Kiteworks lifts advisory after precautionary warning for customers to shut down systems
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Industries
- Government
- Reported by
- 1 outlet
An article from
The firm had received information from law enforcement of a possible attack.
Published Sept. 28, 2026
Two days after advising customers to take their systems offline, Kiteworks on Sunday canceled its precautionary guidance.
After receiving information from federal authorities of a potential threat, the company on Friday issued an advisory for customers to temporarily take their systems offline.
"Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers,” Kiteworks CISO Frank Balonis told Cybersecurity Dive Friday in a statement. “Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter.”
Researchers at Sophos said the warning was related to possible exploitation of a zero-day vulnerability.
California-based Kiteworks, previously known as Accellion, offers a platform to enable secure communication with customers, vendors and other partners.
Kiteworks advised customers with self-managed systems either on-premises or through Azure or AWS to shut down their systems for a nine-hour period, while the threat was investigated.
On Friday, the company said it was not aware of any confirmed compromise, adding that the advisory was a preventative action rather than a response to any confirmed breach.
The company said all known vulnerabilities were addressed in the current security update 9.5.1.
Kiteworks lifted the advisory on Sunday, but did not provide any specifics about what was found during the investigation.
Originally published by Cybersecurity Dive. © Cybersecurity Dive. Written by David Jones.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-28 15:46 UTC
Related stories
- One Packet Can Crash OT Servers in Industrial Sectors
Dark Reading · 2026-09-28
- JadePuffer crims hijacked Azure identities and used them to blow up cloud resources
The Register · 2026-09-28
- Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
Dark Reading · 2026-09-28
- Dutch police confirm arrest in ShinyHunters hacking investigation
BleepingComputer · 2026-09-28
- ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
The Record · 2026-09-28