CYBER FRI — Phone systems, identity data & ransomware's supply chain toll

This week's threat landscape hit the tools businesses use every day — and the data they're trusted to protect.

  • SMB phone systems under active attack: A critical unauthenticated vulnerability (CVE-2026-9586, CVSS 9.3) in Sangoma Switchvox — the VoIP platform used by small and mid-size businesses — is being actively exploited. CISA added it to its Known Exploited Vulnerabilities catalog with a federal patch deadline of September 5. Roughly 4,000 instances are internet-exposed. (The Hacker News)

  • 153 million driver's licenses for sale: The FBI is investigating a new dark-web service selling digital scans of over 153 million U.S. and Canadian driver's licenses. If your organization collects customer IDs — rentals, healthcare, financial services — your data is already in the pool. (SecurityWeek)

  • Ransomware keeps hitting mid-market operators: The Akira ransomware group claimed Congressional Iron Works, a Baltimore-Washington metals contractor, and Flex1, a desktop-as-a-service provider — exactly the kind of mid-market vendors and service providers that enterprise supply chains depend on. (HookPhish)

The executive lens: The Verizon 2026 DBIR found that 96% of ransomware victims are small and mid-size businesses. For executives, that's not a footnote — it's a supply chain risk. The same mid-market vendors you depend on for facilities, IT services, and logistics are the ones ransomware groups are targeting. An unpatched phone system at a vendor, a breach at a service provider, or a single ransomware incident in your supply chain can cascade into operational disruption, data exposure, and regulatory fallout. Threat intelligence programs that only track direct attacks on the enterprise are missing the larger attack surface.

For threat intel analysts:

  • Sangoma Switchvox KEV — Active exploitation is confirmed. If your asset inventory includes VoIP systems (Sangoma or adjacent vendors), prioritize patch verification now. The attack chain includes SQL injection leading to RCE — check for exposure beyond the primary CVE.

  • 153M driver's license trove — Suspected IDScan.net breach. Assess whether your organization's identity verification vendor exposure overlaps. If you use IDScan or a downstream provider, initiate incident review and check for credential exposure in your customer onboarding pipeline.

  • Akira supply chain targeting — Continued targeting of DaaS and construction firms signals that service-provider attacks are accelerating. Map your third-party dependencies against Akira's victim patterns. The group claimed 35GB at Congressional Iron Works and 402GB at Flex1 — both suggest deep access and extended dwell time.

What's the threat your organization is underestimating because it's happening to a vendor, not to you?

Sources (internal reference — don't post):

Previous
Previous

Trust Is the Attack Surface

Next
Next

Modernizing the Threat Intelligence Lifecycle: Why Excel is Failing Your CTI Team