Kiteworks restores systems after shutdown triggered by credible threat intelligence
Kiteworks says customers can bring systems back online after a precautionary shutdown on Sept. 25 tied to credible federal threat intelligence. The company says it found and fixed a previously unknown critical vulnerability during the window and has no indication of exploitation.
Why it matters: - Kiteworks says the incident tested a high-stakes tradeoff: taking customer systems offline to protect private data before an attack could hit. - The company says the shutdown helped prevent exposure of customer environments and led to a fix for a critical vulnerability that had not been publicly known. - The episode underscores how quickly vendors may need to act when federal intelligence points to an imminent threat.
What happened: - Kiteworks told customers on Sept. 25 to shut down their systems after receiving credible threat intelligence from federal intelligence authorities. - The company also shut down the environments it hosts on behalf of customers. - Kiteworks says the threat window has now passed without incident. - Customers who have not yet restarted can bring their systems back online. - All Kiteworks-hosted customer systems have been restored and are operating normally.
The details: - Kiteworks says continuous monitoring during the shutdown showed no abnormal activity. - The company says it has no indication that any Kiteworks system or customer system was compromised. - During the shutdown, Kiteworks discovered a previously unknown critical vulnerability. - The vulnerability was confined to a capability enabled for less than 1% of the customer base. - Kiteworks developed and deployed a fix during the shutdown window. - The company also applied an additional protective layer across all environments. - Kiteworks says there is no indication the vulnerability was ever exploited. - The company says all other Kiteworks products were unaffected.
Between the lines: - Kiteworks chose a precautionary shutdown rather than wait for proof of compromise. - Frank Balonis, chief information security officer, said the company made the call because customer data was not something it was willing to gamble with. - Jonathan Yaron, CEO and chairman, said customers and partners worked through the weekend and overnight, and credited federal authorities for the intelligence and partnership. - Yaron said the industry standard is often to wait for proof of attack, but Kiteworks preferred to act on credible warning.
What's next: - Customers with questions are being directed to Kiteworks Technical Support or their customer success representative. - Support is available by email at support@kiteworks.com, through the customer portal, or at Kiteworks support. - Kiteworks provided regional phone lines for North America, Australia, Germany, Israel, New Zealand, Singapore and the UK. - The company says it intends to keep the same proactive standard for future credible threats.
The bottom line: - Kiteworks says it turned a potential emergency into a controlled response, restored systems, and patched a critical flaw without evidence of exploitation.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Australia News Reporter
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.