4/ Also this month: FRAFOS caught toll fraud through 231 misconfigured Cisco Expressways, a big FreeSWITCH advisory batch (pre-auth mod_verto heap overflow), and our CommCon talk on attacking WebRTC conferencing.
Full issue: https://t.co/nYxY4OntT7
1/ DragonForce ransomware now tunnels its C2 through Microsoft Teams TURN relays. Symantec calls it the first publicly documented case of a threat actor abusing TURN for C2. On the wire it looks like a normal Teams call, slipping past perimeters that safelist Microsoft.
3/ coturn shipped new hardening defaults (4.13.1/4.14.0, including a native amplification rate limit) plus three more CVEs, including a default loopback bypass (CVE-2026-53450). We refreshed our coturn security configuration guide to match.
1/ The May RTCSec newsletter is out. The standout: SIPConfusion (NDSS 2026), where Tsinghua researchers forge caller ID and spoof SMS across VoIP, VoLTE and RCS by exploiting how SIP implementations disagree on parsing identity headers. 🧵
4/ Good news for a change: Cryptex (RFC 9335) negotiation landed in libWebRTC, so RTP header extensions and CSRCs can finally be encrypted, closing a long-standing metadata-leak gap in SRTP.
4/ I'll be presenting DVRTC at @opensips Summit (Bucharest, Apr 28), Kamailio World (Berlin, May 8), and CommCon (Dusseldorf, June 9-11). Three conferences, three different VoIP/WebRTC attack scenarios.
DVRTC, our intentionally vulnerable VoIP/WebRTC lab, now has a second scenario.
v0.2.0 adds pbx2: OpenSIPS, FreeSWITCH, and rtpproxy. It joins pbx1 (Kamailio, Asterisk, rtpengine, coturn), so DVRTC now covers two different VoIP stacks to practice against.
https://t.co/s8GcI09wIi