sandrogauci Profile Banner
Sandro Gauci Profile
Sandro Gauci

@sandrogauci

Followers
4K
Following
828
Statuses
3K

Offensive VoIP/WebRTC security; mostly harmless https://t.co/nwxcTm1wnr Chief Mischief Officer @enablesecurity https://t.co/m1SSe6MyAE

Bavaria, Germany
Joined January 2008
Don't wanna be here? Send us removal request.
@sandrogauci
Sandro Gauci
11 days
The latest edition of RTCSec newsletter is out. Subscribe at You can now listen to the newsletter with the player from @elevenlabsio, giving that a try and seeing if people find that useful.
@enablesecurity
Enable Security
12 days
January 2025 RTCSec newsletter out now! Covers Cisco BroadWorks SIP vulnerability, Asterisk fixes, Wordpress plugin, Samsung Galaxy S24, VoIP and WebRTC security updates. Read it at
0
2
6
@sandrogauci
Sandro Gauci
11 days
RT @enablesecurity: January 2025 RTCSec newsletter out now! Covers Cisco BroadWorks SIP vulnerability, Asterisk fixes, Wordpress plugin, S…
0
2
0
@sandrogauci
Sandro Gauci
22 days
RT @vanhoefm: After an embargo of 8 months, we are glad to finally share our USENIX Security '25 paper! We found more than 4 MILLION vulner…
0
81
0
@sandrogauci
Sandro Gauci
2 months
From Grandstream GDMS compromise to Mitel vulnerabilities - crucial insights for anyone working with WebRTC & VoIP. Great summary by @EnableSecurity. Subscribe here:
@enablesecurity
Enable Security
2 months
🔐 2024 in #WebRTC & #VoIP Security: Great progress with increased research focus, OWASP coverage & conference talks, but concerns remain around conferencing platforms & VoIP vulnerabilities. Read our year-end newsletter wrap-up!
0
3
3
@sandrogauci
Sandro Gauci
2 months
RT @enablesecurity: 🔐 2024 in #WebRTC & #VoIP Security: Great progress with increased research focus, OWASP coverage & conference talks, bu…
0
1
0
@sandrogauci
Sandro Gauci
2 months
RT @TheBrothersWISP: From the VOIP community on Reddit: Grandstream sends notice of GDMS security incident
0
1
0
@sandrogauci
Sandro Gauci
2 months
Your favourite VoIP and WebRTC security newsletter for this month is out! My favorite this time was the presentation by Meta on hacking Messenger, given at @hexacon_fr 2024. 🤓 Contributions to RTC security: @rexploit, @vivekramac, @mod0, @shawnmer2, @Pasc0o, @elwrv and more!
@enablesecurity
Enable Security
2 months
The November edition of the RTCSec Newsletter is out covering: Exploitation of Messenger from Meta, Vulnerabilities in WebRTC, Poly Video Conferencing systems, Cisco phones, Qualcomm DSP video codecs. and VoIP devices on Shodan. Give it a read:
0
0
8
@sandrogauci
Sandro Gauci
4 months
Just finished working on the October edition of the RTCSec newsletter. This one includes a lot of content and contributions thanks to so many great folks. Give it a read or subscribe for the next one:
@enablesecurity
Enable Security
4 months
RTCSec October newsletter is out. 3rd anniversary edition covers: WebRTC related vulnerabilities from DEF CON 32, SIP URI security concerns, VoIP product fixes. Plus, our new white paper on DoS using DTLS in WebRTC! Read online: #RTCSecurity
0
0
4
@sandrogauci
Sandro Gauci
4 months
Excited to share our new white paper on WebRTC DoS vulnerability! It expands on our previous blog post, providing crucial details we missed. Hope it sparks more research into WebRTC security. Check it out! #WebRTCSecurity
@enablesecurity
Enable Security
4 months
We've published a new security white paper on DTLS "ClientHello" race conditions in WebRTC! RTPEngine, Asterisk, FreeSWITCH and Skype (PSTN) were found vulnerable. Tested Discord, Google Meet, Zoom, and more #WebRTCSecurity
0
1
5
@sandrogauci
Sandro Gauci
4 months
We covered VoIP and WebRTC news by @enablesecurity (of course), @owasp, @OWASP_ASVS, @asteriskpbx and many more. This one was worked on a long flight 😉 Subscribe for the next one here:
@enablesecurity
Enable Security
4 months
We just published the latest and greatest RTCSec newsletter, covering news about conferences, talks, OWASP getting into WebRTC security, telco security: VoLTE vulnerabilities, SS7 hacking and vulnerabilities in Asterisk, Cisco, Mitel and more.
0
1
7
@sandrogauci
Sandro Gauci
5 months
Hey SF folks! I'll be around from Sept 25 - Oct 3. Ping me if you're down for a coffee or beer! #OWASP #GlobalAppSecSanFran
0
0
1
@sandrogauci
Sandro Gauci
5 months
RT @trufflesec: 🌟 @owasp 2024 Global AppSec is next week in SF! 🚀 We’re sharing the top talks we're excited about—from 0-days in CI/CD to…
0
1
0
@sandrogauci
Sandro Gauci
5 months
RT @trufflesec: Huge shoutout to to the speakers giving these talks: @amichaishulman @Cassie_Crossley @francoisproulx @InsecureNature @JoeL
0
1
0
@sandrogauci
Sandro Gauci
5 months
RT @JoshCGrossman: @OWASP_ASVS Particular thanks to @sandrogauci for his hard work in pulling this chapter together!
0
1
0
@sandrogauci
Sandro Gauci
6 months
The latest VoIP & WebRTC security newsletter is out early! Dive into Hacker Summer Camp presentation highlights and check out new Cisco phone vulnerabilities. See you next month! 😉
@enablesecurity
Enable Security
6 months
The August edition of RTCSec newsletter was just published. We're sending this out a bit earlier than usual as some of us will be taking some time off soon. See you next month! Read it at
0
0
2
@sandrogauci
Sandro Gauci
6 months
RT @enablesecurity: The August edition of RTCSec newsletter was just published. We're sending this out a bit earlier than usual as some of…
0
1
0
@sandrogauci
Sandro Gauci
7 months
0
0
1
@sandrogauci
Sandro Gauci
7 months
RT @securestep9: #OWASP #ASVS: What a great idea by the @owasp_asvs project to ask for #opensource contributions using a "Wanted" poster a…
0
9
0
@sandrogauci
Sandro Gauci
8 months
this was my favorite bit 😉
@enablesecurity
Enable Security
8 months
and those debates about the WebRTC specs needing, or not, a slight security update, thanks to @HCornflower @ibc__again , @nilsohlmeier , @murillo , @elminiero
0
0
1