ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Newsletters › Past editions › ITsecurity Daily — Friday, 25 September 2026: Kiteworks tells customers to power down servers Saturday over warning of a potential attack

ITSECURITY.GURU

ITsecurity Daily

Daily Briefing

Kiteworks tells customers to power down servers Saturday over warning of a potential attack

Good morning. Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window, BleepingComputer reported, after the secure file-sharing company received threat intelligence warning of a potentially imminent cyberattack. Frank Balonis, CISO at Kiteworks, told Recorded Future News the company "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers." If you run Kiteworks, treat the vendor's six-hour shutdown window as the stated mitigation and plan for it now.

CISA added one new vulnerability to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation: CVE-2026-87902, a WordPress Core Remote File Inclusion vulnerability, per CISA's alert. CISA notes this class of flaw is a frequent attack vector, and points to Binding Operational Directive 26-04 for prioritising updates. Match your estate against the affected product and prioritise accordingly.

Separately, BleepingComputer reported a cross-site request forgery vulnerability in the Elementor plugin for WordPress that could allow an unauthenticated attacker to create administrator accounts. If you run WordPress with Elementor, review your admin account list.

Read the full briefing →

Zoom out: Two of the day's headline items — the KEV addition and the Elementor flaw — sit in the WordPress ecosystem, alongside separate extortion-crew activity.

Elsewhere

  • Krebs on Security: U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions Read it
  • BleepingComputer: Kiteworks urges 6-hour server shutdown over potential zero-day attacks Read it
  • CISA: CISA Adds One Known Exploited Vulnerability to Catalog Read it
  • The Record: Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings Read it
  • The Register: ShinyHunters tells The Reg: We hacked the FBI to 'protect our business' Read it
  • BleepingComputer: Elementor WordPress flaw lets attackers create admin accounts Read it
  • The Register: Crooks use fake desktop apps to fool HR staff into giving them remote access Read it
  • BleepingComputer: CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks Read it
  • The Register: Bitget blames North Korea for $387.5M crypto wallet raid Read it
  • BleepingComputer: Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions Read it
  • CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog Read it
  • The Record: Crypto CEO accuses North Korea of stealing $387 million from Bitget platform Read it

Sources

Every briefing is on the site, with the advisory record behind it. All briefings

You are receiving this because you subscribed at itsecurity.guru.

Headlines from other outlets belong to them; each one credits its outlet and leads to their own report.

All past editions · Get them by email