Back to blog
Deal Diligence 2 min read

Cyber Friday - Sept 4, 2026

Cyber Friday - Sept 4, 2026
YJ

Yasmine Johnston-Ison

This week, the threats came for the tools small businesses use every single day — and the data they're trusted to protect.

  • SMB phone systems under active attack: A critical unauthenticated vulnerability (CVE-2026-9586, CVSS 9.3) in Sangoma Switchvox — the VoIP platform built for small and mid-size businesses — is being actively exploited. CISA added it to its Known Exploited Vulnerabilities catalog with a federal patch deadline of September 5. Roughly 4,000 instances are internet-exposed. (The Hacker News)
  • 153 million driver's licenses for sale: The FBI is investigating a new dark-web service selling digital scans of over 153 million U.S. and Canadian driver's licenses. If your business collects customer IDs — rentals, healthcare, financial services — your data is already in the pool. (SecurityWeek)
  • Ransomware keeps hitting small operators: The Akira ransomware group claimed Congressional Iron Works, a Baltimore-Washington metals contractor, and Flex1, a desktop-as-a-service provider — exactly the kind of mid-market businesses searchers evaluate. (HookPhish)

The deal lens: A new industry report found that 96% of ransomware victims are small and mid-size businesses. When you're buying a company, cyber posture isn't an IT checklist item — it's deal risk. An unpatched phone system, a vendor with weak data handling, or a single ransomware incident can turn a clean-looking acquisition into a six-figure cleanup. Diligence that skips cyber is diligence that skips the biggest threat to the business you're about to own.

What's the cyber question you always ask in diligence — and the one you wish you'd asked sooner?

#CyberSecurity #ThreatIntel #SMBAcquisition #DueDiligence


Sources:

  • Switchvox exploit: The Hacker News · CISA KEV alert (Sep 2) · Horizon3 disclosure · eSecurityPlanet — ~4,000 exposed
  • 153M driver's licenses: Krebs on Security (primary source) · Malwarebytes
  • Akira claims: HookPhish — Congressional Iron Works · HookPhish — Flex1 · DeXpose — Congressional Iron Works · DeXpose — Flex1
  • 96% stat: Verizon 2026 DBIR, via Cyber Readiness Institute
  • To verify before posting: the Sept 5 federal patch deadline in the CISA KEV catalog

Need Structured Guidance for Your Acquisition?

Book a 45-minute strategy call with our team to discuss your search progress, deal thesis, or transition plans.

Book an Appointment

45 minutes to confirm fit and define next steps.