Category: News

Current, event-driven reporting, announcements and industry developments.

  • Sangoma Switchvox Flaw Under Active Exploitation as CISA Sets Federal Patch Deadline

    Sangoma Switchvox Flaw Under Active Exploitation as CISA Sets Federal Patch Deadline

    Threat actors are actively exploiting a critical vulnerability in Sangoma’s Switchvox enterprise VoIP phone system, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog and order federal civilian agencies to remediate it on an accelerated timeline, according to Horizon3.ai, SecurityWeek and CISA’s own advisory.

    An Unauthenticated Path to Remote Code Execution

    Tracked as CVE-2026-9586 and rated CVSS 9.3, the flaw sits in Switchvox’s /pa endpoint, which processes XML content from supported IP phones. According to research published by Horizon3.ai, the endpoint concatenates a user-controlled PhoneIP value directly into PostgreSQL queries without sanitization or parameterization, allowing an unauthenticated remote attacker to execute arbitrary SQL with a single crafted HTTP request. Horizon3.ai reported that exploitation can be chained into full remote code execution, including database modification, privilege escalation within the application, operating-system command execution and extraction of authentication secrets.

    Patch Timeline and a Compressed Federal Deadline

    Horizon3.ai said it reported the flaw to Sangoma in April 2026, and Sangoma shipped a fix in Switchvox 8.4.0.2 on July 14, 2026. Security firm Field Effect reported that researchers began observing exploitation attempts in the wild on August 30, 2026, including reverse-shell deployment and post-exploitation reconnaissance on compromised systems. CISA added CVE-2026-9586 to its KEV catalog on September 2, 2026, and set a September 5, 2026 remediation deadline for federal civilian agencies under Binding Operational Directive 26-04.

    Why It Matters

    Shodan scans cited by researchers show roughly 4,000 Switchvox systems reachable from the open internet. Because Switchvox functions as a business’s core telephony and call-management platform, a successful compromise can expose call records, credentials and internal network access alongside the immediate database and code-execution impact. Organizations running on-premises Switchvox deployments are advised to apply version 8.4.0.2 or later immediately, restrict management interfaces from the public internet, and review logs for indicators of compromise identified by Horizon3.ai and Field Effect.

  • NHTSA Opens Audit Into Tesla’s Cybercab Safety Self-Certification After Austin Launch

    NHTSA Opens Audit Into Tesla’s Cybercab Safety Self-Certification After Austin Launch

    The National Highway Traffic Safety Administration (NHTSA) has opened an Audit Query, numbered AQ26002, into the technical data and process Tesla used to self-certify that its new Cybercab complies with all applicable Federal Motor Vehicle Safety Standards (FMVSS), according to an NHTSA press release and reporting by the New York Times and Electrek. The investigation, opened September 3, 2026, covers an estimated 1,000 Cybercab vehicles and was prompted by public information, according to the filing.

    A Vehicle With No Manual Controls

    Cybercab has no steering wheel or pedals, and Tesla began putting paying passengers in the vehicles in Austin, Texas the same day the audit was opened. NHTSA said it will examine “the extent to which Tesla’s certification depended on determinations that certain FMVSS are inapplicable to the Cybercab,” according to Electrek, focusing on whether standards written for vehicles with traditional human controls can be validly waived for a fully autonomous design.

    How Self-Certification Works

    Under the US system, automakers certify their own compliance with federal safety standards rather than obtaining pre-approval from regulators, with NHTSA auditing that certification after the fact. The audit will assess the technical data and processes underlying Tesla’s compliance determination and how occupant protection is addressed in a vehicle operating without a human driver behind physical controls, according to NHTSA.

    Stakes for Tesla’s Robotaxi Rollout

    Tesla has said it plans to gradually expand Cybercab deployment to more vehicles and locations. The outcome of the audit could influence the pace of that expansion and is being closely watched as a test case for how federal vehicle safety standards, largely written around human-operated cars, apply to commercially deployed vehicles with no manual controls at all.

  • Nvidia Agrees to Buy Hugging Face for Roughly $13 Billion in Push Up the AI Stack

    Nvidia Agrees to Buy Hugging Face for Roughly $13 Billion in Push Up the AI Stack

    Nvidia has agreed to acquire open-source artificial intelligence platform Hugging Face for approximately $12.9 billion, according to CNBC, the Wall Street Journal and the BBC. The deal, confirmed on September 3, 2026, is Nvidia’s second-largest acquisition after its roughly $20 billion purchase of Groq’s assets late last year, and marks one of the chipmaker’s biggest moves yet to expand beyond hardware and further up the AI software stack.

    Deal Terms and Scale

    Under the agreement, Nvidia will pay about $11.9 billion to Hugging Face investors and offer up to $1 billion in stock-based incentives to employees who join the company, according to the BBC. Hugging Face is used by more than 18 million developers and hosts more than three million AI models, with over 200,000 companies using the platform to discover and deploy AI, the companies said.

    Nvidia Pledges to Keep the Platform Open

    Nvidia CEO Jensen Huang said in a blog post that the companies will “scale Hugging Face’s platform, strengthen its infrastructure and expand access to AI for developers and institutions worldwide,” and that Hugging Face will remain an open platform for the broader AI ecosystem rather than being tied exclusively to Nvidia chips or services, according to CNBC.

    Why It Matters for the AI Ecosystem

    The acquisition comes as Nvidia works to counter the rapid rise of open-weight models developed in China, which pose a growing competitive challenge to leading US AI companies, according to the Wall Street Journal. Industry observers noted the deal could be read either as a consolidation risk for an independent hub of open AI development, or, if Nvidia keeps its commitment to openness, as a boost to smaller developers and startups that rely on Hugging Face’s tooling and model hosting.

  • Public Comment Period Closes Today on Federal Rule Expanding Counter-Drone Authority for Local Police

    Public Comment Period Closes Today on Federal Rule Expanding Counter-Drone Authority for Local Police

    A federal rule that would give trained state, local, tribal and territorial (SLTT) law enforcement and correctional agencies formal authority to detect, track, disable or seize threatening drones closes for public comment on September 6, 2026, according to DRONELIFE. The Interim Final Rule, published by the Department of Homeland Security (DHS) and Department of Justice (DOJ), is the first detailed implementing regulation for counter-unmanned aircraft system (C-UAS) powers created under the SAFER SKIES Act, part of the FY2026 National Defense Authorization Act.

    Certification, Training and Two Approved-Systems Lists

    The rule sets out training and certification requirements, reporting procedures and operational safeguards for agencies seeking to conduct counter-drone operations against credible threats to public safety, critical infrastructure, correctional facilities or major public events. It also establishes an Authorized Technologies List and a more specific Authorized Systems List, both to be maintained through the FBI’s Law Enforcement Enterprise Portal, identifying which categories and specific counter-UAS products agencies may lawfully deploy.

    FCC Actions Address Spectrum and Legal Liability

    Alongside the DHS/DOJ rule, the Federal Communications Commission issued four coordinated actions intended to remove practical barriers to deployment. These include a 180-day blanket Special Temporary Authority letting eligible agencies operate approved counter-UAS systems while longer-term licensing is developed, an equipment-authorization waiver allowing manufacturers to sell approved radio-frequency systems to qualified agencies sooner, and declaratory rulings clarifying that SLTT personnel acting under the Act’s oversight can receive derivative immunity from Section 333 of the Communications Act, which otherwise prohibits interference with licensed radio communications.

    Guardrails Remain in Place

    The frameworks do not authorize unrestricted counter-drone activity. Agencies must still meet federal certification requirements, use only systems on the Authorized Systems List, follow operational restrictions written into the SAFER SKIES Act, and report qualifying mitigation actions to federal authorities. With the comment period closing today, stakeholders across the public safety, drone and counter-UAS industries have had a final opportunity to weigh in before the rule is finalized.

  • Geutebrück Enters New Ownership Phase With IBEX and Merantix Momentum Investment

    Geutebrück Enters New Ownership Phase With IBEX and Merantix Momentum Investment

    German video security specialist Geutebrück is entering a new corporate phase after receiving a majority investment from IBEX Wachstumspartner, alongside European AI group Merantix Momentum, according to Security Info Watch and confirmed by law firm Schmitz Knoth, which advised Geutebrück’s shareholders on the transaction. The deal closed on August 31, 2026.

    New Leadership and International Ambitions

    As part of the transition, Tobias Huemmerich will take over management of the company, with plans to further internationalize the business and expand its customer offering, according to Security Middle East. Geutebrück has operated in the video security market for more than 55 years and has built a reputation as a provider of video management software and hardware for public-sector and highly critical infrastructure clients.

    Merantix Momentum Brings AI Expertise

    Merantix Momentum, described as Europe’s leading AI group, is joining the investment specifically to help Geutebrück develop new AI-based applications, according to the companies. Geutebrück has said it sees opportunities to extend its video management platform beyond traditional security use cases, including the potential use of anonymized video data to identify workflow efficiencies and improve occupational safety.

    Part of a Broader Consolidation Trend

    The investment adds to a string of ownership changes across the video surveillance sector as manufacturers seek capital and AI expertise to keep pace with larger competitors. IBEX Wachstumspartner, an owner-managed investment firm focused on succession situations at German medium-sized businesses, said the deal reflects its strategy of pairing growth capital with digitalization expertise for established technology companies entering a generational transition.

  • OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders

    OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders

    OpenAI is committing $1 billion to subsidize access to its cyber-capable AI models for critical infrastructure defenders and launching a center to train security professionals in the U.S. public sector, as part of an expansion of its Daybreak program, the company said.

    What’s New

    The Daybreak Defense Network will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about specific costs or eligibility criteria. The company has selected HackerOne as one of a limited group of cybersecurity vendors with early access to its frontier cyber capabilities through the network. OpenAI co-founder Greg Brockman has separately published a blog post describing the use of AI agents to find and fix security vulnerabilities.

    Why It Matters

    “There are a large amount of people and organizations that want to uplevel their security, but they don’t know how,” Brockman said, adding that without broader adoption of AI-assisted defense, “it’s possible we can expect critical infrastructure outages as part of normal life.” The pledge follows a separate letter signed by OpenAI, Anthropic, Google, Microsoft and more than 100 other companies calling for coordinated industry defense against AI-driven cyber threats, and reflects a wider push by frontier AI labs to position their models as tools for under-resourced defenders in sectors like water, energy and healthcare.

  • NAPCO Releases Prima v8 App With New Security Controls

    NAPCO Releases Prima v8 App With New Security Controls

    September 4, 2026 — NAPCO Security Technologies has released Prima v8, a redesigned mobile app for its Prima self-contained smart security systems. The update adds revised security controls, biometric authentication, expanded notification settings and an Apple Watch companion app.

    What Changed in Prima v8

    The new version reorganizes navigation and rebuilds core workflows for arming, device control and account management. Security screens provide clearer entry and exit countdowns, alarm details and sensor status information. Users can also manage connected lights, locks, garage doors, water valves and thermostats from the app.

    NAPCO says existing users can install the update without creating a new account or re-pairing their system devices. Credentials, configurations and device pairings are intended to carry over. The Apple Watch companion app supports arming and disarming from the watch, while revised settings give users more control over push, email and SMS notifications.

    Why It Matters

    Residential and small-commercial security platforms increasingly combine alarm status, connected-device control and account administration in one mobile interface. A clearer workflow can reduce routine friction for users and installers, but app convenience does not replace professional system design, reliable communications or an appropriate alarm-response plan.

    The release follows the wider shift toward software-led management of intrusion and connected-building systems. For background on the underlying sensors and control architecture, see SectechMedia’s guide to intrusion detection and alarm systems.

    Sources

  • FOSA Webinar to Explore DTS for Early Fault Detection in Solar PV and Underground Cables

    FOSA Webinar to Explore DTS for Early Fault Detection in Solar PV and Underground Cables

    SAMM Technology (SAMM Teknoloji İletişim A.Ş.) is taking part in an upcoming webinar hosted by the Fiber Optic Sensing Association (FOSA), addressing how Distributed Temperature Sensing (DTS) can support early fault detection across solar photovoltaic (PV) installations and underground power cable networks.

    The webinar, titled “DTS for Modern Energy Systems: Early Fault Detection Across Solar PV and Underground Cables,” takes place on September 2, 2026, at 9:00 AM EDT (13:00 UTC), hosted online via Zoom by FOSA, the US-based non-profit industry association focused on advancing distributed and quasi-distributed fiber optic sensing technologies.

    SAMM Technology on the Panel

    Representing SAMM Technology, Mark Horton, the company’s International Operations Director, joins the session alongside Ralf Albrecht of AP Sensing, with Dane Langen of Luna Innovations moderating. According to FOSA’s own event announcement, the panel will discuss how DTS technology is being applied to monitor modern energy infrastructure, with a focus on practical approaches to early fault detection in solar PV installations and underground power cable networks.

    In its own announcement of the participation, SAMM Technology said the webinar “provides an excellent opportunity to share knowledge, discuss emerging trends, and demonstrate how innovative monitoring technologies are supporting the future of energy systems,” adding that it was “proud to see Mark Horton representing SAMM Technology on this distinguished panel.”

    Why DTS for Solar PV and Underground Cables

    Distributed Temperature Sensing turns a standard optical fiber into a continuous string of temperature sensors along its full length, without the need for external power at the sensing points. For underground and solar PV power infrastructure, that capability is particularly relevant: temperature anomalies along a cable route or within a PV installation can be early indicators of developing faults, hotspots, or degrading connections — issues that are otherwise difficult to catch before they cause an outage or safety incident. Panel discussions on this topic typically cover how real-time DTS monitoring data feeds into asset reliability programs, operational efficiency, and system safety practices for energy operators.

    How to Attend

    The FOSA webinar is scheduled for September 2, 2026, 9:00 AM EDT (13:00 UTC), and will be held online via Zoom. Registration details are available through FOSA’s website.

    This article is based on SAMM Technology’s own announcement of its webinar participation (dated August 5, 2026) and FOSA’s official event promotional graphic and public webinar listing.

  • Meta Tests Robots From Watney, Kinova and ABB to Automate Data Center Maintenance

    Meta Tests Robots From Watney, Kinova and ABB to Automate Data Center Maintenance

    Meta is piloting robots from three vendors, Watney Robotics, Kinova and ABB, to handle physical maintenance tasks inside its data centers, including swapping network cables, power-cycling servers, reseating components and inspecting equipment, according to an August 31, 2026 report from WIRED based on current and former employees familiar with the trials.

    What the Robots Are Doing

    At Meta’s Altoona, Iowa campus, a pair of dual-armed Watney robots has been tested on cabling work since June 2025, supervised by human operators and still slower than a person, per the report. At the Prometheus campus in New Albany, Ohio, four-wheel ABB robots equipped with a scissor-lift riser and a six-axis arm are being used to reseat hardware components, and Meta is separately evaluating a Kinova Gen3 robotic arm for power-cycling servers. Meta has also deployed simpler robots that remotely restart devices by physically pressing power buttons. Kinova and ABB declined to comment to WIRED, and Watney did not respond to the outlet’s requests for comment.

    Why It Matters

    One Meta data-center worker told WIRED that a working cable-swapping system could eventually take on as much as 80% of some technicians’ current workload, though that figure is an employee estimate rather than a company-published target, and the robots still struggle with dense cabling, tight corners and tasks that require sustained autonomy. As AI-driven data center buildouts accelerate, the trials point to facility operations and physical security converging with the same automation trends reshaping server hardware itself.

  • Report: Security Leaders Overconfident on Authentication Even as Modernization Stalls

    Report: Security Leaders Overconfident on Authentication Even as Modernization Stalls

    A new report from rf IDEAS and Wavelynx has found that most security leaders believe their organizations are more advanced than industry peers on authentication, even though barely a quarter describe their systems as largely modernized, according to the 2026 State of Authentication Modernization Report published August 31, 2026.

    Key Findings

    The survey of 500 IT and security leaders at mid-sized to enterprise organizations found 93% believe their authentication and security maturity outpaces their industry peers, yet only 24% said their systems are largely modernized and 53% have not significantly updated authentication systems in at least three years. While 78% called modernization a high priority for the next 12 months, only 72% of managers closer to day-to-day execution agreed it was a high priority, and 27% cited unclear return on investment as a barrier. Among organizations that do prioritize the work, 55% plan to allocate at least $500,000 to it, but credential and authentication upgrades ranked eighth among security initiatives overall, behind higher-profile priorities.

    Why It Matters

    Forty percent of respondents estimated that a breach involving unauthorized access would cost their organization less than $1 million, well below the $4.4 million global average cost of a data breach reported for 2025. rf IDEAS and Wavelynx said the gap between confidence and readiness underscores the need to treat physical and logical access control as a single modernization effort rather than two separate budgets.