BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 29, 2026 · 2 min read · Original story

Kiteworks patches critical flaw, brings customer systems online

Kiteworks patches critical flaw, brings customer systems online

American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability.

Formerly known as Accellion, it operates a Private Content Network (PCN) that integrates enterprise email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform.

Kiteworks provides services to thousands of global corporations and government agencies, and its Private Data Network has over 100 million end-users.

The secure file-sharing software company urged customers worldwide on Saturday to temporarily shut down their servers after receiving a warning of a potentially imminent cyberattack from federal intelligence authorities.

On Monday, the company brought all hosted customer systems back online after finding no evidence of compromise and no suspicious activity.

"Continuous monitoring throughout the period showed no abnormal activity, and the company has no indication that any Kiteworks or customer system was compromised," Kiteworks said.

"As of September 27th, the shutdown recommendation is now lifted for all customers. If you have not already restarted, you may bring your Kiteworks system back online," the company added in an update to the original advisory.

Kiteworks has also patched a critical vulnerability in an unnamed feature used by less than 1% of all customers and advised those with self-hosted Kiteworks Advanced Forms to contact support for further assistance.

"Kiteworks developed and deployed a fix during the window, applied an additional protective layer across all environments, and has no indication the vulnerability was ever exploited. All other Kiteworks products were unaffected," it noted.

The company has yet to share additional details on the fixed vulnerability and has not yet assigned a CVE ID for easy tracking.

Threat watchdog Shadowserver has spotted nearly 400 Kiteworks instances accessible over the Internet, most of them (234) from the United States, but provides no information on how many are honeypots or have already been patched.

Internet-exposed Kiteworks instances (Shadowserver)

​Because they store sensitive documents, cybercrime gangs often target vulnerable file-sharing platforms in data-theft extortion attacks.

For instance, the Clop extortion gang, which has a long history of exploiting vulnerabilities in enterprise file-sharing platforms, also targeted a legacy Kiteworks File Transfer Appliance (FTA) software in zero-day attacks when the company was still known as Accellion.

Accellion said at the time that 300 customers used the 20-year-old legacy FTA software, with fewer than 100 of them breached and fewer than two dozen victims appeared "to have suffered significant data theft."

That Clop hacking campaign led to a stream of data breaches impacting many high-profile entities that used the Accellion FTA software to transfer sensitive files, including cybersecurity firm Qualys, energy giant Shell, the Reserve Bank of New Zealand, supermarket giant Kroger, Singtel, the Australian Securities and Investments Commission (ASIC), the Office of the Washington State Auditor, and multiple universities.

Five Eyes members also issued a joint security advisory in February 2021 about these attacks and subsequent extortion attempts, warning Accellion customers to block Internet access to vulnerable servers and update them to block the attacks.

References in this story

  1. Kiteworks urges 6-hour server shutdown over potential zero-day attacks www.bleepingcomputer.com Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent…
  2. Kiteworks' Difficult and Unique Decision to Ensure Customer Data Protection Through Customer-Wide Shutdown Successfully… www.kiteworks.com Kiteworks restored all customer systems after a precautionary shutdown, confirming no evidence of compromise from the credible threat. Read the full update.
  3. Kiteworks Issues Precautionary Shutdown Advisory for Customers Following Credible Threat Intelligence From Federal… www.kiteworks.com Kiteworks issues a precautionary shutdown advisory for all customers after credible threat intelligence from federal authorities. No indication of compromise.
  4. Time series · IoT device statistics · The Shadowserver Foundation dashboard.shadowserver.org
  5. Latest Accellion news www.bleepingcomputer.com The latest news about Accellion
  6. Global Accellion data breaches linked to Clop ransomware gang www.bleepingcomputer.com Threat actors associated with a financially-motivated hacker groups combined multiple zero-day vulnerabilities and a new web shell to breach up to 100 companies using Accellion's legacy File Transfer Appliance and steal…
  7. Cybersecurity firm Qualys is the latest victim of Accellion hacks www.bleepingcomputer.com Cybersecurity firm Qualys is the latest victim to have suffered a data breach after a zero-day vulnerability in their Accellion FTA server was exploited to steal hosted files.
  8. Energy giant Shell discloses data breach after Accellion hack www.bleepingcomputer.com Energy giant Shell has disclosed a data breach after attackers compromised the company's secure file-sharing system powered by Accellion's File Transfer Appliance (FTA).
  9. New Zealand Reserve Bank breached using bug patched on Xmas Eve www.bleepingcomputer.com A recent data breach at the Reserve Bank of New Zealand, known as Te Pūtea Matua, was caused by attackers exploiting a critical vulnerability patched the same day.
  10. Kroger data breach exposes pharmacy and employee data www.bleepingcomputer.com Supermarket giant Kroger has suffered a data breach after a service used to transfer files securely was hacked, and threat actors stole files.
  11. Singtel, QIMR Berghofer report Accellion-related data breaches www.bleepingcomputer.com Singtel and the QIMR Berghofer Medical Research Institute are the latest companies to disclose data breaches caused by a vulnerability in the Accellion FTA secure file transfer software.
  12. Australian securities regulator discloses security breach www.bleepingcomputer.com The Australian Securities and Investments Commission (ASIC) has revealed that one of its servers has been accessed by an unknown threat actor following a security breach.
  13. Data breach exposes 1.6 million Washington unemployment claims www.bleepingcomputer.com Washington's State Auditor office has suffered a data breach that exposed the personal information in 1.6 million employment claims.
  14. Five Eyes members warn of Accellion FTA extortion attacks www.bleepingcomputer.com Four members of Five Eyes, in collaboration with Singapore as an active contributor, have issued a joint security advisory about ongoing attacks and extortion attempts targeting organizations using the Accellion File…

Guides related to this story

← Back to all news