Vulnerabilities · 3h ago
Kiteworks told customers to shut down their servers for a six-hour window after receiving credible threat intelligence from federal authorities about an imminent attack. The company says it has no confirmed compromise and is treating the warning as preventative, not as a breach response, while also pointing customers to version 9.5.1 as the current release.
The point of the advisory is the timing: Kiteworks is trying to deny attackers a live target window, not just wait for a later patch cycle. The company says all known vulnerabilities are fixed in 9.5.1, but it cannot rule out other access paths or unknown flaws while the platform stays exposed.
For customers running on-premises or self-hosted file-transfer servers, the immediate exposure is whatever sensitive data is resident or moving through those systems during the warned period. The unanswered question is whether the threat is a zero-day route Kiteworks has not seen yet or some other path that only becomes actionable while the servers are online.
3 sources covering this story
The Record from Recorded Future
Kiteworks urges customers to stop using platform after warning from federal intelligence agencies
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.”
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack.
The tech giant, which allows companies to send large datasets over the internet, said it received a "credible threat" from law enforcement about an imminent attack.
Part of the PlainSec briefing for 2026-09-25