1. X
  2. Enable Security
Log inSign up
Enable Security
294 posts
Enable Security profile banner
user avatar

Enable Security

@enablesecurity
We talk about Offensive Real-Time Communications / VoIP and WebRTC Security Blog: enablesecurity.com/blog/ Newsletter: rtcsec.com/subscribe
Germany
enablesecurity.com
Joined May 2016
178
Following
362
Followers
RepliesRepliesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • user avatar
    Enable Security
    @enablesecurity
    Jul 30
    1/ AI-generated vulnerability reports are burying open source projects. This month we did something about one of them: we took 0day Rubbish's AI-found, self-published RCE chains and actually ran them. July RTCSec newsletter 🧵
  • user avatar
    Enable Security
    @enablesecurity
    Jun 30
    1/ DragonForce ransomware now tunnels its C2 through Microsoft Teams TURN relays. Symantec calls it the first publicly documented case of a threat actor abusing TURN for C2. On the wire it looks like a normal Teams call, slipping past perimeters that safelist Microsoft.
  • user avatar
    Enable Security
    @enablesecurity
    May 29
    1/ The May RTCSec newsletter is out. The standout: SIPConfusion (NDSS 2026), where Tsinghua researchers forge caller ID and spoof SMS across VoIP, VoLTE and RCS by exploiting how SIP implementations disagree on parsing identity headers. 🧵
  • user avatar
    Enable Security
    @enablesecurity
    Apr 23
    1/ April RTCSec newsletter is out. AI-assisted vulnerability research is accelerating fast across the RTC ecosystem.
    Image
    April 2026: wolfSSL DTLS overflow, Mozilla AI vuln hunting, Kamailio DoS, coturn fixes
    From enablesecurity.com
  • user avatar
    Enable Security
    @enablesecurity
    Apr 21
    DVRTC, our intentionally vulnerable VoIP/WebRTC lab, now has a second scenario. v0.2.0 adds pbx2: OpenSIPS, FreeSWITCH, and rtpproxy. It joins pbx1 (Kamailio, Asterisk, rtpengine, coturn), so DVRTC now covers two different VoIP stacks to practice against.
    Image
    DVRTC v0.2.0: pbx2 and SIP SQL injection
    From enablesecurity.com
Advertisement
Advertisement