Sandro Gauci (@sandrogauci) 's Twitter Profile
Sandro Gauci

@sandrogauci

Offensive VoIP/WebRTC security; mostly harmless

enablesecurity.com/blog
Chief Mischief Officer @enablesecurity
savvycal.com/sandrogauci/pub

ID: 12869202

linkhttps://www.enablesecurity.com calendar_today30-01-2008 10:46:43

2,2K Tweet

3,3K Followers

1,1K Following

Sandro Gauci (@sandrogauci) 's Twitter Profile Photo

Your favourite VoIP and WebRTC security newsletter for this month is out! My favorite this time was the presentation by Meta on hacking Messenger, given at Hexacon 2024. 🤓 Contributions to RTC security: Max Moser, Vivek Ramachandran, @[email protected], Shawn Merdinger, Pascal Zenker, Willy R. Vasquez (@[email protected]) and more!

Enable Security (@enablesecurity) 's Twitter Profile Photo

🔐 2024 in #WebRTC & #VoIP Security: Great progress with increased research focus, OWASP coverage & conference talks, but concerns remain around conferencing platforms & VoIP vulnerabilities. Read our year-end newsletter wrap-up! enablesecurity.com/newsletter/202…

Sandro Gauci (@sandrogauci) 's Twitter Profile Photo

From Grandstream GDMS compromise to Mitel vulnerabilities - crucial insights for anyone working with WebRTC & VoIP. Great summary by Enable Security. Subscribe here: enablesecurity.com/subscribe

Mathy Vanhoef (@vanhoefm) 's Twitter Profile Photo

After an embargo of 8 months, we are glad to finally share our USENIX Security '25 paper! We found more than 4 MILLION vulnerable tunneling servers by scanning the Internet. These vulnerable servers can be abused as proxies to launch DDoS attacks and access internal networks.

Enable Security (@enablesecurity) 's Twitter Profile Photo

January 2025 RTCSec newsletter out now! Covers Cisco BroadWorks SIP vulnerability, Asterisk fixes, Wordpress plugin, Samsung Galaxy S24, VoIP and WebRTC security updates. Read it at enablesecurity.com/newsletter/202….

Sandro Gauci (@sandrogauci) 's Twitter Profile Photo

The latest edition of RTCSec newsletter is out. Subscribe at enablesecurity.com/subscribe/. You can now listen to the newsletter with the player from ElevenLabs, giving that a try and seeing if people find that useful.

Sandro Gauci (@sandrogauci) 's Twitter Profile Photo

If you're not subscribed to our newsletter and need to know your VoIP and WebRTC security fu, you're missing out. Here's the link to fix that now: enablesecurity.com/subscribe/.

Enable Security (@enablesecurity) 's Twitter Profile Photo

RTCSec News for March - VoIP and WebRTC Security Updates: upcoming presentations at Kamailio World and OpenSIPS Summit, WebRTC vulnerabilities from OWASP Global AppSec, and a FreeSWITCH security vulnerability. Visit enablesecurity.com/newsletter/202…

Enable Security (@enablesecurity) 's Twitter Profile Photo

June RTCSec Newsletter is live! Covering: OWASP ASVS v5 with WebRTC security chapter Critical Yealink vulnerabilities (worse than reported) Meta's Android WebRTC privacy exploit exposed Multiple CVEs: AudioCodes, Qualcomm, Cisco enablesecurity.com/newsletter/202… #VoIP #CyberSecurity

Sandro Gauci (@sandrogauci) 's Twitter Profile Photo

As usual, lots of commentary on all topics VoIP and WebRTC security - out on the RTCSec newsletter. Subscribe for the next one ;)

Sandro Gauci (@sandrogauci) 's Twitter Profile Photo

Been some months in the making but our advisory for rtpengine vis-a-vis RTP Bleed and RTP Inject is out. It describes security fixes that aim to fully address or at least mitigate these RTP Bleed and RTP Inject attacks. Fix requires upgrade and config changes.

Sandro Gauci (@sandrogauci) 's Twitter Profile Photo

Last post for today .. I already went over my 1 post a month limit. Please enjoy the RTC Sec newsletter for July .. or subscribe for the next one :-) enablesecurity.com/newsletter/202…

Adam Crosser (@unc1739) 's Twitter Profile Photo

In case you missed my Black Hat Arsenal or DEF CON Demo Labs presentation, here’s a pre-recorded talk covering our new OAuthSeeker utility, released during hacker summer camp in Las Vegas 🎥 youtube.com/watch?v=MfvWi9…