UC
A couple of weeks ago I provided some guidelines for UC security (http://www.networkworld.com/community/node/67878), noting that SIP-based services such as SIP trunking and SIP-based peering create new vectors for potential attack. This week comes reports of widespread SIP brute-force attacks targeting public-facing SIP servers (see: http://www.stuartsheldon.org/blog/2010/11/sip-brute-force-attacks-escalate-over-halloween-weekend/).
As Mark Collier noted over on the VOIPSA mailing list, these are likely bot attacks due to the wide range of source IP addresses. From the enterprise perspective, the only vulnerability to these sorts of attacks lies in not adequately protecting internal servers from external attack. Perhaps the greatest impact is to generate increased awareness of threat of SIP-based attack. Expect to see not only renewed interest in VOIP security architecture, but also more focus from SIP-based services providers to secure their internal networks.
Make sure you address provider security architectures and practices in your evaluation of SIP trunking and other SIP-based applications.




