Post

Imminent Zero-Day Attack KiteWorks Urges Customers to Shut Down Servers

Imminent Zero-Day Attack KiteWorks Urges Customers to Shut Down Servers

Imminent Zero-Day Attack 🚨

The American software company KiteWorks has warned its customers of an imminent cyberattack. In an email obtained by Heise Security, the KiteWorks CISO urges its customers to temporarily shut down their servers. The company confirmed the process, stating that all customer systems worldwide are to be shut down for six hours starting tomorrow, Saturday.

KiteWorks CISO Frank Balonis writes: “We have received credible threat intelligence from law enforcement indicating an attack on KiteWorks systems may be imminent this weekend. We strongly recommend you shut down your KiteWorks system for six hours.”

The attack warning appears to apply worldwide, at least according to the list of time zones from AEST (Australian Eastern Standard Time) to PDT (Pacific Daylight Time). In Central Europe, all systems are to be shut down on Saturday, September 26, from 4 a.m. to 10 a.m. KiteWorks recommends shutting down the servers even before this time - even if they are not accessible from the internet. It cannot be said with certainty what potential access routes there might be.

The cause of the warning is apparently an unknown security vulnerability exploited by attackers - a “Zero-Day.” KiteWorks customer support confirmed this, stating: “The reason we’re asking you to shut down the servers is to protect against any potential zero-day attacks.” Ransomware gangs often exploit zero-day vulnerabilities for large-scale raids. For example, the cl0p gang infiltrated various corporate networks in August after exploiting flaws in FlexPLM. It also exploited the MoveIT transfer software for extortion - parallels to the current KiteWorks case are striking.

Large companies and corporations worldwide use KiteWorks products for secure file transfer but also for communication via webmail. In Germany, several state banks and insurance companies, a media group, consulting firms, and well-known automotive suppliers are among the company’s customers. Admins should therefore take the warning seriously and shut down their KiteWorks servers early Saturday morning, regardless of version and network topology.

Read full article

This post is licensed under CC BY 4.0 by the author.