commission (ASIC), the Office of the Washington State Auditor and several universities.
In February 2021, the Five Eyes intelligence alliance (Australia, Canada, New Zealand, the UK and the US) issued a joint advisory about the attacks and the extortion attempts that followed. It told Accellion customers to cut internet access to vulnerable servers and to update them.
Our Take
The Kiteworks episode shows how vendors now respond when government intelligence points to an imminent threat. Asking customers to pull servers offline is costly and disruptive. The fact that Kiteworks chose to do it suggests the company, and possibly the authorities who warned it, saw the risk as serious enough to justify the downtime.
History explains the caution. The Accellion FTA campaign showed how one flaw in a file transfer product can spread into breaches at many organizations. Internet-facing enterprise appliances continue to attract attackers, as recent mass exploitation of Citrix NetScaler and attacks on a Check Point VPN flaw have shown.
The open questions are practical ones. Without a CVE or technical details, self-hosted customers have little to go on beyond the vendor's word. Watch whether Kiteworks publishes more information, whether a CVE is assigned, and whether the number of exposed instances Shadowserver sees goes down. Organizations running Kiteworks Advanced Forms should contact support now rather than wait for those answers.
