Skip to content

Invest3 publishers3 min readPublished

Kiteworks asks customers to power down for nine hours to guard against zero-day attacks

Kiteworks told customers to shut its file-transfer servers for nine hours this weekend after a federal warning. The company says its current release fixes every known flaw, so the outage guards against one it does not know about.

The Investor · Invest desk

Illustration accompanying Kiteworks asks customers to power down for nine hours to guard against zero-day attacks

What happened

  • Kiteworks will switch off the systems it hosts itself, but customers running the software on-premises or on AWS or Azure have to shut down their own.
  • The company would not say which agency warned it or which hacking group may be behind the threat; the FBI declined to comment and CISA would not comment on the record.
  • A healthcare customer told TechCrunch it took its server down immediately and that the outage is delaying doctors' ability to contact patients.
  • Subsidiaries including Zivver, DRACOON, totemo and ownCloud are not affected by the threat, according to the company.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost Customers who run their own servers pay for the precaution twice: staff time for the shutdown on top of the lost service. Kiteworks takes on the work only for the systems it hosts.
  • exposure Servers left running this weekend put at risk the files sent through them and never deleted, the stored data an extortion gang took from hundreds of organisations through an Accellion flaw.
  • contradiction Kiteworks called its source law enforcement in the customer email and to TechCrunch, but federal intelligence authorities in its release, so customers cannot tell which agency to check the warning with.

The email Kiteworks sent customers on Friday named the fear: attackers exploiting vulnerabilities currently unknown to the company [5]. Kiteworks customer support wrote to heise that the reason for the shutdown was "to protect against any potential zero-day attacks" [6]. A version number tells you how exposed you are to bugs someone has already found. If nobody at the vendor has found the bug, there is nothing to install, and the only control left is to turn the software off. Kiteworks asked for that even on servers that cannot be reached from the internet, because it cannot say with certainty what other routes in might exist [7]. "We have no indication that Kiteworks or our customers' systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach," said Frank Balonis, the company's chief information security officer [4].

The window grew between that email and the press release [11][1]. "We strongly recommend you shut down your Kiteworks system for six hours," Balonis wrote to customers, according to heise [11]. Heise put the Central European slot at 4 a.m. to 10 a.m. on Saturday, September 26 [12]. The release, dated the same Saturday, asks for nine hours in each customer's local time zone [1]. That is three hours more, a window 50% longer than the one first requested [13].

Security researcher Kevin Beaumont pointed to at least a thousand internet-facing Kiteworks systems, and TechCrunch said that number is likely an overcount of affected customer systems [14]. Nine hours across a thousand systems comes to 9,000 system-hours offline [15]. That total leaves out the servers with no internet exposure, which Kiteworks also wants shut [7]. The company says its platform serves over 100 million end-users and thousands of enterprises and government agencies [16].

Heise compared the case to the cl0p gang's use of flaws in the MOVEit transfer software for extortion [17]. In Germany, according to heise, Kiteworks customers include several state banks and insurers, a media group, consulting firms and automotive suppliers [18].

Suppose the window passes quietly and servers restart on the same code. Then any flaw that was unknown on Friday is still there when they come back up [5]. A release after 9.5.1 would mean the company found something, and that the shutdown bought time to fix it [4]. The worst case is attackers reaching servers that customers left running. I think only the second outcome turns nine hours of downtime into a lasting cut in risk, because switching off protects against an attack on a known date and does nothing about the flaw itself. Balonis's email supports the counter-case: it warned of an attack that "may be imminent this weekend" [11]. If the intelligence concerned one timed operation, a bounded shutdown was the right tool. That view is borne out if servers return without a new release and no exploitation surfaces in the weeks after.

What to watch

  • Whether Kiteworks ships a release after 9.5.1 once the window closes; a new version would mean the company found the flaw it feared.
  • Confirmation from the FBI, CISA or Germany's BSI of who issued the warning and what it covered.
  • Reports of exploitation against Kiteworks servers that stayed online through the weekend.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories