Threat Brief — 2026-09-03 — Supply-chain scars and widening scans
Executive summary: Active mass-scanning of the Sangoma Switchvox unauthenticated RCE has begun, confirming the vulnerability is moving from disclosure to broad exploitation. A Dark Reading discussion raises questions about whether ShinyHunters may have breached ReliaQuest. A ThreatsDay roundup highlights CEO phishing kits and OAuth consent-phishing traps as growing attack vectors that blend into normal business workflows.
Top items
- Switchvox unauthenticated RCE now mass-scanned in the wild. Automated scanners are actively probing for the critical Switchvox PBX vulnerability that accepts XML and returns a shell. This marks escalation beyond the earlier CISA KEV listing — attackers are now sweeping for exposed instances at scale. The vulnerability was first reported 2026-09-02 by The Hacker News when it was confirmed in CISA KEV. (src: SecurityLab)
- Dark Reading editors question whether ShinyHunters breached ReliaQuest. A video discussion covers the latest activity attributed to ShinyHunters, including the question of whether the threat actor successfully breached ReliaQuest, alongside research on the prevalence (or lack thereof) of AI-generated malware. The findings do not confirm a breach — they frame it as an open question. (src: Dark Reading)
- ThreatsDay roundup: CEO phishing kits and OAuth consent traps gaining traction. A compilation highlights attacker use of legitimate tools and workflows — IT calls, shared files, trusted apps, and OAuth "Allow" prompts — to gain access without technical exploitation. CEO phishing kits and OAuth consent-phishing are presented as increasingly common entry vectors alongside the previously reported Dropbox account compromises. (src: The Hacker News)
Themes
Social engineering at scale. The ThreatsDay roundup and the ongoing "Phantom Deal" M&A scam campaign both illustrate attackers investing heavily in contextually convincing lures — fake executives, fake IT calls, fake file shares — rather than relying on technical exploits alone. The barrier to credible phishing continues to lower.
Exploitation velocity increasing. The Switchvox mass-scanning development underscores how quickly critical PBX and network-edge vulnerabilities move from advisory to active sweeps. Organisations with internet-exposed unified communications infrastructure face a narrowing remediation window.
