Skip to content

Security1 publisher2 min readPublished

Kiteworks clears customers to restart file-transfer servers after a weekend shutdown on a federal tip

Kiteworks lifted its worldwide shutdown advice after patching a critical flaw in a feature used by under 1% of customers. Self-hosted operators stopped and restarted on the vendor's word alone, with no CVE yet to check the fix against.

The Watch · Security desk

Illustration accompanying Kiteworks clears customers to restart file-transfer servers after a weekend shutdown on a federal tip

What happened

  • On Saturday, after federal intelligence authorities warned of a potentially imminent attack, Kiteworks urged customers worldwide to shut down their servers temporarily.
  • Kiteworks brought all hosted customer systems back online on Monday, saying it had found no evidence of compromise and no suspicious activity.
  • Customers running self-hosted Kiteworks Advanced Forms were told to contact support for further assistance.
  • Clop previously hit the company's legacy File Transfer Appliance with zero-days, when Accellion said fewer than 100 of its 300 FTA customers were breached.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Self-hosted teams picked their own restart point on the vendor's clearance alone, so restart criteria for MFT servers need to be settled before the next advisory arrives.
  • constraint Without a CVE ID, scanners and patch trackers have nothing to match against, so confirming a self-hosted system is fixed has to go through Kiteworks support.
  • exposure Any remaining exposure sits with self-hosted, internet-facing deployments, and the public exposure count cannot separate patched servers from unpatched ones.
  • precedent Customers can now expect Kiteworks to ask for a worldwide shutdown on a federal tip alone, at weekend notice. In 2021 the Five Eyes cut-off advice came only after the breaches.

Every statement about the flaw comes from Kiteworks [8]. The company said it "developed and deployed a fix during the window, applied an additional protective layer across all environments, and has no indication the vulnerability was ever exploited" [7]. It said all other Kiteworks products were unaffected [7].

The restart clearance was two sentences. "As of September 27th, the shutdown recommendation is now lifted for all customers. If you have not already restarted, you may bring your Kiteworks system back online," the company wrote in its update [6]. For self-hosted teams, the weekend meant two actions with no compromise to respond to: a shutdown on the vendor's request and a restart on the vendor's clearance [3][6][3]. Kiteworks bundles managed file transfer with enterprise email, file sharing, APIs and web forms in one platform [2], so taking a server down stops more than file transfer. Its customers include thousands of corporations and government agencies, and its Private Data Network has over 100 million end users [9]. The report does not name the agency behind the warning or any group expected to attack, and it does not say how many self-hosted customers went offline or for how long [3].

Shadowserver's internet count is far smaller than that customer base: nearly 400 reachable Kiteworks instances [10][2]. Of those, 234 are in the United States [10], more than half [1]. The count includes honeypots and already-patched systems in unknown numbers [10].

The sustained pattern on this platform is Clop's. Cybercrime gangs often go after file-sharing platforms because they store sensitive documents [16]. Clop's zero-day campaign against the old Accellion FTA led to breaches at Qualys, Shell, Kroger and the Reserve Bank of New Zealand [11][12]. In February 2021, the Five Eyes told Accellion customers to block internet access to vulnerable servers and update them [13]. That advice followed the attacks [13]. This time the shutdown came first, and Kiteworks says it found no compromise [5].

What to watch

  • A Kiteworks advisory with a CVE ID and technical detail on the patched feature, so scanners can confirm fixes on self-hosted systems.
  • Any public statement from the federal agency behind the warning, or attribution of the threatened attack to a named group such as Clop.
  • Shadowserver's next count of internet-reachable Kiteworks instances, and any report of exploitation against unpatched self-hosted servers.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories