Kiteworks, formerly known as Accellion, told customers on Saturday to temporarily take their servers offline after receiving a warning from federal intelligence authorities of a potentially imminent cyberattack. On Monday, the company brought all hosted customer systems back online.
"Continuous monitoring throughout the period showed no abnormal activity, and the company has no indication that any Kiteworks or customer system was compromised," Kiteworks said in a press release.
The company said the shutdown recommendation was lifted as of September 27th. "If you have not already restarted, you may bring your Kiteworks system back online," it added.
Kiteworks said it has patched a critical vulnerability in an unnamed feature used by less than 1% of all customers. Customers with self-hosted Kiteworks Advanced Forms have been advised to contact support for further assistance. The fix was developed and deployed during the shutdown window, and an additional protective layer was applied across all environments. The company said it has no indication the vulnerability was ever exploited and that all other Kiteworks products were unaffected.
Kiteworks has not yet shared details of the vulnerability or assigned a CVE ID for tracking. Threat watchdog Shadowserver has identified nearly 400 Kiteworks instances accessible over the internet, most of them in the United States, though it is unclear how many are honeypots or have already been patched.
Kiteworks operates a Private Content Network that integrates enterprise email, file sharing, managed file transfer, APIs and web forms into a single platform. It provides services to thousands of global corporations and government agencies. Because such platforms store sensitive documents, they are frequent targets of cybercrime gangs in data-theft extortion attacks. The Clop extortion gang, which has a history of exploiting enterprise file-sharing platforms, previously targeted a legacy Kiteworks File Transfer Appliance in zero-day attacks.