Kiteworks urges 6-hour server shutdown over potential zero-day attacks

2026-09-26T07:23:20Z•c7aa5164406e57fddd14c3e3638ce76c112e4309928b278bf18700ce25e91fd5
CVE-2026-5430AI agentsAdobe CommerceCSRFCarbonatoClopDockerElementorGitLabGrav CMSKiteworksMacSyncMicrosoft SharePointNorth KoreaWSO2WordPressactive exploitationcryptocurrency theftmacOS malwarepath traversalransomwaresupply chain securityzero-day

What happened

BleepingComputer security news highlights multiple active or high-impact threats, including suspected zero-day attacks against Kiteworks customers, exploitation of WSO2, SharePoint, and Adobe Commerce vulnerabilities, an Elementor WordPress CSRF flaw enabling administrator account creation, a Grav CMS path traversal compromise, macOS MacSync malware delivery via public iCloud calendars, and Carbonato malware targeting exposed Docker hosts. The feed also reports a major Bitget cryptocurrency theft attributed to suspected North Korean hackers and exposure of GitLab project email interfaces thatє

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c7aa5164406e57fddd14c3e3638ce76c112e4309928b278bf18700ce25e91fd5
Enrichment time
2026-09-26T07:23:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.