Kiteworks urges 6-hour server shutdown over potential zero-day attacks

A six-hour server shutdown has been recommended by secure file-sharing software company Kiteworks to customers worldwide due to potential imminent cyberattacks. The warning was issued after the company received threat intelligence from law enforcement indicating a possible attack on their systems this weekend.

According to Heise, a German technology publication, Kiteworks CISO Frank Balonis emailed customers urging them to shut down their servers for six hours as a precautionary measure. This shutdown window applies to customers worldwide, with affected time zones ranging from Australian Eastern Standard Time (AEST) to Pacific Daylight Time (PDT). In Central Europe, the recommended shutdown period is between 4:00 a.m. and 10:00 a.m. on Saturday, September 26, while in New York, it would be from 10:00 p.m. Friday to 4:00 a.m. Saturday.

The company advises shutting down servers before the scheduled window and recommends taking systems offline even if they are not directly accessible from the Internet. Kiteworks confirmed the warning to BleepingComputer, stating that they received intelligence from federal authorities indicating that a threat actor may attempt to target some customer systems.

It’s essential to note that the warning is precautionary rather than a response to a confirmed breach. Kiteworks stressed that there has been no compromise of their systems, and this advisory is preventative rather than reactive. The company also emphasized that all known vulnerabilities are addressed in their current release, 9.5.1, and they continue to recommend customers run the latest version.

The recommendation for a server shutdown is intended to protect against potential zero-day attacks, which occur when attackers exploit previously unknown vulnerabilities. While Kiteworks has not confirmed that attackers are exploiting an unknown vulnerability, customer support said the shutdown recommendation aims to safeguard against such attacks. However, neither the statement provided to BleepingComputer nor the customer notification confirms that a zero-day vulnerability has been discovered or exploited.

Kiteworks develops secure file-transfer and communications products used by government organizations, financial institutions, and enterprises. Secure file-sharing platforms commonly store sensitive documents, making them a valuable target for cybercriminals who conduct data-theft extortion attacks. While it’s not known which threat actor is linked to these potential attacks, the Clop extortion gang has a history of targeting enterprise platforms in data-theft attacks.

As this situation demonstrates, even companies with robust security measures can be vulnerable to unknown threats. It’s crucial for organizations to stay vigilant and regularly update their systems with the latest patches and software versions. In this case, Kiteworks’ prompt action may have helped prevent a potential attack, but it serves as a reminder of the importance of proactive cybersecurity measures.

For readers, this incident highlights the need to be prepared for unexpected threats. If you’re using secure file-sharing platforms or similar services, ensure that your systems are up-to-date with the latest security patches and software versions. Be cautious of unsolicited emails or notifications from vendors, and always verify information through official channels before taking any action. By staying informed and proactive in managing cybersecurity risks, organizations can minimize their exposure to potential threats like these.


Source: Bleeping Computer — 2026-09-25