字号 ·· | 护眼
techcrunch

Kiteworks敦促客户在“迫在眉睫”的网络攻击威胁下关闭服务器Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack

点「原文对照」整页切到原文,或双击某段只看那段的原文。

科技巨头Kiteworks敦促客户关闭其系统,因为该公司收到信息称黑客可能试图针对他们发动攻击。

Technology giant Kiteworks is urging customers to shut down their systems after the company received information that hackers may attempt to target them.

Kiteworks(前身为Accellion)向TechCrunch证实,已就潜在威胁通知客户。该公司提供通过互联网传输大文件和敏感数据集的工具。德国出版物Heise独家首先报道了这一消息,并援引Kiteworks发给客户的电子邮件称,最早可能在本周末发生“迫在眉睫”的攻击。

Kiteworks (formerly Accellion), which makes tools for transferring large files and sensitive datasets over the internet, confirmed to TechCrunch that it had notified its customers about a potential threat. The news was first reported exclusively by German publication Heise, which cited an email that Kiteworks had sent to its customers about an “imminent” attack that could happen as soon as this weekend.

Kiteworks首席信息安全官Frank Balonis周五通过电子邮件回复TechCrunch时表示,该公司“从执法部门收到可信的威胁情报,显示威胁行为者可能试图针对部分客户的Kiteworks系统发动攻击”。

When reached by email on Friday, Kiteworks chief information security officer Frank Balonis told TechCrunch that the company “received credible threat intelligence from law enforcement indicating that a threat actor may attempt to target some Kiteworks systems for customers.”

Balonis表示:“出于高度谨慎,我们直接通知了客户,并建议设置预防性关闭窗口,同时我们与执法合作伙伴共同处理此事。”“我们不知道Kiteworks系统有任何遭入侵的情况,这份通知是预防性的,而不是对已确认入侵的回应。”当被问及是哪家执法机构向该公司发出警报,或哪个黑客组织可能是威胁幕后黑手时,Kiteworks没有说明。美国联邦调查局拒绝置评。当TechCrunch询问美国网络安全机构CISA对Kiteworks向客户发出警报一事时,该机构发言人Marco DiSandro不愿正式置评。

“Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter,” said Balonis. “We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach.” Kiteworks did not say, when asked, which law enforcement agency alerted the company or which hacking group may be behind the threat. The FBI declined to comment. Marco DiSandro, a spokesperson for U.S. cybersecurity agency CISA, would not comment on the record when asked by TechCrunch about the Kiteworks alert to customers.

Balonis表示,该公司已在其最新软件版本9.5.1中修复了所有已知漏洞,并建议所有客户使用该版本。

Balonis said that the company has fixed all known vulnerabilities in its latest software release, 9.5.1, which it recommends all customers use.

根据TechCrunch获得的一份周五发送给客户的电子邮件副本,该公司表示担心目前Kiteworks尚不知晓的漏洞遭到利用。这些漏洞被称为零日漏洞,因为它们没有给供应商——在这里指Kiteworks——留下在漏洞被利用前进行修复的时间。

According to a copy of the email sent to customers on Friday and shared with TechCrunch, the company said it was concerned about the exploitation of vulnerabilities that are currently unknown to Kiteworks. These bugs are known as zero-day flaws because they give the vendor — in this case Kiteworks — no time to fix the flaws before they are exploited.

在邮件中,Kiteworks敦促客户在周末前,如果不是更早的话,关闭他们的系统,以“防范任何潜在的零日攻击”,因为该公司无法确认是否存在其他不当访问的潜在途径。

In the email, Kiteworks urged customers to shut down their systems before the weekend, if not sooner, to “protect against any potential zero-day attacks,” as the company cannot confirm whether there are other potential routes for improper access.

目前尚不清楚具体有多少客户可能受到影响,但Kiteworks在其网站上指出,它在医疗保健、科技、教育、汽车和政府等领域拥有数千家客户。安全研究员Kevin Beaumont指出,目前网上至少有上千个面向互联网的Kiteworks系统列表,不过这个数字很可能高估了受影响的客户系统数量。

It’s unclear exactly how many customers may be affected, but Kiteworks notes on its website that it has thousands of customers across healthcare, technology, education, automotive, and government, among others. Security researcher Kevin Beaumont pointed to a listing of at least a thousand internet-facing Kiteworks systems online today, though the number is likely an overcount of affected customer systems.

一位在医疗保健领域工作的Kiteworks客户告诉TechCrunch,他们收到了Kiteworks的警报,并立即关闭了其组织的服务器。这位要求匿名的人士表示,此次宕机正在导致延误,并扰乱了医生联系患者的能力。

One Kiteworks customer who works in healthcare told TechCrunch that they received the alert from Kiteworks and took down their organization’s server immediately. The person, who asked not to be publicly named, said the outage is causing delays and disruption to doctors’ ability to contact their patients.

Kiteworks对网络攻击并不陌生。在2021年底从Accellion更名之前,其文件传输应用程序中的一个漏洞曾让一个勒索团伙大规模入侵并窃取了数百家组织的数据,这些组织依赖该产品通过互联网发送客户或企业内部数据。

Kiteworks is no stranger to cyberattacks. Prior to its rebrand from Accellion in late 2021, a vulnerability in its file-transfer application allowed an extortion gang to mass-hack and steal data from hundreds of organizations that relied on the product to send customer or internal corporate data over the internet.

这起大规模黑客攻击是针对文件传输产品的更广泛黑客行动的一部分,目的是窃取此前通过互联网发送但未从受影响服务器中删除的数据副本。黑客随后扣押这些数据以索取赎金,威胁如果受害组织不支付赎金,就公开客户的信息。

The mass hack was part of a broader hacking campaign targeting file transfer products, with the goal of stealing copies of the data that had been previously sent over the internet but not deleted from the affected servers. The hackers then held the data for ransom, threatening to publicly release customers’ information if the victim organizations did not pay a ransom.