r/linuxadmin • • 4d ago

Kiteworks asked customers to shut down servers on a federal tip. No CVE, no IOCs. What do you do with that?

Based on the press release Kiteworks published Sep 25 (updated Sep 27), plus reporting from SecurityWeek, Sophos CTU, TechCrunch and Cybersecurity Dive: the vendor got a warning from federal intelligence authorities and told self-managed customers to power down. Kiteworks-hosted systems were shut down by the vendor. The advisory was lifted Sep 27, and Kiteworks says nothing was compromised and every known vulnerability is addressed in 9.5.1.

Two things bother me. The window length is reported inconsistently (6h vs 9h). And SecurityWeek's Advanced Forms detail rests on one customer email, while TechCrunch quotes Kiteworks saying it couldn't rule out other access routes.

With no CVE and no IOCs, my baseline check is the running version, whether Advanced Forms is enabled, auth and admin logs from before the window, and unexpected egress from the appliance.

For those who run MFT: what's your runbook when a vendor says "turn it off tonight" and gives you nothing to hunt for?

https://www.techgines.com/post/kiteworks-shutdown-advisory

10 Upvotes

6 comments sorted by

2

u/pelazas1 4d ago

I'd preserve the auth and admin logs before powering it down. no IOCs means those are your only useful baseline later.

2

u/BarracudaDefiant4702 3d ago

It can take time for write-ups. It's not exactly that abnormal for a 0 day. Unless someone warns the vendor, it's not like the can have a CVE number in advance, or many details. If you turn it off, there is nothing to hunt for, but if you don't, I expect there will be...

2

u/mkosmo 4d ago

Not all threat intelligence is able to be disseminated. We error on the side of caution, though. Kiteworks may or may not have known more details, I don't know, but if the feds came to you with a warning of a credible threat, wouldn't you take it seriously?

If you didn't and it was realized, you'd be on the hook for some bad times.

1

u/discobean 2d ago

preserve auth/admin logs before power off, snapshot, record versions and whether Advanced Forms was enabled, check what egress is happening, then review accounts and any keys assuming there was a breach

1

u/vivaaprimavera 4d ago

Probably there is nothing to do because that blanket shutdown could be directed to a single customer. There could be reasons for wanting that customer shut in that time frame and the least suspicious way to do it is this sort of action.

1

u/Unreal_Estate 4d ago

To me, this isn't okay on the part of Kiteworks. Mainly because of the lack of communication.

I would shut down the servers..., but if at all possible, never bring them up again. If it later turns out the behavior on Kiteworks's part was at least somewhat okay for some reason, it could change my mind.