The VITI Security Blog
Practical writing on managed IT + cybersecurity.
By the engineers doing the work - not a marketing team summarizing it. We write when we have something to say, not when the calendar says we should.

Avada RCE: Why Third-Party WordPress Theme Flaws Demand Proactive Defense
A critical RCE vulnerability in the popular Avada WordPress theme highlights the constant supply chain risk in web applications. Practitioners must prioritize rapid patching, deploy robust WAFs, and maintain vigilant monitoring to counter such threats.

Unpatched Flaws: Lessons from Kaltura's Deserialization Risk
Recent unpatched Kaltura vulnerabilities underscore the critical risks of insecure deserialization and poor patch management, leading to server compromise. Learn what actions practitioners must take now.

Protecting PII: Why SMBs Need to Get Serious About Data Classification and Response
Breaches exposing sensitive PII and medical data are unfortunately common, but often stem from fundamental security control failures within an organization. For many SMBs, the core issue is a lack of rigorous data classification and untested incident response capabilities.

Stopping Mirage2FA: A Practitioner's Guide to Microsoft 365 Phishing Defense
The Mirage2FA campaign actively bypasses Microsoft 365 MFA by exploiting login flows, putting thousands of organizations at risk. This article outlines concrete defense strategies to protect your SMB from these advanced phishing attacks.

Unpatched Router Flaws: Why Your Perimeter Isn't What You Think
An unpatched vulnerability in Calix routers reminds us that NAT is not a security boundary, demanding a proactive shift to defense-in-depth and strong internal controls.

AI Code Security: Stop Drowning in Remediation Debt
AI tools speed up development but can overwhelm security with new dependencies and vulnerabilities. Learn how to manage this remediation debt proactively.

Beyond the Endpoint: Tackling Supply Chain Risks in Your Hardware Ecosystem
A recent incident involving compromised Android car head units highlights how easily unmanaged devices can become botnet fodder. This post breaks down how supply chain attacks on hardware impact SMBs and what practical steps to take for defense.

TikTok's $400M Privacy Bill: Hard Lessons for Every Data Handler
TikTok's hefty settlement over child privacy violations underscores a critical truth: regulatory bodies are serious about enforcing data protection, and every business, not just tech giants, must pay attention.

Securing Windows Named Pipes Against Interprocess Exploits
Windows named pipes offer high-performance interprocess communication, but poor access controls leave privileged services vulnerable to local privilege escalation.
