Vulnerabilità · 3 ore fa
Kiteworks ha chiesto ai clienti di spegnere la piattaforma per sei ore dopo un avviso di intelligence federale su un attacco imminente. L’azienda dice di non vedere una compromissione confermata dei propri sistemi e indica la 9.5.1 come release corrente raccomandata.
Il punto non è una patch d’emergenza già legata a una CVE nota, ma una finestra operativa da negare all’attaccante: se il servizio resta esposto durante quell’intervallo, il bersaglio diventa il sistema di file transfer stesso, con i dati sensibili in transito o residenti sulla piattaforma a fare da impatto iniziale.
Per chi gestisce installazioni on-premises o self-hosted di Kiteworks, questa resta una misura di contenimento legata al rischio immediato, non una semplice nota di aggiornamento. Il quadro può cambiare solo se emergono dettagli tecnici o una vulnerabilità specifica; fino ad allora, la minaccia è il tempo in cui il sistema resta online.
3 fonti che coprono questa storia
The Record from Recorded Future
Kiteworks urges customers to stop using platform after warning from federal intelligence agencies
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.”
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack.
The tech giant, which allows companies to send large datasets over the internet, said it received a "credible threat" from law enforcement about an imminent attack.
Part of the PlainSec briefing for 2026-09-25