ITsecurity Daily
Daily Briefing
Kiteworks tells customers to power down servers Saturday over warning of a potential attack
Good morning. Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window, BleepingComputer reported, after the secure file-sharing company received threat intelligence warning of a potentially imminent cyberattack. Frank Balonis, CISO at Kiteworks, told Recorded Future News the company "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers." If you run Kiteworks, treat the vendor's six-hour shutdown window as the stated mitigation and plan for it now.
CISA added one new vulnerability to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation: CVE-2026-87902, a WordPress Core Remote File Inclusion vulnerability, per CISA's alert. CISA notes this class of flaw is a frequent attack vector, and points to Binding Operational Directive 26-04 for prioritising updates. Match your estate against the affected product and prioritise accordingly.
Separately, BleepingComputer reported a cross-site request forgery vulnerability in the Elementor plugin for WordPress that could allow an unauthenticated attacker to create administrator accounts. If you run WordPress with Elementor, review your admin account list.
Zoom out: Two of the day's headline items — the KEV addition and the Elementor flaw — sit in the WordPress ecosystem, alongside separate extortion-crew activity.
Elsewhere
- Krebs on Security: U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions Read it
- BleepingComputer: Kiteworks urges 6-hour server shutdown over potential zero-day attacks Read it
- CISA: CISA Adds One Known Exploited Vulnerability to Catalog Read it
- The Record: Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings Read it
- The Register: ShinyHunters tells The Reg: We hacked the FBI to 'protect our business' Read it
- BleepingComputer: Elementor WordPress flaw lets attackers create admin accounts Read it
- The Register: Crooks use fake desktop apps to fool HR staff into giving them remote access Read it
- BleepingComputer: CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks Read it
- The Register: Bitget blames North Korea for $387.5M crypto wallet raid Read it
- BleepingComputer: Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions Read it
- CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog Read it
- The Record: Crypto CEO accuses North Korea of stealing $387 million from Bitget platform Read it
Sources
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions Krebs on Security
- Kiteworks urges 6-hour server shutdown over potential zero-day attacks BleepingComputer
- Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee Schneier on Security
- Kiteworks urges customers to stop using platform after warning from federal intelligence agencies The Record
- Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script The Register
- In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure SecurityWeek
- Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware The Hacker News
- Threat detection dashboards are masking security coverage gaps Help Net Security
- CISA Adds One Known Exploited Vulnerability to Catalog CISA
- ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw BleepingComputer
- Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings The Record
- ShinyHunters tells The Reg: We hacked the FBI to 'protect our business' The Register
- Elementor WordPress flaw lets attackers create admin accounts BleepingComputer
- Crooks use fake desktop apps to fool HR staff into giving them remote access The Register
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Every briefing is on the site, with the advisory record behind it. All briefings