Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack.
"Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief Information Security Officer (CISO) at Kiteworks.
"Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we continue to work through the matter with federal intelligence authorities."
The company said it has not found any evidence that its customers' systems have been compromised, emphasizing the advisory is preventative rather than a response to a confirmed hack. The development was first reported by German news publication Heise.
Kiteworks did not disclose which law enforcement agency alerted the company, or who may be behind it. The American software firm said all known vulnerabilities have been addressed in its latest software release, 9.5.1, recommending that customers apply the patches for optimal protection.
Other subsidiaries of Kiteworks, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder, are not affected.
Kiteworks also revealed that it has sent an email to all customers detailing the specific hours as well as the recommended nine-hour timeframe.
In late 2020-early 2021, the Clop threat actor (aka UNC2546) was found exploiting multiple zero-day vulnerabilities in its file transfer program to conduct a data theft and extortion campaign targeting high-profile entities.
Reproduced in full under licence from The Hacker News. © The Hacker News. Written by info@thehackernews.com (The Hacker News).
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-26 07:48 UTC
Related stories
- ISC Stormcast For Monday, September 28th, 2026 https://isc.sans.edu/podcastdetail/10112, (Mon, Sep 28th)
SANS Internet Storm Center · 2026-09-28
- Wireshark 4.6.9 Released, (Sun, Sep 27th)
SANS Internet Storm Center · 2026-09-27
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
BleepingComputer · 2026-09-26 · exploited
- Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Hacker News · 2026-09-26
- GitHub Actions re-enabled with Mini Shai-Hulud payload still active
BleepingComputer · 2026-09-26