Threat Brief — 2026-09-26 — Kiteworks extends shutdown, Roskomnadzor acts on MikroTik
Executive summary: Kiteworks has updated its emergency guidance, now urging customers to shut down systems for nine hours over the weekend—up from the six hours cited yesterday—after receiving credible threat intelligence about an imminent attack. Separately, Russia's telecom regulator Roskomnadzor is recommending ISPs restrict unpatched MikroTik routers, a regulatory escalation for a vulnerability already known to be exploited in the wild. A new operational risk for Russian financial institutions also emerged: banks may lose the ability to reach clients by phone after an October 15 deadline.
Top items
- Kiteworks extends recommended shutdown window from 6 to 9 hours. Kiteworks (formerly Accellion) received credible threat intelligence about an imminent cyber attack and is now urging customers to shut down their systems for nine hours over the weekend as a precaution, an increase from the six-hour window reported yesterday. No CVE or exploit details have been published; the guidance remains precautionary. (src: The Hacker News)
- Roskomnadzor recommends ISP-level restrictions on unpatched MikroTik devices. Russia's State Radio Frequency Center (GRChTs) is advising ISPs to warn owners of vulnerable MikroTik routers and temporarily close dangerous ports on unpatched devices. This is a regulatory response to a MikroTik RouterOS vulnerability that has been actively exploited and was added to CISA's KEV catalog earlier this month (first reported 2026-09-04 by SecurityLab). The development marks a shift from vulnerability advisory to mandated ISP-level mitigation. (src: SecurityLab)
- Russian banks face October 15 deadline for client phone outreach. Sber, VTB, and Alfa-Bank may be unable to reach clients by phone starting October 15 unless the financial sector resolves an ongoing regulatory conflict by that date. This is an operational continuity risk for institutions that rely on outbound calls for fraud alerts, verification, and customer service. (src: SecurityLab)
Themes
Regulatory escalation on known-exploited vulnerabilities. The Roskomnadzor action on MikroTik follows a pattern of national regulators moving beyond advisories to impose network-level restrictions on unpatched infrastructure. Where CISA's KEV catalog drives US federal remediation deadlines, the Russian approach places the burden on ISPs to enforce compliance at the network edge—a model that could constrain connectivity for non-compliant devices rather than merely flagging them.
