Overview
- Kiteworks told customers to perform a nine-hour precautionary shutdown after receiving credible federal threat intelligence about possible targeting, and the company lifted that recommendation on September 27.
- Investigators traced the risk to a severe bug confined to the Advanced Forms secure data-collection product, which Kiteworks says is enabled for fewer than 1% of its more than 3,800 customers.
- Kiteworks reported no evidence that its systems or customers were compromised and advised all customers to run release 9.5.1, which the company says accounts for known vulnerabilities.
- The firm said it coordinated the response with federal intelligence authorities and industry partners, including Mandiant, and provided targeted support to self-hosted Advanced Forms customers.
- Experts noted the operational pain of a vendor-directed outage and flagged Kiteworks’ Accellion lineage as a reason for ongoing scrutiny, so observers are watching for any signs of exploitation or further disclosures.