[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYfQqpSQBoPpqf6NhKMp29Zar7BL7AkxZPZi0CI1l5eY":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":33},"28399905-0ee5-4708-991c-59b6f3818e32","Kiteworks lifts shutdown advisory after ‘credible threat intelligence’ from federal authorities","kiteworks-lifts-shutdown-advisory-after-credible-threat-intelligence-from-federa-910221","The company said it found and patched a previously unknown critical vulnerability in one product during the weekend shutdown, and has no indication it was exploited. The post Kiteworks lifts shutdown advisory after ‘credible threat intelligence’ from federal authorities appeared first on CyberScoop.","Kiteworks advised customers to take production systems offline due to credible threat intelligence from federal authorities, but has since lifted the advisory. During the precautionary shutdown, the company discovered and patched a critical, previously unknown vulnerability in its Advanced Forms product, with no indication of exploitation.","Kiteworks lifts shutdown advisory after federal authorities warn of imminent attack.","Kiteworks, a provider of secure file transfer and data-sharing tools, told customers Monday they could resume normal operations after a weekend-long precautionary shutdown prompted by what it called “credible threat intelligence” from federal authorities. The recommendation, issued last week, advised customers to take production systems offline ahead of a potential imminent attack. The company also shut down the environments it hosts on customers’ behalf. By Sunday, Kiteworks said continuous monitoring showed no abnormal activity. “Telling customers to take production systems offline is not a decision any vendor makes lightly, and we knew exactly what we were asking of them,” Chief Information Security Officer Frank Balonis said in the company’s statement. “We made it anyway, because when the choice is between certainty and convenience, customer data is not something we are willing to gamble with.” During the shutdown, Kiteworks discovered a previously unknown critical vulnerability in Advanced Forms, a secure data collection tool used by fewer than 1% of its customers, a group the company said comprises approximately 50 organizations. The company said its other products, including file collaboration, file transfer, email encryption and managed file transfer, were unaffected. Kiteworks said it developed and deployed a fix during the window and has no indication the vulnerability was ever exploited. All known vulnerabilities are addressed in release 9.5.1, which the company recommends customers run. Company CEO Jonathan Yaron said in a release that being proactive about the threat was top of mind.“Our customers gave up their weekend on our recommendation, at short notice and at difficult hours, and many of their teams worked through the night alongside ours,” Yaron said. “The industry standard is to wait for proof of an attack. We would rather be proactive on credible warning than wait for certainty and be too late. That is the standard we intend to keep.” Kiteworks, a California-based company formerly known as Accellion, rebranded in October 2021 after a vulnerability in its legacy file transfer appliance allowed an extortion gang to breach hundreds of organizations. That campaign was part of a broader wave of attacks on file transfer products. Kiteworks declined to identify which federal authorities provided the intelligence or which hacking group prompted the warning. The company said it worked with federal intelligence authorities throughout the weekend and shared threat intelligence with industry partners, including Mandiant. Share Facebook LinkedIn Twitter Copy Link Add to Preferred Sources","https:\u002F\u002Fcyberscoop.com\u002Fkiteworks-lifts-shutdown-advisory-after-credible-threat-intelligence-from-federal-authorities\u002F","https:\u002F\u002Fcyberscoop.com\u002Fwp-content\u002Fuploads\u002Fsites\u002F3\u002F2026\u002F09\u002FScreenshot-2026-09-29-at-10.07.53-AM.png","2026-09-29T14:11:43+00:00","2026-09-29T16:00:20.057196+00:00",8,[18,21,24,26],{"name":19,"type":20},"Advanced Forms","product",{"name":22,"type":23},"Kiteworks","vendor",{"name":25,"type":23},"Accellion",{"name":27,"type":23},"Mandiant","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":28,"icon":30,"name":31,"slug":32},null,"Threat Intelligence","threat-intelligence",[34,39,44,49],{"category":35},{"id":36,"icon":30,"name":37,"slug":38},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":40},{"id":41,"icon":30,"name":42,"slug":43},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":45},{"id":46,"icon":30,"name":47,"slug":48},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":50},{"id":28,"icon":30,"name":31,"slug":32},[]]