Kiteworks Urges Server Shutdown Following Federal Threat Intelligence on Advanced Forms Vulnerability
Kiteworks, a provider of secure data sharing solutions, advised its customers over the weekend to shut down their servers due to credible threat intelligence from federal authorities. The company initially recommended a nine-hour precautionary shutdown for on-premises and customer-hosted instances, citing potential zero-day vulnerabilities. On Sunday, Kiteworks lifted the shutdown recommendation for most customers, allowing them to bring their systems back online. However, customers utilizing self-hosted Advanced Forms were instructed to contact customer support for assistance. The company clarified that the severe vulnerability is confined to its Advanced Forms product, which is used by fewer than 1% of its customers (under 50 organizations). Other Kiteworks products, including DPE, file collaboration, file transfer, email encryption, APIs, and MFT, remain unaffected. Kiteworks CISO Frank Balonis stated that the advisory was preventative, as there was no indication of compromise, and the company is collab...