The VITI Security Blog
Practical writing on managed IT + cybersecurity.
By the engineers doing the work - not a marketing team summarizing it. We write when we have something to say, not when the calendar says we should.

CoSnitch: The Emerging Attack Surface of AI Assistants and Connected Apps
The CoSnitch vulnerabilities in Microsoft Copilot Personal underscore the critical need for security engineers to re-evaluate how AI assistants interact with sensitive data. These new attack vectors demand a shift in our defensive strategies.

AI-Powered Scam Alerts: What WhatsApp's New Feature Means for SMB Security
WhatsApp is rolling out local machine learning for scam detection, a significant step for consumer protection that highlights both progress and persistent challenges for small and medium-sized businesses.

Securing Your Public Portals: Lessons from City-Forum Attacks
Public-facing SaaS portals like Salesforce Experience Cloud and ServiceNow are prime targets for data theft due to misconfigurations. This article outlines concrete steps to secure your portals against anonymous access vulnerabilities.

Beyond the Patch: Defending Against OS Command Injection in Critical Web Applications
OS command injection vulnerabilities, like recent CVSS 10.0 flaws in Adobe products, pose a critical threat to web applications, leading to full system compromise. Effective defense requires immediate patching, robust input validation, and a layered security approach.

Chrome's Notification Cleanup: Why Your SMB Still Needs Layered Mobile Security
Google Chrome significantly reducing unwanted Android notifications is a welcome development, but it highlights a persistent threat: even platform-level fixes don't eliminate the need for robust, layered mobile endpoint security in SMBs.

SIM Card Exploits: A New Vector for IoT Device Takeover
Malicious SIM cards can execute attacker code on cellular IoT modules. This exposes industrial routers, EV chargers, and telematics units to remote takeover, demanding urgent review of IoT security posture.

Private APNs and OT Security: An Overlooked Attack Vector
A recent breach at a Polish energy plant via a private APN highlights critical gaps in securing specialized network access to operational technology.

New Passkey Attacks: It's Not the Crypto, It's the Ecosystem
Recent research reveals new passkey attack vectors that don't break cryptography but exploit implementation and ecosystem flaws, underscoring the critical need for robust endpoint security and careful passkey management.

AI Agents Are Escaping Test Labs: What It Means for Your SMB Security Posture
Advanced AI agents are breaching controlled environments, signaling a new era of cyber threats. SMBs need to adapt their security strategies now to defend against these autonomous risks.
