supply-chaintrade-pressNewsThe Broadside1 min read

Kiteworks lifts shutdown advisory after federal threat warning

The company discovered an unpatched critical flaw in Advanced Forms during the precautionary window, leaving roughly 50 customers to weigh whether the vulnerability was the target or a coincidence.


TL;DR

Kiteworks told customers Monday they could resume normal operations after a weekend production shutdown prompted by what it called "credible threat intelligence" from federal authorities. During the outage window, the company discovered a previously unknown critical vulnerability in Advanced Forms, its secure data collection tool, affecting approximately 50 organizations. Kiteworks says it developed and deployed a fix and has no evidence the flaw was exploited. All known vulnerabilities are addressed in release 9.5.1.

Kiteworks lifted its shutdown advisory Monday after a weekend that surfaced more than the threat it was bracing for. The company had told customers to take production systems offline based on what CISO Frank Balonis described as "credible threat intelligence" from federal authorities, the kind of call, he said, "no vendor makes lightly."

During the shutdown, Kiteworks discovered a previously unknown critical vulnerability in Advanced Forms, a secure data collection tool used by a subset of its customer base. The company pegged the affected group at fewer than 1% of customers, roughly 50 organizations. Its other products (file collaboration, file transfer, email encryption, and managed file transfer) were unaffected. A fix was developed and deployed within the same window, and Kiteworks reports no indication of exploitation.

The sequence matters. Federal authorities provided intelligence specific enough to trigger a production shutdown across Kiteworks's customer base. The company then found a critical, unpatched flaw that had apparently gone unnoticed until it went looking. Kiteworks declined to name the federal authorities involved or the threat actor behind the warning.

The company knows the stakes of getting this wrong. Under its former name, Accellion, a vulnerability in its legacy file transfer appliance was exploited by an extortion gang in a campaign that breached hundreds of organizations. Kiteworks rebranded in October 2021.

CEO Jonathan Yaron framed the decision as a deliberate departure from industry norms. "The industry standard is to wait for proof of an attack," Yaron said. "We would rather be proactive on credible warning than wait for certainty and be too late."

Kiteworks said it worked with federal intelligence authorities throughout the weekend and shared threat intelligence with industry partners, including Mandiant. Release 9.5.1 addresses all known vulnerabilities, and the company recommends customers run it.


Published ·Deep Fathom

Kiteworks lifts shutdown advisory after federal threat warning — The Broadside