VITI Security

The VITI Security Blog

Practical writing on managed IT + cybersecurity.

By the engineers doing the work - not a marketing team summarizing it. We write when we have something to say, not when the calendar says we should.

AI Assistants and Data Exfiltration: A New Frontier for Security Controls - VITI Security
AI Security

AI Assistants and Data Exfiltration: A New Frontier for Security Controls

The Atlassian Rovo incident shows AI assistants introduce new data exfiltration risks. Organizations must update data access controls and prompt security strategies to prevent sensitive data leaks.

Aug 8, 2026Read
Protecting Your Supply Chain: Practical Defenses Against Malicious npm Packages - VITI Security
Cybersecurity

Protecting Your Supply Chain: Practical Defenses Against Malicious npm Packages

The recent discovery of nearly 800 malicious packages on npm highlights a critical software supply chain vulnerability that demands immediate attention for any team using Node.js or JavaScript. This incident underscores the need for robust dependency management and proactive security measures to prevent sophisticated cross-platform malware.

Aug 8, 2026Read
Open Source Security Isn't Child's Play: Practical Steps for Engineers - VITI Security
Cybersecurity

Open Source Security Isn't Child's Play: Practical Steps for Engineers

The carefree era of open source is over. Learn concrete steps to secure your open source supply chain and protect your organization from critical vulnerabilities.

Aug 7, 2026Read
Free ChatGPT Upgrades: Securing Your SMB in the AI Era - VITI Security
AI Security

Free ChatGPT Upgrades: Securing Your SMB in the AI Era

OpenAI's recent ChatGPT upgrades mean more powerful AI is widely available, even for free users. This shift demands SMBs reassess their security controls to mitigate new AI-driven threats while leveraging its benefits.

Aug 7, 2026Read
The Silent Threat: How Weak Randomness Undermines Your Application Security - VITI Security
Cybersecurity

The Silent Threat: How Weak Randomness Undermines Your Application Security

A recent $5.7 million drain from crypto wallets highlights a critical and often overlooked vulnerability: weak random number generation. This flaw can silently compromise cryptographic keys, session tokens, and other vital security elements, demanding immediate attention from developers and security practitioners.

Aug 6, 2026Read
Ransomware Arrests: Why Proactive Defense Remains Non-Negotiable - VITI Security
Cybersecurity

Ransomware Arrests: Why Proactive Defense Remains Non-Negotiable

A recent sentencing shows law enforcement wins against ransomware, but don't mistake this for a decreased threat. Comprehensive cybersecurity controls and incident response are still critical.

Aug 6, 2026Read
OVSwrap: Understanding and Mitigating Linux Local Privilege Escalation - VITI Security
Cybersecurity

OVSwrap: Understanding and Mitigating Linux Local Privilege Escalation

A recent Linux kernel vulnerability (CVE-2026-64531) highlights the critical threat of local privilege escalation. Learn why this matters for your Linux infrastructure and what immediate steps you need to take.

Aug 5, 2026Read
AI Agents Are Here: Fortifying SMB Defenses Against Automated Attacks - VITI Security
AI Security

AI Agents Are Here: Fortifying SMB Defenses Against Automated Attacks

AI agents are now a proven attack vector, making advanced cyberattacks more accessible and scalable. SMBs must adapt their security posture with concrete controls and vigilance.

Aug 5, 2026Read
AI Erases the Junior: New Threat Models for SMBs - VITI Security
AI Security

AI Erases the Junior: New Threat Models for SMBs

AI is fundamentally changing the threat landscape, transforming what we once called 'junior' attackers into adversaries capable of sophisticated operations. Our old risk models are now obsolete; every threat must be taken seriously.

Aug 4, 2026Read