The VITI Security Blog
Practical writing on managed IT + cybersecurity.
By the engineers doing the work - not a marketing team summarizing it. We write when we have something to say, not when the calendar says we should.

AI Agents Are Here: Fortifying SMB Defenses Against Automated Attacks
AI agents are now a proven attack vector, making advanced cyberattacks more accessible and scalable. SMBs must adapt their security posture with concrete controls and vigilance.

AI Erases the Junior: New Threat Models for SMBs
AI is fundamentally changing the threat landscape, transforming what we once called 'junior' attackers into adversaries capable of sophisticated operations. Our old risk models are now obsolete; every threat must be taken seriously.

Beyond Hotel Wi-Fi: Securing Microsoft 365 Against Sophisticated Cloud Attacks
Recent APT29 attacks via hotel Wi-Fi highlight a critical lesson for SMBs: your Microsoft 365 environment is a direct target for sophisticated actors, and you need robust defenses that extend beyond basic network security.

AI in the SOC: Beyond the Hype, Practical Steps for SMBs
Integrating AI into your SMB SOC isn't about replacing analysts; it's about augmenting them to tackle an ever-increasing workload. We'll detail concrete use cases and practical implementation strategies.

AI That Solves Math: Your Mandate for Proactive AI Security
OpenAI's Astra signals a critical inflection point for cybersecurity. We must prioritize AI governance and secure every layer of the AI lifecycle to manage its evolving capabilities.

Rails Active Storage RCE - Immediate Action Required for Your Applications
A critical vulnerability in Rails Active Storage opens the door to arbitrary file reads and potential RCE. Understand the impact and what immediate actions your team must take to secure your applications.

When 'Bulletproof' Hardware Fails: Lessons from the Coldcard $70M Bitcoin Theft
A recent $70 million Bitcoin theft linked to a Coldcard hardware wallet flaw exposes how even specialized security hardware can fail due to fundamental design errors. For SMBs, this incident highlights the critical need for deep technical validation of vendor claims and robust, multi-layered security strategies.

Stop the Poison: Hardening Your Client-Side Supply Chain
The recent Adform script poisoning highlights a critical blind spot for many businesses: the client-side supply chain. Protecting your website from these insidious attacks requires a proactive strategy that extends beyond traditional network defenses.

Cloud Data Breaches: Third-Party Risk Is Your Risk
When third-party cloud providers face a data breach, your sensitive information is often exposed. Learn how to secure your data even when it's out of your direct control.
