Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
Kiteworks Ends Global Shutdown After Weekend Zero-Day Scare, Says Flaw Was Confined to Rarely-Used Forms Tool

Secure file-transfer company Kiteworks told customers around the world to shut their servers down over the weekend of September 26-27 after receiving what its Chief Information Security Officer, Frank Balonis, called "credible threat intelligence from federal intelligence authorities" warning that a threat actor might target Kiteworks systems.
The federal government's decision to issue such a specific warning to a private vendor, with enough weight behind it to trigger a worldwide shutdown, is not routine. It happened anyway, and Kiteworks acted on it.
What Actually Happened
On Friday, September 25, Kiteworks emailed customers recommending they power down self-managed systems, whether on-premises, on AWS, or on Azure, even if those systems weren't reachable from the internet. Kiteworks said it would shut down the customer systems it hosts directly, so hosted customers didn't need to lift a finger.
How long the window actually lasted depends on which report you read. Kiteworks's own advisory, cited by TechRadar, SecurityWeek, and cybersecurity firm rescana, described a nine-hour precautionary window. BleepingComputer, citing German outlet Heise, reported specific local times: a 10 p.m. Friday to 4 a.m. Saturday window in New York and a 4 a.m. to 10 a.m. window in Central Europe, both of which are six hours, not nine. Tech Times ran with the six-hour figure and reported the window closed at 4:00 a.m. ET Saturday, September 26. Neither figure was corrected on the record by Kiteworks in the material reviewed here, and the discrepancy remains unresolved.
On Sunday, September 27, Kiteworks lifted the recommendation. "All systems Kiteworks hosts on customers' behalf have been brought back up and are operating normally," the company said in its advisory.
The Actual Vulnerability
SecurityWeek reported that Kiteworks told customers by email the trigger was a severe vulnerability in Advanced Forms, a secure data-collection product. "Advanced Forms is enabled for fewer than 1% of our customers, under 50 organizations, and the vulnerability is confined to that product only," the email read, according to a copy shared on Reddit and cited by SecurityWeek. Kiteworks said file collaboration, file transfer, email encryption, APIs, and its managed file transfer product were unaffected.
Kiteworks said it has no evidence the vulnerability was exploited and that it's working with incident response firm Mandiant to share threat intelligence. Customers who self-host Advanced Forms were told to contact Kiteworks support directly, meaning that subset of under 50 organizations still had unfinished business after the broader shutdown recommendation was lifted.
Kiteworks also said the threat does not touch its other subsidiary brands, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder.
Where Tech Times Gets Ahead of the Facts
Tech Times, publishing Monday, September 28, framed the situation as an ongoing crisis, writing that "the prescribed window has closed but no patch or CVE exists, keeping at-risk systems in limbo" and that organizations "must now decide whether to restore service before Kiteworks and its law enforcement partners have declared the situation resolved."
That framing overlooked what Kiteworks and SecurityWeek had already reported by Sunday: the shutdown recommendation was lifted, systems were brought back online, and the root cause was traced to a specific product used by a small customer base, not an unresolved company-wide threat. It's true no Common Vulnerabilities and Exposures identifier has been publicly assigned to the Advanced Forms flaw, which is a fair thing to flag. But describing the broader customer base as still "at-risk" and "in limbo" doesn't match Kiteworks's own Sunday statement that hosted systems were back up and operating normally.
The Fair Concern, and What's Still Unclear
Security researchers have a legitimate gripe: with no CVE issued, the broader security community has no independent way to verify the scope or severity of the flaw, or to confirm Kiteworks's own account that it was confined to Advanced Forms. That's a real transparency gap, not a manufactured one. Several outlets, including Aviatrix and TechRadar, also raised the specter of the Cl0p ransomware gang, whose past campaigns hit managed file-transfer platforms MOVEit, Accellion, and GoAnywhere, and noted that Kiteworks was formerly Accellion. None of the sources reviewed confirm Cl0p involvement in this incident. That connection is speculation drawn from historical pattern, not an established fact, and should be read that way.
The FBI declined to comment when asked by reporters, and CISA did not respond to requests for comment, according to Tech Times. Neither agency has publicly detailed what intelligence triggered the original warning, why a six-hour window in some reports became a nine-hour window in official statements, or whether a CVE will eventually be assigned to the Advanced Forms flaw. Kiteworks has not said when, or whether, that identifier is coming.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.