Kiteworks patches critical flaw, brings customer systems online

Kiteworks patches critical flaw, brings customer systems online
Kiteworks lifted its precautionary shutdown advisory after patching a critical vulnerability and finding no signs that any customer or company systems were compromised. The company, formerly known as Accellion, warned customers after a federal intelligence alert, while threat researchers noted nearly 400 internet-exposed instances and past abuse of Accellion by the Clop group. #Kiteworks #Accellion #Clop

Keypoints

  • Kiteworks asked customers to shut down systems after a warning of a possible imminent attack.
  • The company later restored hosted systems after finding no evidence of compromise.
  • A critical vulnerability in a low-use feature was patched and an extra protective layer was added.
  • The flaw has not been assigned a CVE ID, and no exploitation has been confirmed.
  • Kiteworks and its former Accellion platform have been targeted before by the Clop extortion gang.

Read More: https://www.bleepingcomputer.com/news/security/kiteworks-lifts-shutdown-warning-after-patching-critical-flaw/