Kiteworks, the secure file-sharing and managed file transfer vendor formerly known as Accellion, has lifted a precautionary shutdown advisory issued to customers after patching a critical vulnerability. The company had urged customers worldwide over the weekend to temporarily take their servers offline following a warning from federal intelligence authorities about a potentially imminent cyberattack.

Kiteworks operates a Private Content Network (PCN) that combines enterprise email, file sharing, managed file transfer, APIs, and web forms into a single platform, serving thousands of corporations and government agencies with more than 100 million end-users across its Private Data Network.

On Monday, Kiteworks confirmed that all hosted customer systems were restored after continuous monitoring during the shutdown window turned up no abnormal activity. The company said it has no indication that any Kiteworks or customer system was compromised.

“As of September 27th, the shutdown recommendation is now lifted for all customers,” Kiteworks said in an update to its original advisory, adding that customers who had not yet restarted could safely bring their systems back online.

Critical Flaw in Niche Feature

The vulnerability that prompted the advisory affected an unnamed feature used by less than 1% of Kiteworks customers. The company said it developed and deployed a fix during the shutdown window and applied an additional protective layer across all environments. Kiteworks has found no indication the flaw was ever exploited and stated that all other products were unaffected.

Customers running self-hosted Kiteworks Advanced Forms have been advised to contact support for further assistance. The company has not yet released technical details about the vulnerability and has not assigned it a CVE ID.

Threat intelligence group Shadowserver has identified nearly 400 internet-exposed Kiteworks instances, with 234 located in the United States, though it has not specified how many are honeypots or already patched.

A History With Clop

File-sharing platforms are frequent targets for data-theft extortion because they store sensitive documents at scale. Kiteworks, under its former Accellion name, was previously hit by the Clop extortion gang in zero-day attacks against its legacy File Transfer Appliance (FTA) software. That campaign affected roughly 100 of Accellion’s 300 FTA customers, with victims including Qualys, Shell, the Reserve Bank of New Zealand, Kroger, Singtel, and several government bodies and universities. The Five Eyes intelligence alliance issued a joint advisory in February 2021 urging affected organizations to restrict internet access to vulnerable servers.

Security teams running Kiteworks should confirm patch status, review Advanced Forms configurations if self-hosted, and monitor for any indicators of compromise despite the vendor’s assurance that no exploitation occurred.