Skip to content
Threat Feed

Vendor

Twilio

4 briefs RSS
critical advisory

CVE-2026-9181: Unauthenticated Directory Traversal in ArcGIS Server

An unauthenticated attacker can exploit CVE-2026-9181, a critical directory traversal vulnerability in ArcGIS Server versions 12.0 and prior, by sending crafted path parameters to access sensitive files, leading to unauthorized information disclosure.

ArcGIS Server +17 directory-traversal web-vulnerability esri cve
2t 1i updated
high advisory

Google Security Updates — July 2026

Roundup of Google security advisories published in July 2026.

golang.org/x/crypto/ssh +74 roundup
5c 41i updated
medium advisory

Pipecat Telephony Runner Unauthenticated Call-Control Abuse

An unauthenticated remote attacker can leverage a missing authorization vulnerability (CWE-862) in the Pipecat development runner's `/ws` WebSocket endpoint to supply a crafted `callSid` in a handshake message, compelling the server to use its configured Twilio, Telnyx, or Plivo credentials to issue authenticated API requests that terminate active calls, resulting in denial of service and credential abuse.

pipecat development runner api-security websocket telephony cwe-862 python
1r 3t 3i
medium advisory

Phone Number Reuse in Scam Email Campaigns

Talos has begun tracking phone numbers in emails as indicators of compromise, revealing insights into their reuse in scam campaigns where attackers use API-driven VoIP services for cost-effective operations, rotating phone number blocks to evade security filters, and maximizing reach by recycling numbers across diverse lures.

Geek Squad email phishing voip scam
2r 1t 2i