Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Kiteworks patches critical flaw, brings customer systems online

    September 29, 2026

    Is the OWASP Top 10 Still Relevant?

    September 29, 2026

    80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

    September 29, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Kiteworks patches critical flaw, brings customer systems online
    News

    Kiteworks patches critical flaw, brings customer systems online

    adminBy adminSeptember 29, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Kiteworks

    American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability.

    Formerly known as Accellion, it operates a Private Content Network (PCN) that integrates enterprise email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform.

    Kiteworks provides services to thousands of global corporations and government agencies, and its Private Data Network has over 100 million end-users.

    The secure file-sharing software company urged customers worldwide on Saturday to temporarily shut down their servers after receiving a warning of a potentially imminent cyberattack from federal intelligence authorities.

    On Monday, the company brought all hosted customer systems back online after finding no evidence of compromise and no suspicious activity.

    “Continuous monitoring throughout the period showed no abnormal activity, and the company has no indication that any Kiteworks or customer system was compromised,” Kiteworks said.

    “As of September 27th, the shutdown recommendation is now lifted for all customers. If you have not already restarted, you may bring your Kiteworks system back online,” the company added in an update to the original advisory.

    Kiteworks has also patched a critical vulnerability in an unnamed feature used by less than 1% of all customers and advised those with self-hosted Kiteworks Advanced Forms to contact support for further assistance.

    “Kiteworks developed and deployed a fix during the window, applied an additional protective layer across all environments, and has no indication the vulnerability was ever exploited. All other Kiteworks products were unaffected,” it noted.

    The company has yet to share additional details on the fixed vulnerability and has not yet assigned a CVE ID for easy tracking.

    Threat watchdog Shadowserver has spotted nearly 400 Kiteworks instances accessible over the Internet, most of them (234) from the United States, but provides no information on how many are honeypots or have already been patched.

    Internet-exposed Kiteworks instances
    Internet-exposed Kiteworks instances (Shadowserver)

    ​Because they store sensitive documents, cybercrime gangs often target vulnerable file-sharing platforms in data-theft extortion attacks.

    For instance, the Clop extortion gang, which has a long history of exploiting vulnerabilities in enterprise file-sharing platforms, also targeted a legacy Kiteworks File Transfer Appliance (FTA) software in zero-day attacks when the company was still known as Accellion.

    Accellion said at the time that 300 customers used the 20-year-old legacy FTA software, with fewer than 100 of them breached and fewer than two dozen victims appeared “to have suffered significant data theft.”

    That Clop hacking campaign led to a stream of data breaches impacting many high-profile entities that used the Accellion FTA software to transfer sensitive files, including cybersecurity firm Qualys, energy giant Shell, the Reserve Bank of New Zealand, supermarket giant Kroger, Singtel, the Australian Securities and Investments Commission (ASIC), the Office of the Washington State Auditor, and multiple universities.

    Five Eyes members also issued a joint security advisory in February 2021 about these attacks and subsequent extortion attempts, warning Accellion customers to block Internet access to vulnerable servers and update them to block the attacks.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleIs the OWASP Top 10 Still Relevant?
    admin
    • Website

    Related Posts

    News

    80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

    September 29, 2026
    News

    JadePuffer agentic AI attacks target Azure, destroy cloud resources

    September 28, 2026
    News

    Dutch police confirm arrest in ShinyHunters hacking investigation

    September 28, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    Woman Arrested, Dragged Away After Quietly Speaking About Flock at City Council Meeting

    September 23, 202653 Views

    How fraudsters target credit unions

    May 4, 202644 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    Woman Arrested, Dragged Away After Quietly Speaking About Flock at City Council Meeting

    September 23, 202653 Views

    How fraudsters target credit unions

    May 4, 202644 Views
    Our Picks

    Kiteworks patches critical flaw, brings customer systems online

    September 29, 2026

    Is the OWASP Top 10 Still Relevant?

    September 29, 2026

    80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

    September 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.