No CVE, No Patch, Just Intel: Why Kiteworks Told Everyone to Unplug
TL;DR: Kiteworks told customers to unplug servers for nine hours on federal threat intel with no CVE attached, a different DPRK crew walked off with $351.6M from Bitget days after last week’s WaterPlum haul, and Windows malware now takes orders from a vote of AI models. Build a playbook for acting on intelligence with no patch available, and confirm your F5 BIG-IP APM patch actually took.
Kiteworks pushed a nine-hour precautionary shutdown across its customer base this weekend, and there’s no CVE behind it. CISO Frank Balonis said federal threat intelligence flagged a possible attack on Kiteworks systems: no confirmed compromise, no known exploit path, just credible intel from law enforcement. Kiteworks made the right call. A managed file transfer platform holding sensitive customer data, with Accellion and Clop still fresh in institutional memory, isn’t the box you leave running while you wait for confirmation you may never get.
I’ve made calls on less certainty than this. Every time, the annoying option — take it down, eat the downtime, explain it to the business — beat waiting for proof. If your org got that email and spent an hour figuring out who actually owns the “shut it down” decision, that gap is the finding, not the vulnerability. Write the playbook now: who authorizes an unscheduled outage on intel alone, what’s the notification chain, how fast can you physically pull the plug. This won’t be the last vendor email like it this year.
Following last week’s report on WaterPlum stealing $10.7 million through fake recruiter interviews, a different DPRK-linked crew compromised Bitget’s backend this week and took $351.6 million, thirty times the prior haul, this time through a straight infrastructure breach rather than social engineering. State-sponsored theft is funding a state at industrial scale, and every exchange running hot wallets without hard cold-storage segmentation is next quarter’s headline.
Cisco Talos found CLOSEDQUORUM, Windows malware that puts its next move to a vote among up to four AI models instead of phoning home to a fixed C2 server. No single point of command, no static infrastructure for detection to key on. This isn’t a research demo. It’s the AI-driven automation I’ve flagged in recent posts showing up in malware that’s already running.
F5 patched CVE-2026-94127, a critical unauthenticated RCE zero-day in BIG-IP APM when it’s deployed as an OAuth authorization server. Same product line that had a fileless rootkit living in memory two weeks ago. If BIG-IP APM is in your stack, this isn’t a “read the advisory” week, it’s a “confirm the patch applied and pull 30 days of logs” week.
Patch F5 BIG-IP APM today if you’re exposed. Then put it on paper: who in your org can order a shutdown on threat intelligence alone, with zero technical proof in hand. Kiteworks just showed you that decision doesn’t wait for a CVE, and neither should your answer.