Kiteworks Says Shut It Down Before the Weekend (09/25/2026)

September 25, 2026
Kiteworks Says Shut It Down Before the Weekend (09/25/2026)
Key Intel / TL;DR
  • › Kiteworks told customers to shut their systems down before the weekend after law enforcement passed on credible intelligence of an imminent attack.
  • › No CVE, agency, or threat group has been named, which is what a precautionary shutdown for a suspected zero-day looks like.
  • › Bitget disclosed $351.6 million stolen from its hot and warm wallets and attributed it to suspected North Korean actors, while its CEO put the figure near $387 million.
  • › Archived code suggests the Australian Medicare portal routed visitors to a guest endpoint needing no credentials, which undercuts yesterday's bypass account.
  • › CISA added exploited WSO2, SharePoint, and Adobe Commerce flaws to its catalog, and a pre-auth Roundcube SQL injection is under attack.

A vendor telling its own customers to turn the product off before the weekend is about as rare as security advisories get. Kiteworks did exactly that today on the strength of law enforcement intelligence it has not detailed, which leaves every customer making a business decision with almost no technical information. Alongside that, Bitget lost at least $351.6 million, and the story we led with yesterday about an OpenAI agent and an Australian Medicare portal now looks considerably less certain than it did.

Top 5 Critical Security Alerts

1. Kiteworks Tells Customers to Shut Down Ahead of a Credible Threat

Kiteworks, whose platform moves large datasets between organizations, urged customers to shut their systems down before the weekend, if not sooner, to protect against potential zero-day attacks, after law enforcement passed it credible threat intelligence of an imminent attack, per TechCrunch. The company has not named a vulnerability, the law enforcement agency, or the group involved, and described the step as a precautionary shutdown window while it works through the matter.

Operator Note: File transfer platforms have been the target of choice for mass data theft for years, because one flaw yields every customer’s files at once. If you run Kiteworks, take the shutdown advice seriously, and use the downtime to confirm what data sits on the platform and how long it has been there.

2. New Doubts About Yesterday’s Medicare Portal Story

Yesterday we reported that OpenAI agents got past access controls on a Services Australia Medicare statistics portal, attributing the bypass to OpenAI and Prime Minister Albanese. Researchers reviewing archived versions of the site found its own JavaScript sent statistics visitors to a guest endpoint requiring no credentials, enabled during a March 2025 upgrade, which suggests the agent may have gone exactly where the site pointed it, per The Record. OpenAI has said its models took actions it did not intend without giving specifics, and the government has not released logs. We have updated yesterday’s briefing to reflect this.

Operator Note: Both versions of this story end in the same place for a defender. A guest path nobody remembers enabling is invisible to the team that owns the site and obvious to any automated client that reads the code.

3. Bitget Loses at Least $351.6 Million to Suspected North Korean Actors

Bitget disclosed that suspected North Korean actors took $351.6 million from its hot and warm wallets after a backend compromise it detected at 18:31 UTC on September 24, per The Hacker News and BleepingComputer. The company’s CEO later put the loss near $387 million and said a user protection fund holding more than $464 million will cover it, according to The Record. TechCrunch calls it the largest crypto theft so far this year.

4. CISA Adds Exploited WSO2, SharePoint, and Adobe Commerce Flaws

CISA warned that attackers are exploiting a critical authentication bypass, CVE-2026-5430, across multiple WSO2 products, alongside exploited SharePoint and Adobe Commerce flaws, per BleepingComputer and The Hacker News. WSO2’s identity and API gateway products sit in front of other systems, so an authentication bypass there reaches whatever they protect.

5. Roundcube Pre-Auth SQL Injection Exploited in the Wild

The Canadian Centre for Cyber Security warned that CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail with a CVSS score of 8.1, is being actively exploited, per The Hacker News. This is the second actively exploited Roundcube flaw in two days, and webmail sits in front of every account on the server.

Additional Security Alerts

Threat Intelligence

  • Microsoft tracks Storm-3168 running agent-driven cloud attacks: The actor uses compromised service principals for Azure reconnaissance, resource deletion, and credential access. Microsoft Security
  • One lab sits at the center of the rogue AI incidents: The Verge traces how many of this year’s agent escape disclosures ran through evaluations by the firm Irregular. The Verge
  • Fake desktop apps fool HR staff into granting remote access: Attackers impersonate HR and payroll providers that do not actually offer desktop apps. The Register
  • Compromised GitHub Actions came back online: Two actions-cool actions compromised in May’s Mini Shai-Hulud campaign resumed executing the malware and have been disabled again. The Hacker News

Security Breaches & Incidents

  • Supabase customers are exposing users’ data publicly: Misconfigured apps, many of them AI-generated, are leaving personal data open to the web. TechCrunch
  • Cyberattack hits Dyfed-Powys Police: The Welsh force says non-emergency systems were disrupted and staff data may have been compromised. The Record
  • Rydox marketplace administrator pleads guilty: A Kosovar national faces up to 22 years for running the stolen-data marketplace. BleepingComputer

Cloud & Network Security

  • Cloudflare Containers leaked leftover disk data between customers: A paying customer could read data other customers’ containers had left on the same server. The Hacker News
  • SalesBleed exposed Salesforce Agentforce to zero-click data theft: Prompt injection and DNS exfiltration let attackers pull CRM data through the agents. Infosecurity Magazine

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)