Kiteworks tells customers worldwide to shut down servers for six hours after a federal warning of an imminent attack
The secure file-sharing vendor says it knows of no compromise and calls the shutdown preventative.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.
Secure file-sharing company Kiteworks urged customers worldwide to take their systems offline for a six-hour window on Saturday, September 26, after receiving what CISO Frank Balonis called credible threat intelligence from federal authorities that a threat actor may attempt to target some customer systems. The customer email, first reported by Heise, said an attack 'may be imminent this weekend.' In Central Europe the window ran from 4:00 to 10:00 a.m. Saturday; in New York, from 10:00 p.m. Friday to 4:00 a.m. Saturday. Customers were told to shut down even systems not directly reachable from the internet, BleepingComputer reported. Balonis told The Record the company is not aware of any compromise and described the advisory as preventative, adding that all known vulnerabilities are addressed in the current release, 9.5.1. Kiteworks did not answer whether a CVE exists or which groups might be involved, and the FBI declined to comment. The Hacker News headline describes a nine-hour window, a discrepancy with other reports. Kiteworks software is used for confidential communications, so organizations that rely on it face both a planned outage and uncertainty about the underlying threat.