Kiteworks lifted its precautionary shutdown advisory after patching a critical vulnerability and finding no signs that any customer or company systems were compromised. The company, formerly known as Accellion, warned customers after a federal intelligence alert, while threat researchers noted nearly 400 internet-exposed instances and past abuse of Accellion by the Clop group. #Kiteworks #Accellion #Clop
Keypoints
- Kiteworks asked customers to shut down systems after a warning of a possible imminent attack.
- The company later restored hosted systems after finding no evidence of compromise.
- A critical vulnerability in a low-use feature was patched and an extra protective layer was added.
- The flaw has not been assigned a CVE ID, and no exploitation has been confirmed.
- Kiteworks and its former Accellion platform have been targeted before by the Clop extortion gang.