None
NL
On The Insecurity of Telecom Stacks in the Wake of Salt Typhoon
['View Archive']
Dhole Moments
2025-01-27: I send an email on to the email address listed on FreeSWITCH’s security policy with the details of the vulnerability. To recap: An employee of SignalWire (which develops FreeSWITCH) came right out and said they would let people who aren’t paying for FreeSWITCH Advantage stay vulnerable until their regularly scheduled release (sometime in the Summer). The worst part is, when I confided in a friend that works in telecom (after SignalWire published the fixes, of course) about this carnival-quality vulnerability management from the FreeSWITCH developers, their response was: