The American software company KiteWorks has warned its customers of an imminent cyberattack. In an email obtained by heise security, the KiteWorks CISO urges its customers to temporarily shut down their servers. The company confirmed the process – all customer systems worldwide are to be shut down for six hours starting tomorrow, Saturday.
KiteWorks sells various products for secure and confidential communication, also targeting authorities and financial institutions – an attack at this point would be fatal. And it appears to be such an attack, as KiteWorks CISO Frank Balonis writes: “We have received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend. We strongly recommend you shut down your Kiteworks system for six hours [..].”
The attack warning appears to apply worldwide, at least according to the list of time zones from AEST (Australian Eastern Standard Time) to PDT (Pacific Daylight Time). In Central Europe, all systems are to be shut down on Saturday, September 26, from 4 a.m. to 10 a.m. KiteWorks recommends shutting down the servers even before this time – even if they are not accessible from the internet. It cannot be said with certainty what potential access routes there might be.
The cause of the warning is apparently an unknown security vulnerability exploited by attackers – a “Zero-Day.” This is what KiteWorks customer support wrote to us after we requested confirmation of the process by phone: “The reason we’re asking you to shut down the servers is to protect against any potential zero-day attacks.” The Federal Office for Information Security (BSI) and the Federal Criminal Police Office (BKA) did not respond immediately to a request for comment – the authenticity of the warning message is beyond doubt anyway.
Ransomware gangs often exploit zero-day vulnerabilities for large-scale raids. For example, the cl0p gang infiltrated various corporate networks in August after exploiting flaws in FlexPLM. It also exploited the MoveIT transfer software for extortion – parallels to the current KiteWorks case are striking.
Large companies and corporations worldwide use KiteWorks products for secure file transfer but also for communicationnies, a media group, consulting firms, and well-known automotive suppliers are among the company’s customers. The cybersecurity industry also trusts KiteWorks – for example, the Google subsidiary Mandiant, with whose partnership KiteWorks advertises on its website
Admins should therefore take the warning seriously and shut down their KiteWorks servers early Saturday morning, regardless of version and network topology.
Don’t miss any news – follow us on
Facebook,
LinkedIn or
Mastodon.
This article was originally published in
German.
It was translated with technical assistance and editorially reviewed before publication.
