# Enable Security > VoIP and WebRTC security testing specialists Enable Security is a dedicated security company focused on Real-Time Communications (RTC) security. Based in Germany, we provide penetration testing, DDoS testing, and security consultancy for VoIP, WebRTC, and SIP systems. ## Services - [VoIP Penetration Testing](https://www.enablesecurity.com/voip-penetration-testing.md): Security testing of Voice-over-IP systems and infrastructure - [WebRTC Security Assessment](https://www.enablesecurity.com/penetration-testing.md): Security testing of WebRTC applications and infrastructure - [DDoS Testing](https://www.enablesecurity.com/ddos-testing.md): Distributed denial-of-service resilience testing for RTC systems - [Fuzz Testing](https://www.enablesecurity.com/fuzz-testing.md): Protocol fuzzing for VoIP and WebRTC - [RTC Security Consultancy](https://www.enablesecurity.com/consultancy.md): Expert security advice for real-time communications systems - [VoIP Security Assessment](https://www.enablesecurity.com/voip-security-assessment.md): Comprehensive VoIP security assessments - [Code and Config Analysis](https://www.enablesecurity.com/code-and-config-analysis.md): Security review of RTC code and configurations ## About - [About Enable Security](https://www.enablesecurity.com/about.md) - [Contact](https://www.enablesecurity.com/contact.md) - [SIPVicious Tools](https://www.enablesecurity.com/sipvicious.md) - [Research](https://www.enablesecurity.com/research.md) ## Security Advisories - [OpenSIPS: Denial of service in presence.handle_publish() from unchecked Content-Type state](https://www.enablesecurity.com/advisories/ES2026-01-opensips-presence-publish-content-type-dos.md) (2026-05-21) - [OpenSIPS: Watcherinfo XML generation denial of service from oversized watcher URI](https://www.enablesecurity.com/advisories/ES2026-02-opensips-watcherinfo-uri-stack-buffer-overflow.md) (2026-05-21) - [OpenSIPS: Denial of service in SDP bandwidth parsing via QoS SDP cloning](https://www.enablesecurity.com/advisories/ES2026-03-opensips-sdp-bandwidth-parsing-dos.md) (2026-05-21) - [OpenSIPS: Denial of service in IMC #list member listing](https://www.enablesecurity.com/advisories/ES2026-04-opensips-imc-list-buffer-overflow.md) (2026-05-21) - [OpenSIPS: Out-of-bounds read in IMC unknown-command reply building](https://www.enablesecurity.com/advisories/ES2026-05-opensips-imc-unknown-command-oob-read.md) (2026-05-21) - [SIPGO: Response DoS vulnerability via nil pointer dereference](https://www.enablesecurity.com/advisories/ES2025-02-sipgo-response-dos.md) (2025-12-17) - [rtpengine: RTP Inject and RTP Bleed vulnerabilities despite proper configuration](https://www.enablesecurity.com/advisories/ES2025-01-rtpengine-improper-behavior-bleed-inject.md) (2025-07-31) - [FreeSWITCH: denial of service via DTLS Hello packets during call initiation](https://www.enablesecurity.com/advisories/ES2023-02-freeswitch-dtls-hello-race.md) (2023-12-22) - [Asterisk: denial of service via DTLS Hello packets during call initiation](https://www.enablesecurity.com/advisories/ES2023-01-asterisk-dtls-hello-race.md) (2023-12-15) - [rtpengine: denial of service via DTLS Hello packets during call initiation](https://www.enablesecurity.com/advisories/ES2023-03-rtpengine-dtls-hello-race.md) (2023-12-15) - [FreeSWITCH: denial of service via invalid SRTP packets](https://www.enablesecurity.com/advisories/ES2021-09-freeswitch-srtp-dos.md) (2021-10-25) - [FreeSWITCH: denial of service via SIP flooding](https://www.enablesecurity.com/advisories/ES2021-06-freeswitch-flood-dos.md) (2021-10-25) - [FreeSWITCH: SIP digest leak for configured gateways](https://www.enablesecurity.com/advisories/ES2021-05-freeswitch-vulnerable-to-SIP-digest-leak.md) (2021-10-25) - [FreeSWITCH: unauthenticated SIP MESSAGE requests allow spam and spoofing](https://www.enablesecurity.com/advisories/ES2021-07-freeswitch-SIP-MESSAGE-without-auth.md) (2021-10-25) - [FreeSWITCH: unauthenticated SIP SUBSCRIBE requests by default](https://www.enablesecurity.com/advisories/ES2021-08-freeswitch-SIP-SUBSCRIBE-without-auth.md) (2021-10-25) - [VoIPmonitor: buffer overflow in live sniffer](https://www.enablesecurity.com/advisories/ES2021-03-voipmonitor-livesniffer-buffer-overflow.md) (2021-03-15) - [VoIPmonitor: cross-site scripting via SIP messages](https://www.enablesecurity.com/advisories/ES2021-02-voipmonitor-gui-xss.md) (2021-03-15) - [VoIPmonitor: static builds lack memory corruption protections](https://www.enablesecurity.com/advisories/ES2021-04-voipmonitor-staticbuild-memory-corruption-protection.md) (2021-03-15) - [coturn: access control bypass via loopback peer address](https://www.enablesecurity.com/advisories/ES2021-01-coturn-access-control-bypass.md) (2021-01-11) - [sngrep: buffer overflow via malformed SDP media type](https://www.enablesecurity.com/advisories/ES2020-03-sngrep-malformed-media-type.md) (2020-11-20) - [sngrep: stack overflow via malformed SDP connection address](https://www.enablesecurity.com/advisories/ES2020-04-sngrep-malformed-connection-address.md) (2020-11-20) - [Asterisk: crash via INVITE flood over TCP](https://www.enablesecurity.com/advisories/ES2020-02-asterisk-tcp-invite-crash.md) (2020-11-06) - [Kamailio: header smuggling via remove_hf bypass](https://www.enablesecurity.com/advisories/ES2020-01-kamailio-remove-hf.md) (2020-09-01) - [Kamailio: off-by-one heap overflow](https://www.enablesecurity.com/advisories/ES2018-05-kamailio-heap-overflow.md) (2018-03-19) - [Asterisk PJSIP: crash via invalid SDP fmtp attribute](https://www.enablesecurity.com/advisories/ES2018-02-asterisk-pjsip-sdp-invalid-fmtp-segfault.md) (2018-02-22) - [Asterisk PJSIP: crash via invalid SDP media format description](https://www.enablesecurity.com/advisories/ES2018-03-asterisk-pjsip-sdp-invalid-media-format-description-segfault.md) (2018-02-22) - [Asterisk PJSIP: crash via repeated INVITE messages over TCP/TLS](https://www.enablesecurity.com/advisories/ES2018-04-asterisk-pjsip-tcp-segfault.md) (2018-02-22) - [Asterisk PJSIP: stack corruption via large Accept header in SUBSCRIBE](https://www.enablesecurity.com/advisories/ES2018-01-asterisk-pjsip-subscribe-stack-corruption.md) (2018-02-22) - [Asterisk: RTP Bleed vulnerability](https://www.enablesecurity.com/advisories/ES2017-04-asterisk-rtp-bleed.md) (2017-09-01) - [Asterisk PJSIP: heap overflow in CSeq header parsing](https://www.enablesecurity.com/advisories/ES2017-01-asterisk-pjsip-cseq-overflow.md) (2017-05-23) - [Asterisk PJSIP: out-of-bound memory access in multipart parser](https://www.enablesecurity.com/advisories/ES2017-02-asterisk-pjsip-multi-part-crash.md) (2017-05-23) - [Asterisk Skinny: memory exhaustion denial of service](https://www.enablesecurity.com/advisories/ES2017-03-asterisk-chan-skinny-crash.md) (2017-05-23) - [Liferay: XML External Entity vulnerability in OpenID component](https://www.enablesecurity.com/advisories/ES2016-01-liferay-xxe.md) (2016-01-01) - [Juniper VPN SSL: client-side cross-site scripting](https://www.enablesecurity.com/advisories/ES2013-01-juniper-junos-dom-xss.md) (2013-09-12) - [Applicure dotDefender: stored cross-site scripting in admin interface](https://www.enablesecurity.com/advisories/ES2010-01-applicure-dotDefender-stored-xss.md) (2010-06-01) - [Armorlogic Profense WAF: multiple vulnerabilities](https://www.enablesecurity.com/advisories/ES2009-02-armorlogic-profense-multiple-vulnerabilities.md) (2009-05-13) - [OpenX: multiple vulnerabilities](https://www.enablesecurity.com/advisories/ES2009-01-openx-multiple-vulnerabilities.md) (2009-04-01) - [Apple Mail.app: S/MIME encrypted emails stored in clear text](https://www.enablesecurity.com/advisories/ES2008-01-apple-mailapp-stores-smime-clear-text.md) (2008-10-03) ## Blog Posts - [DVRTC v0.2.0: pbx2 and SIP SQL injection](https://www.enablesecurity.com/blog/dvrtc-v0-2-0-adds-pbx2-and-sql-injection.md) (2026-04-21) - [SIPVicious tutorial: testing VoIP security with DVRTC](https://www.enablesecurity.com/blog/sipvicious-tutorial-voip-security-testing-with-dvrtc.md) (2026-04-13) - [AI is coming for your C code and it does not need coffee](https://www.enablesecurity.com/blog/ai-coming-for-your-c-code.md) (2026-04-03) - [Introducing DVRTC: a vulnerable lab for RTC security](https://www.enablesecurity.com/blog/introducing-dvrtc-damn-vulnerable-real-time-communications.md) (2026-03-27) - [Securing coturn: Configuration Guide](https://www.enablesecurity.com/blog/coturn-security-configuration-guide.md) (2026-02-25) - [TURN Server Security Best Practices](https://www.enablesecurity.com/blog/turn-security-best-practices.md) (2026-02-25) - [TURN Security Threats: A Hacker's View](https://www.enablesecurity.com/blog/turn-server-security-threats.md) (2026-02-12) - [VoIP Eavesdropping: How it Works, Threats & Defense Tactics ](https://www.enablesecurity.com/blog/voip-eavesdropping-defense.md) (2025-10-09) - [Sandro talks RTC Security with Safety Detectives](https://www.enablesecurity.com/blog/sandro-talks-rtc-security-with-safetydetectives.md) (2025-08-06) - [Rtpengine RTP Injection and Media Bleed Vulnerabilities (CVE-2025-53399)](https://www.enablesecurity.com/blog/rtpengine-critical-security-advisory-cve-2025-53399.md) (2025-07-31) - [New White Paper: DTLS "ClientHello" Race Conditions in WebRTC Implementations](https://www.enablesecurity.com/blog/webrtc-hello-race-conditions-paper.md) (2024-10-15) - [TADSummit Innovators Podcast reviews the Last 6 Months of RTC Security Trends with Sandro Gauci](https://www.enablesecurity.com/blog/tadsummit-innovators-podcast-with-sandro-gauci.md) (2024-07-26) - [A Novel DoS Vulnerability affecting WebRTC Media Servers](https://www.enablesecurity.com/blog/novel-dos-vulnerability-affecting-webrtc-media-servers.md) (2024-06-25) - [OpenSIPS Security Audit Report is fully disclosed and out there](https://www.enablesecurity.com/blog/opensips-security-audit-report.md) (2023-03-17) - [SIPVicious PRO incremental update - and Gitlab CI/CD examples](https://www.enablesecurity.com/blog/sipvicious-pro-with-various-fixes-and-gitlab-ci.md) (2023-03-07) - [Kamailio's exec module considered harmful](https://www.enablesecurity.com/blog/kamailio-exec-module-considered-harmful.md) (2023-01-26) - [How to perform a DDoS attack simulation](https://www.enablesecurity.com/blog/how-to-perform-ddos-simulation.md) (2022-11-29) - [RTCSec newsletter is one year old!](https://www.enablesecurity.com/blog/rtcsec-newsletter-one-year-old.md) (2022-10-26) - [SIPVicious PRO experimental now supports STIR/SHAKEN and 5 new tools](https://www.enablesecurity.com/blog/sipviciouspro-with-stir-shaken-support-and-new-tools.md) (2022-07-06) - [We're hiring a pentester / security researcher](https://www.enablesecurity.com/blog/hiring-pentester.md) (2022-05-04) - [Exploiting CVE-2022-0778, a bug in OpenSSL vis-à-vis WebRTC platforms](https://www.enablesecurity.com/blog/exploiting-cve-2022-0778-in-openssl-vs-webrtc-platforms.md) (2022-04-08) - [Killing bugs ... one vulnerability report at a time](https://www.enablesecurity.com/blog/killing-bugs-one-vulnerability-report-at-a-time.md) (2021-10-29) - [ClueCon: FreeSWITCH Security Advisories](https://www.enablesecurity.com/blog/freeswitch-advisories-presentation.md) (2021-10-25) - [Why volumetric DDoS cripples VoIP providers and what we see during pentesting](https://www.enablesecurity.com/blog/how-i-learned-to-stop-worrying-and-love-the-flood.md) (2021-10-13) - [Massive DDoS attacks on VoIP Providers and simulated DDoS testing](https://www.enablesecurity.com/blog/massive-ddos-and-simulated-attacks.md) (2021-09-24) - [Abusing SIP for Cross-Site Scripting? Most definitely!](https://www.enablesecurity.com/blog/sip-exploitation-for-xss.md) (2021-06-10) - [SIPVicious OSS v0.3.4 released with exit codes and automation features](https://www.enablesecurity.com/blog/sipvicious-oss-0.3.4-released-with-exit-codes.md) (2021-06-02) - [DEMO - An overview of the VoIP and RTC offensive security toolset, SIPVicious PRO](https://www.enablesecurity.com/blog/an-overview-of-the-voip-and-rtc-offensive-security-toolset-sipvicious-pro.md) (2021-05-25) - [SIPVicious PRO 6.0.0-beta.4 getting close to take-off!](https://www.enablesecurity.com/blog/sipvicious-pro-release-6-beta-4.md) (2021-05-20) - [TADSummit Asia 2021 talk about SIPVicious Pro and the Demo Server](https://www.enablesecurity.com/blog/tadsummit-asia-2021-introducing-sipvicious-pro-and-the-demo-server.md) (2021-05-18) - [OpenSIPIt'01: Lessons learned, STIR/SHAKEN security testing and RFC 8760](https://www.enablesecurity.com/blog/opensipit-01-lessons-learned.md) (2021-04-16) - [SIPVicious OSS 0.3.3 released with new STDIN and target URL specification](https://www.enablesecurity.com/blog/sipvicious-oss-0.3.3-released-stdin-target-urls.md) (2021-03-25) - [Bug discovery diaries: Abusing VoIPmonitor for Remote Code Execution](https://www.enablesecurity.com/blog/buffer-overflow-discovery-to-rce-in-voipmonitor.md) (2021-03-16) - [VoIPmonitor advisories: buffer overflow leading to RCE + XSS vulnerabilities](https://www.enablesecurity.com/blog/voipmonitor-xss-and-bufferoverflow-advisories.md) (2021-03-15) - [SIPVicious OSS 0.3.2 released with more IPv6 goodness!](https://www.enablesecurity.com/blog/sipvicious-oss-0.3.2-released-more-ipv6.md) (2021-03-03) - [Communication Breakdown / rtcsec also on FreeRTC and SIP Planet](https://www.enablesecurity.com/blog/now-on-freertc-and-sip5060-planet.md) (2021-02-12) - [SIPVicious PRO 6.0.0-beta.2 takes STDIN and fixes various bugs](https://www.enablesecurity.com/blog/sipvicious-pro-release-6-beta-2.md) (2021-02-09) - [Details about CVE-2020-26262, bypass of Coturn's default access control protection](https://www.enablesecurity.com/blog/cve-2020-26262-bypass-of-coturns-access-control-protection.md) (2021-01-11) - [Bug discovery diaries: uncovering sngrep overflow issues with blackbox fuzzing](https://www.enablesecurity.com/blog/discovering-sngrep-overflow-with-fuzzing.md) (2021-01-05) - [SIPVicious PRO beta release contains SIP fuzzer and better automation](https://www.enablesecurity.com/blog/sipvicious-pro-beta-with-fuzzer-and-better-ci-cd-integration.md) (2020-12-03) - [How doing QA testing for SIPVicious PRO led to an Asterisk DoS](https://www.enablesecurity.com/blog/asterisk-tcp-crash.md) (2020-11-10) - [ClueCon Weekly with Sandro Gauci, demonstration of SIP Digest Leak](https://www.enablesecurity.com/blog/cluecon-weekly-sip-digest-leak-demo.md) (2020-10-16) - [RTC Security chat at Kamailio World Online with Daniel and Olle](https://www.enablesecurity.com/blog/kamailio-world-2020-rtc-security.md) (2020-10-05) - [The great Kamailio security debate and some misconceptions debunked](https://www.enablesecurity.com/blog/kamailio-security-debate-and-misconceptions.md) (2020-09-22) - [Smuggling SIP headers past Session Border Controllers FTW!](https://www.enablesecurity.com/blog/smuggling-sip-headers-past-sbc.md) (2020-09-01) - [Kamailio World Online SIP and VoIP Security Panel](https://www.enablesecurity.com/blog/kamailio-world-online-sip-and-voip-security-panel.md) (2020-08-27) - [Bug bounty bout report 0x01 - WebRTC edition](https://www.enablesecurity.com/blog/bug-bounty-bout-0x01-webrtc-edition.md) (2020-06-16) - [Attacking a real VoIP System with SIPVicious OSS](https://www.enablesecurity.com/blog/attacking-real-voip-system-with-sipvicious-oss.md) (2020-06-08) - [SIPVicious PRO v6.0.0 alpha.5 available to our clients](https://www.enablesecurity.com/blog/sipvicious-pro-v6.0.0-alpha.5.md) (2020-06-03) - [A gentle introduction to caller ID spoofing](https://www.enablesecurity.com/blog/an-introduction-to-caller-id-spoofing.md) (2020-05-07) - [Awesome RTC hacking list published on Github](https://www.enablesecurity.com/blog/awesome-rtc-hacking.md) (2020-04-29) - [Jitsi Meet on Docker default passwords - how bad is it, how to detect and fix it](https://www.enablesecurity.com/blog/jitsi-meet-on-docker-default-password-exploitation.md) (2020-04-20) - [How we abused Slack's TURN servers to gain access to internal services](https://www.enablesecurity.com/blog/slack-webrtc-turn-compromise-and-bug-bounty.md) (2020-04-06) - [What's up with SIPVicious PRO?](https://www.enablesecurity.com/blog/whats-up-with-sipvicious-pro.md) (2020-03-30) - [SIPVicious OSS 0.3.0 released](https://www.enablesecurity.com/blog/sipvicious-oss-0.3.0.md) (2020-03-10) - [If SIPVicious gives you a ring...](https://www.enablesecurity.com/blog/if-sipvicious-gives-you-ring.md) (2012-12-10) - [Using XSS to switch off dotDefender 4.0](https://www.enablesecurity.com/blog/2010/6/1/using-xss-to-switch-off-dotdefender-40.md) (2010-06-01) - [Setting the secure flag in the cookie is easy](https://www.enablesecurity.com/blog/2008/8/29/setting-the-secure-flag-in-the-cookie-is-easy.md) (2008-08-29) - [Surf Jack - HTTPS will not save you](https://www.enablesecurity.com/blog/2008/8/11/surf-jack-https-will-not-save-you.md) (2008-08-11) ## RTCSec Newsletter - [August 2026: FreeSWITCH RCE in the wild, coturn advisories verified, Hacker Summer Camp](https://www.enablesecurity.com/newsletter/2026-08-rtcsec-news.md) (2026-08-31) - [July 2026: AI-found RCEs verified, the impact-assessment problem, Kamailio SBOM](https://www.enablesecurity.com/newsletter/2026-07-rtcsec-news.md) (2026-07-30) - [June 2026: DragonForce hides C2 in Teams TURN relays, FreeSWITCH and coturn advisory batches](https://www.enablesecurity.com/newsletter/2026-06-rtcsec-news.md) (2026-06-30) - [May 2026: SIPConfusion caller-ID spoofing, FreeSWITCH SIP DoS, OpenSIPS CVE batch](https://www.enablesecurity.com/newsletter/2026-05-rtcsec-news.md) (2026-05-29) - [April 2026: wolfSSL DTLS overflow, Mozilla AI vuln hunting, Kamailio DoS, coturn fixes](https://www.enablesecurity.com/newsletter/2026-04-rtcsec-news.md) (2026-04-23) - [March 2026: DTLS-SRTP auth bypass, AI vuln research, DVRTC, WebRTC skimmer](https://www.enablesecurity.com/newsletter/2026-03-rtcsec-news.md) (2026-03-31) - [February 2026: TURN security series, libvpx VP9 overflow, Grandstream RCE, coturn fixes](https://www.enablesecurity.com/newsletter/2026-02-rtcsec-news.md) (2026-02-26) - [January 2026: Cisco UCM zero-day, 39C3 telco talks, FreePBX exploitation](https://www.enablesecurity.com/newsletter/2026-01-rtcsec-news.md) (2026-01-30) - [December 2025: Year in review, FreePBX vulns, see you in 2026](https://www.enablesecurity.com/newsletter/2025-12-rtcsec-news.md) (2025-12-17) - [November 2025: VoIP and WebRTC vulnerability roundup](https://www.enablesecurity.com/newsletter/2025-11-rtcsec-news.md) (2025-11-28) - [October 2025: RTP attacks, Cisco VoIP phones, satellite leaks, and nation-state breaches](https://www.enablesecurity.com/newsletter/2025-10-rtcsec-news.md) (2025-10-31) - [September 2025: more RTP, FreePBX and Voice AI vulnerabilities this time](https://www.enablesecurity.com/newsletter/2025-09-rtcsec-news.md) (2025-09-30) - [August 2025: WHY 2025, Black Hat, DEF CON, ClueCon and FreePBX 0day ITW!](https://www.enablesecurity.com/newsletter/2025-08-rtcsec-news.md) (2025-08-30) - [July 2025: Rtpengine fixes, RTC conferences and showers of vulnerabilities](https://www.enablesecurity.com/newsletter/2025-07-rtcsec-news.md) (2025-07-31) - [June 2025: WebRTC security, privacy and Yealink provisioning vulnerabilities](https://www.enablesecurity.com/newsletter/2025-06-rtcsec-news.md) (2025-06-30) - [May 2025: VoIP conferences, VoLTE vulnerabilities and so much more](https://www.enablesecurity.com/newsletter/2025-05-rtcsec-news.md) (2025-05-29) - [April 2025: Verizon's CDR compromise, Cisco VoIP security flaws and phreaking](https://www.enablesecurity.com/newsletter/2025-04-rtcsec-news.md) (2025-04-30) - [March 2025: Upcoming and Past VoIP and WebRTC security presentations, FreeSWITCH vulnerabilities - or not](https://www.enablesecurity.com/newsletter/2025-03-rtcsec-news.md) (2025-03-31) - [February 2025: VoIP phones join botnets, and vulnerabilities in Cisco, Twilio, Asterisk, AudioCodes and more](https://www.enablesecurity.com/newsletter/2025-02-rtcsec-news.md) (2025-02-28) - [January 2025: SIP, WebRTC and IoT security news, security fixes for Cisco, Asterisk, Samsung and more](https://www.enablesecurity.com/newsletter/2025-01-rtcsec-news.md) (2025-01-31) - [December 2024: Wrap-Up & Latest VoIP and WebRTC Security News](https://www.enablesecurity.com/newsletter/2024-12-rtcsec-news.md) (2024-12-19) - [November 2024: Breaking VoIP & WebRTC – Exploits, Vulnerabilities, and Shodan Insights](https://www.enablesecurity.com/newsletter/2024-11-rtcsec-news.md) (2024-11-29) - [October 2024: WebRTC app vulnerabilities at DEF CON 32, SIP URI security, VoIP product fixes](https://www.enablesecurity.com/newsletter/2024-10-rtcsec-news.md) (2024-10-25) - [September 2024: OWASP in San Francisco, WebRTC, Telco security and much more](https://www.enablesecurity.com/newsletter/2024-09-rtcsec-news.md) (2024-09-30) - [August 2024: WebRTC security at OWASP Global AppSec, WebRTC RCE technical posts and new talks](https://www.enablesecurity.com/newsletter/2024-08-rtcsec-news.md) (2024-08-16) - [July 2024: WebRTC flaws that suddenly appear out of nowhere, hardphone security and more!](https://www.enablesecurity.com/newsletter/2024-07-rtcsec-news.md) (2024-07-31) - [June 2024: WebRTC security specs that need fixing and vulnerable VoIP firmware and WebEx](https://www.enablesecurity.com/newsletter/2024-06-rtcsec-news.md) (2024-06-28) - [May 2024: Presenting on DTLS WebRTC DoS and the latest VoIP vulnerabilities](https://www.enablesecurity.com/newsletter/2024-05-rtcsec-news.md) (2024-05-31) - [April 2024: Kamailio security, Mitel, sngrep and Grandstream vulnerabilities and more](https://www.enablesecurity.com/newsletter/2024-04-rtcsec-news.md) (2024-04-30) - [March 2024: Webex leak, WhatsApp and Apple WebRTC vulnerabilities](https://www.enablesecurity.com/newsletter/2024-03-rtcsec-news.md) (2024-03-28) - [February 2024: manipulating audio using LLM, malware using CPaaS and WebRTC security](https://www.enablesecurity.com/newsletter/2024-02-rtcsec-news.md) (2024-02-29) - [January 2024: Critical WebRTC, CUCM and SIP ALG security fixes - fuzz it all and disable stuff](https://www.enablesecurity.com/newsletter/2024-01-rtcsec-news.md) (2024-01-31) - [December 2023: Round-up of this year's VoIP and WebRTC security news, and DTLS hello race flaw](https://www.enablesecurity.com/newsletter/2023-12-rtcsec-news.md) (2023-12-22) - [November 2023: Advisories for VoIP systems and devices, WebRTC privacy and spying on your calls](https://www.enablesecurity.com/newsletter/2023-11-rtcsec-news.md) (2023-11-30) - [October 2023: security theatre and PBX hacking, plus last month's advisories](https://www.enablesecurity.com/newsletter/2023-10-rtcsec-news.md) (2023-10-26) - [September 2023: Security advisories, SIP & DTLS-SRTP interoperability and 5G infra attacks](https://www.enablesecurity.com/newsletter/2023-09-rtcsec-news.md) (2023-09-29) - [August 2023: Join OpenSIPit, learn about Zoom, Skype vulnerabilities, and more](https://www.enablesecurity.com/newsletter/2023-08-rtcsec-news.md) (2023-08-31) - [July 2023: VoIP and WebRTC attack surface, pentesting for 2023 and VoIP DDoS attacks](https://www.enablesecurity.com/newsletter/2023-07-rtcsec-news.md) (2023-07-28) - [June 2023: Talks on VoIP security, WebRTC server-side attacks and WISH/WHIP](https://www.enablesecurity.com/newsletter/2023-06-rtcsec-news.md) (2023-06-30) - [May 2023: RTC conferences, advisories for Cisco, Mitel, sofia-sip](https://www.enablesecurity.com/newsletter/2023-05-rtcsec-news.md) (2023-05-31) - [April 2023: 3CX incident updates, WebRTC security and H264](https://www.enablesecurity.com/newsletter/2023-04-rtcsec-news.md) (2023-04-28) - [March 2023: Trojan 3CX Client, CRA talk, OpenSIPS audit report and much more](https://www.enablesecurity.com/newsletter/2023-03-rtcsec-news.md) (2023-03-31) - [WebRTC attacks, FOSDEM'23 and security fixes](https://www.enablesecurity.com/newsletter/2023-02-rtcsec-news.md) (2023-02-28) - [Kamailio's exec module, SIPVicious still ringing phones and many vulnerabilities](https://www.enablesecurity.com/newsletter/2023-01-rtcsec-news.md) (2023-01-31) - [Highlights from the past year and various security fixes](https://www.enablesecurity.com/newsletter/2022-12-rtcsec-news.md) (2022-12-22) - [DDoS simulation tutorial, WebRTC IP leak and vulnerable RTC libraries](https://www.enablesecurity.com/newsletter/2022-11-rtcsec-news.md) (2022-11-30) - [Celebrations, presentations and new VoIP security tools](https://www.enablesecurity.com/newsletter/2022-10-rtcsec-news.md) (2022-10-31) - [DDoS workshop at TADSummit, toll fraud via MS Teams Direct Routing and WebRTC news](https://www.enablesecurity.com/newsletter/2022-09-rtcsec-news.md) (2022-09-30) - [SIP ALG exploit hits Realtek SDK, our Attack Platform and holidays](https://www.enablesecurity.com/newsletter/2022-08-rtcsec-news.md) (2022-08-31) - [WebRTC 0day, FreePBX not Asterisk attacks and talks at MCH2022](https://www.enablesecurity.com/newsletter/2022-07-rtcsec-news.md) (2022-07-29) - [SIPVicious PRO out with 2 releases, ransomware and participation in the survey](https://www.enablesecurity.com/newsletter/2022-06-rtcsec-news.md) (2022-06-30) - [OpenSIPS security audit report is out, Zoom and Wire RCEs and DTLS](https://www.enablesecurity.com/newsletter/2022-05-rtcsec-news.md) (2022-05-31) - [We're hiring, new SIPVicious PRO tools, advisories and blog post galore](https://www.enablesecurity.com/newsletter/2022-04-rtcsec-news.md) (2022-04-27) - [OpenSSL DoS and DTLS, SIMBoxes, SIP-TLS and lots of advisories](https://www.enablesecurity.com/newsletter/2022-03-rtcsec-news.md) (2022-03-29) - [Commentary: security fixes in PJSIP, Zyxel, BIG-IP, Vicidial and others](https://www.enablesecurity.com/newsletter/2022-02-rtcsec-news.md) (2022-02-25) - [STIR/SHAKEN DoS, Cisco phone passwords, Zoom and Yealink](https://www.enablesecurity.com/newsletter/2022-01-rtcsec-news.md) (2022-01-26) - [DDoS, SIPit33, log4j and plans for 2022](https://www.enablesecurity.com/newsletter/2021-12-rtcsec-news.md) (2021-12-21) - [Vulnerabilities, honeypots, STIR/SHAKEN, DDoS and more](https://www.enablesecurity.com/newsletter/2021-11-rtcsec-news.md) (2021-11-22) - [VoIP DDoS, the OpenSIPS security audit and more](https://www.enablesecurity.com/newsletter/2021-10-rtcsec-news.md) (2021-10-20) ## Contact - Email: hello@enablesecurity.com - Website: https://www.enablesecurity.com/ - LinkedIn: https://www.linkedin.com/company/enablesecurity - GitHub: https://github.com/enablesecurity