Customers who run Kiteworks file-sharing servers on their own hardware are being asked to switch them off for nine hours this weekend. The company issued the advisory on Friday, September 25, after what it calls credible threat intelligence from federal authorities.
Kiteworks sells software that companies use to exchange sensitive files. Its customers include hospitals, schools, carmakers and government agencies. Asking customers to go offline means the company cannot rule out a flaw that nobody has found yet.
A warning, not a breach
The company says there is no sign that its systems or its customers' systems have been compromised. "Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window," said Frank Balonis, the company's chief information security officer.
Kiteworks says version 9.5.1, its latest release, fixes all known vulnerabilities, and it recommends that customers install it. The shutdown is meant to cover what it does not yet know about. Customers whose servers Kiteworks hosts need to do nothing, because the company will handle the window for them.
The FBI and CISA, the U.S. cybersecurity agency, declined to comment to TechCrunch. The company has not said which agency sent the warning. It also says its other brands, including ownCloud and DRACOON, are not affected.
The software has a history here. In 2021, when the company was still called Accellion, flaws in its older file-transfer product led to data theft at hundreds of organizations.