09/04/2026
Remember last week when we talked about “computers that aren’t computers”? Well, we can add the office phone system to the list.
Researchers are seeing active exploitation of a critical vulnerability in Sangoma Switchvox, an enterprise VoIP platform used for business communications. The vulnerability can allow an attacker to execute code remotely without credentials, and researchers have observed attackers establishing reverse shells on compromised systems.
It’s a real-world reminder that cybersecurity isn’t limited to the devices we traditionally think of as computers. A business phone system is still software running on a network-connected system—and it can become part of your organization’s attack surface.
Organizations should maintain visibility into network-connected and internet-facing systems, clearly define patching responsibilities, use network segmentation to limit access, and monitor these systems for unusual activity.
At AGT, we help organizations understand their real-world attack surface and make sure security controls extend across the entire technology environment—not just the devices that immediately come to mind.
Sometimes the most important question isn’t, “Are our computers secure?”
It’s, “Do we know everything on our network that is actually a computer?”
Article: https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html
Attackers exploit a patched Switchvox SQL injection flaw to deploy reverse shells, with about 4,000 instances exposed online.