Kiteworks, formerly Accellion, warned customers of a credible and potentially imminent cyberattack targeting its systems and recommended a coordinated six-hour shutdown before the September 26 weekend. The company said the warning was based on law-enforcement intelligence and may involve exploitation of an unknown zero-day vulnerability; it advised shutting down affected systems even if they are not internet-facing because the potential access paths are unknown.
Kiteworks said it had no evidence that customer environments had been compromised when it issued the advisory. It stated that all known vulnerabilities are fixed in version 9.5.1 and urged customers to upgrade, while withholding the suspected attack vector, threat actor, law-enforcement source, and number of organizations potentially at risk.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Kiteworks advised customers to shut down systems, including those not exposed to the internet, for a six-hour worldwide precautionary window while it and law-enforcement partners investigated possible exploitation of an unknown zero-day. For Central Europe, the planned shutdown window was 04:00–10:00 on September 26.
Kiteworks told customers it had received credible threat intelligence from law enforcement that a threat actor might imminently target customer systems. It said the advisory was preventative and that it was not aware of any compromise at the time.
Kiteworks stated that all vulnerabilities known to the company had been fixed in software version 9.5.1 and recommended that customers use that release. The company remained concerned about a potential unknown zero-day vulnerability.
Before its late-2021 rebrand to Kiteworks, Accellion suffered a vulnerability-based mass compromise in which an extortion gang stole data from hundreds of organizations' file-transfer servers and threatened to publish it unless ransoms were paid.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcetechcrunch.com
Open sourceheise.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.