The VITI Security Blog
Practical writing on managed IT + cybersecurity.
By the engineers doing the work - not a marketing team summarizing it. We write when we have something to say, not when the calendar says we should.

Beyond npm install: Guarding Your Linux Servers from Supply Chain Backdoors
Recent trojanized npm packages delivering AI-assisted Linux backdoors highlight the critical need for robust software supply chain security, even for SMBs. This isn't just a developer problem; it's a critical infrastructure risk.

Integrating AI into Your SMB SOC: Practical Steps and Pitfalls
Integrating artificial intelligence into an SMB Security Operations Center (SOC) requires clear objectives, clean data, and a human-in-the-loop strategy to avoid new risks.

Rust Crates Hacked: Your Supply Chain is Next-Level Vulnerable
A recent Rust supply chain attack underscores how critical it is for every development team to secure their dependency management and build processes. You need to act now.

Unauthenticated Application Access: Lessons from NASA for SMB Security
A recent NASA vulnerability highlights the critical danger of unauthenticated command execution in applications. For SMBs, this means understanding that application-layer flaws can bypass network defenses, necessitating robust security controls.

When Cloud Services Fail: The Real Lessons from SaaS Outages
SaaS outages like the recent ChatGPT downtime are a stark reminder that even widely adopted external services are single points of failure, necessitating robust third-party risk management and resilient operational planning for any organization. This isn't just an AI issue; it's fundamental business continuity.

Weaponized Websites: Why Your WordPress Site is a Cybercrime Infrastructure Target
The 'StopAndProtect' operation reveals a critical shift: your web assets are now being weaponized as sophisticated cybercrime infrastructure. This demands a fundamental change in how we approach web security.

Beyond the Firewall: Why Your Router's New Tricks Demand a Security Rethink
New passive sensing capabilities in consumer routers, like WiFi motion detection, introduce significant privacy and security challenges for businesses. Practitioners must re-evaluate network device capabilities and update their defense strategies.

New Ransomware Intermediaries Complicate Incident Response
A new breed of actors is contacting ransomware victims, claiming to delete stolen data for a fee. This tactic introduces significant new challenges for incident response teams.

MLflow SSRF to Cloud Credentials: Your Attack Surface is Broader Than You Think
Recent exploits targeting MLflow's SSRF vulnerability highlight a critical risk: open-source components in AI/ML stacks can directly compromise your cloud environment. SMBs must audit dependencies and fortify cloud security now to protect sensitive assets.
