Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response

Cybersecurity vendors are facing a tough choice when it comes to responding to zero-day vulnerabilities: how much information to share with customers about potential attacks, and whether to recommend taking systems offline. Two recent incidents involving Kiteworks and Citrix highlight the challenges of balancing transparency and caution in the face of emerging threats.

On September 24, threat detection firm GreyNoise Intelligence observed a US-based IP address scanning for Citrix NetScaler installations and conducting remote code execution (RCE) attacks. Over the next two days, reports of potential zero-day attacks on NetScaler installations emerged on social media, with some cybersecurity professionals debating whether the activity targeted vulnerabilities already patched in August. However, by September 26, Benjamin Harris, founder and CEO of exposure-management firm watchTowr, urged NetScaler users to take their systems offline.

Citrix seemed to agree, posting an update that patched eight vulnerabilities, including two zero-days that had been exploited in the wild. The company’s blog post did not recommend taking servers offline until they were patched, instead urging customers to upgrade to versions containing the fix immediately. However, this approach has come under fire from many in the cybersecurity community as being too little, too late.

In contrast, data protection provider Kiteworks took a more aggressive stance. The company issued a recommendation to customers to proactively take their systems offline based on intelligence about an imminent attack. With its engineering team and external national intelligence experts working together to identify the security issue, the company warned that a zero-day attack could be coming. On Monday, Kiteworks published an advisory identifying the vulnerability with an update to patch it.

The decision to tell customers to shut down their systems did not come easy for Kiteworks, according to CEO and chairman Jonathan Yaron. “The industry standard is to wait for proof of exploitation before alerting customers,” he said in a statement. However, Kiteworks chose to err on the side of caution, warning that a zero-day attack could be coming.

While Citrix’s response has been criticized as being too little, too late, Kiteworks’ approach has raised questions about overreacting to potential threats. “This isn’t an active attack — people aren’t actively being breached — and yet the vendor is telling customers to take their systems offline,” said John Strand, owner of Black Hills Information Security.

Ultimately, the decision to shut down or stay up in the face of emerging threats depends on the specific circumstances. For vendors like Kiteworks and Citrix, it’s a delicate balance between transparency and caution. While there is no one-size-fits-all solution, one thing is clear: cybersecurity vendors must be prepared to make tough decisions quickly when faced with zero-day vulnerabilities.

In practical terms, this means that organizations should be prepared for the possibility of system downtime in the event of a potential attack. This may involve having a plan in place for emergency patching or taking systems offline temporarily. Vendors like Kiteworks are showing that proactive communication and caution can be key in preventing attacks, even if it means inconveniencing customers.


Source: Dark Reading — 2026-10-02