Kiteworks tells every customer to switch off over a zero-day warning
The secure file-transfer vendor asked customers to take self-managed systems offline for nine hours over the weekend, found and fixed a critical flaw during the window and lifted the advisory on 27 September
- Kiteworks issued the advisory on 25 September and asked for a nine-hour shutdown in each customer’s local time zone over the weekend.
- The shutdown recommendation was lifted for all customers on 27 September, with Kiteworks-hosted systems back online.
- On 28 September Kiteworks said the critical vulnerability found during the window was confined to a capability enabled for less than 1% of customers.
- TechCrunch reported that researcher Kevin Beaumont pointed to a Shodan listing of at least 1,000 internet-facing Kiteworks systems.
- Kiteworks says release 9.5.1 accounts for all known vulnerabilities.
A vendor telling its whole customer base to pull the plug over a weekend at a day’s notice is a new incident-response pattern, and MSPs and MSSPs with legal, healthcare and public-sector clients need a playbook for it: who can authorize taking a client’s file-transfer system offline out of hours, what the contract says about vendor-directed downtime, and who confirms the 9.5.1 upgrade before restart.
The episode also favors hosted over self-managed: Kiteworks switched off its own hosted estate, while self-managed customers and their partners had to find engineers at the weekend. Partners who cannot say which clients run a self-managed instance, or whether it faces the internet, are the ones who lose.
“When the choice is between certainty and convenience, customer data is not something we are willing to gamble with.”Frank Balonis, chief information security officer, Kiteworks
Kiteworks, the secure file-transfer vendor, told every customer on 25 September to shut down self-managed systems for nine hours over the weekend, in a precautionary shutdown advisory prompted by what it called credible threat intelligence from federal intelligence authorities that a threat actor might target some of its systems. It switched off the systems it hosts for customers itself.
The instruction covered on-premises, Amazon Web Services and Microsoft Azure deployments. Kiteworks-hosted customers had nothing to do. Frank Balonis, chief information security officer, said the company had no indication that its systems or its customers’ systems were compromised, and that release 9.5.1 accounts for all known vulnerabilities.
TechCrunch reported on 25 September that Kiteworks’s email to customers warned of potential zero-day attacks, that security researcher Kevin Beaumont pointed to a Shodan listing of at least 1,000 internet-facing Kiteworks systems, likely an overcount, and that one healthcare customer took its server down as soon as the alert arrived.
What the shutdown found
Kiteworks lifted the recommendation on 27 September. In a second statement on 28 September it said the threat window had passed without incident, and that during the shutdown its engineers found a previously unknown critical vulnerability in a capability enabled for less than 1% of its customer base. A fix was built and deployed inside the window, and the company says it has no indication the flaw was ever exploited. SecurityWeek reported, citing a customer email shared online, that the capability is Advanced Forms.
