KITEWORKS told customers worldwide to temporarily disconnect their secure file transfer servers after receiving sensitive intelligence from unnamed federal authorities about a possible imminent attack. The initial customer instruction called for physical isolation from 02:00 to 08:00 UTC on 26 September, although a subsequent public advisory recommended a nine-hour window based on each customer’s local time zone.
The measure applied to on-premises systems and self-hosted deployments in AWS and Azure, including servers without direct internet access. Kiteworks said it would isolate systems hosted in its own infrastructure. The company has not reported evidence of a successful breach, data theft, unauthorised access or compromise of its corporate systems.
The warning has been linked by Kiteworks support staff to a possible, currently unidentified software flaw, but the company has not confirmed that a zero-day exists or that it has been exploited. No technical details, CVE, indicators of compromise or dedicated patch have been published. Kiteworks says version 9.5.1 addresses all vulnerabilities currently known to it and urged customers to standardise on that release, but this does not confirm that it fixes the suspected threat.
The company has not explained why even internally isolated systems required shutdown, or identified the federal agency, attacker or expected attack method. The advisory does not affect subsidiary products including Zivver, DRACOON, totemo, ownCloud, WAMNET and 123Formbuilder. Kiteworks also distinguished the situation from historic attacks on the separate, now-deprecated Accellion File Transfer Appliance codebase.