Kiteworks has lifted its Kiteworks shutdown advisory after asking customers to temporarily take certain systems offline following Kiteworks threat intelligence received from federal intelligence authorities. The company said the action was precautionary and that it has no indication that Kiteworks or customer systems were compromised.
The shutdown recommendation was lifted on September 27. Customers that had not already restarted their systems were permitted to bring them back online, while all systems hosted by Kiteworks on behalf of customers had been restored and were operating normally.
Kiteworks Shutdown Advisory Followed Threat Intelligence
Kiteworks issued the advisory after receiving information indicating that a threat actor may attempt to target some Kiteworks systems.
As a precaution, the company recommended a nine-hour shutdown window during the weekend, with customers following the timeframe in their local time zones.
Customers managing their own Kiteworks environments on-premises or through AWS or Azure were instructed to shut down their systems during the specified period. For systems hosted by Kiteworks, the company said it would carry out the shutdown on behalf of customers.
Frank Balonis, Chief Information Security Officer at Kiteworks, said the company notified customers directly after receiving the intelligence and recommended the precautionary measure while continuing to work with federal intelligence authorities.

No Confirmed Kiteworks Systems Compromise
Kiteworks said there is currently no indication that its systems or customer environments have been compromised.
The company described the advisory as preventative rather than a response to a confirmed breach. It has not disclosed the identity of the suspected threat actor or provided details about how the potential targeting could have occurred.
The company also said all known vulnerabilities have been addressed in its current 9.5.1 release.
Kiteworks continues to recommend that customers run the latest version of its software.
Kiteworks 9.5.1 Addresses Known Vulnerabilities
According to the company, Kiteworks 9.5.1 addresses all known vulnerabilities in the current release.
The precautionary action was separate from a confirmed compromise, with Kiteworks saying the decision to recommend a temporary shutdown was based on information received from federal intelligence authorities.
The company has not stated that any customer data was accessed or stolen as a result of the threat described in the advisory.
The threat also does not affect several other Kiteworks subsidiaries, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai and 123FormBuilder.
Kiteworks Systems Back Online
With the precautionary shutdown recommendation now lifted, customers can bring their systems back online if they have not already restarted them.
Kiteworks said all systems it hosts for customers have already been brought back up and are operating normally. Customers using self-hosted Advanced Forms were asked to contact Customer Support for assistance.
The company previously sent customers an email advisory containing the specific shutdown hours and recommended nine-hour timeframe. Customers with questions about the advisory or their individual environments were directed to Kiteworks Technical Support.
Kiteworks has not reported a confirmed breach connected to the threat intelligence that triggered the advisory.
The company said it will continue recommending the use of its latest release while the matter is handled with federal intelligence authorities. At this stage, the available information points to a precautionary response to a potential threat rather than a confirmed compromise of Kiteworks or customer systems.

