All Posts
Is Microsoft Copilot Worth the Investment?
Apr 18, 2024
Is Microsoft Copilot worth the investment? Varonis experts weigh in on the ROI of the powerful generative AI tool based on Forrester Research's latest study.
Stop Configuration Drift With Varonis
Apr 16, 2024
Stop configuration drift in your environment with Varonis' automated data security posture management platform.
Palo Alto Networks PAN-OS Zero-Day Active Exploit: What You Need to Know
Apr 12, 2024
Palo Alto Networks issued a warning on April 12, 2024, that a critical, unpatched vulnerability in their PAN-OS firewall is being actively exploited.
Sisense Data Breach: What You Need to Know
Apr 11, 2024
The U.S. Cybersecurity and Infrastructure Agency (CISA) issued an alert this week warning Sisense customers of a data breach. Here's what you need to know.
Ensuring Data Integrity in the Age of AI: How State and Local Governments Can Protect Their Data
Apr 09, 2024
Varonis Field CTO Brian Vecci chats about enhancing digital integrity for state and local governments in the age of AI.
Speed Data: Combating the Cybersecurity Skills Shortage With Bryan Chnowski
Apr 09, 2024
Bryan Chnowski, Deputy CISO for Nuvance Health, explains why one of the most significant cybersecurity risks on the horizon is the shortage of workers.
Sidestepping SharePoint Security: Two New Techniques to Evade Exfiltration Detection
Apr 09, 2024
Varonis Threat Labs discovered two techniques in SharePoint that allow users to circumvent audit logs and avoid triggering download events while exfiltrating files.
XZ Backdoor: Supply Chain Jump Scare
Apr 05, 2024
While the XZ backdoor is scary, most companies learned from SolarWinds
Know Before You Go: Your Guide to RSAC 2024
Apr 03, 2024
Discover what sessions, events, and activities should be added to your RSA Conference 2024 agenda.
Introducing Varonis for Microsoft 365 Copilot
Apr 02, 2024
Varonis for Microsoft 365 Copilot is the industry's first purpose-built cybersecurity solution to secure Microsoft’s AI-powered productivity tool before and after deployment.
Speed Data: The Benefits of Simplicity With Mark Bruns
Mar 29, 2024
CISO Mark Burns shares cybersecurity knowledge amassed over 25 years, the pros and cons of gen AI, how to protect data, and why compromise is key.
Varonis Accelerates the Secure Adoption of Microsoft Copilot for Microsoft 365
Mar 28, 2024
Varonis and Microsoft forged a new strategic collaboration to help organizations safely harness one of the most powerful productivity tools on the planet — Microsoft Copilot for Microsoft 365.
What's New in Varonis: March 2024
Mar 28, 2024
Varonis unveiled updates designed to help you detect and investigate threats, improve your Salesforce and Azure security posture, and streamline your data discovery requests.
What is Managed Data Detection and Response (MDDR)?
Mar 26, 2024
XDR and MDR offerings are threat-focused and leave you data-blind. Varonis MDDR helps mitigate complex threats to your most valuable asset: data.
Increased Threat Activity Targeting Ivanti Vulnerabilities
Mar 20, 2024
A recent surge in activity targeting Ivanti Connect Secure (ICS) involves chaining two vulnerabilities that give threat actors the ability to execute arbitrary commands remotely.
6 Prompts You Don't Want Employees Putting in Copilot
Mar 15, 2024
Discover what simple prompts could expose your company’s sensitive data in Microsoft Copilot.
Generative AI Security: Preparing for Salesforce Einstein Copilot
Mar 12, 2024
See how Salesforce Einstein Copilot’s security model works and the risks you must mitigate to ensure a safe and secure rollout.
DSPM Buyer's Guide: How To Choose a DSPM Solution
Mar 11, 2024
Understand the different types of DSPM solutions, avoid common pitfalls, and ask questions to ensure you purchase a data security solution that meets your unique requirements.
Speed Data: Preparing for the Unknown in Cybersecurity With Ian Hill
Mar 11, 2024
Ian Hill, the Director of Information and Cybersecurity for Upp Telecommunications, offers his take on AI and the future of tech, shares his tricks for a good cyber defense, and explains why the best-laid plans of mice and security professionals often go astray.
Understanding and Applying the Shared Responsibility Model at Your Organization
Mar 07, 2024
To avoid significant security gaps and risks to sensitive data, organizations need to understand the shared responsibility model used by many SaaS providers.
Varonis MDDR: Industry's First Managed Data Detection and Response Offering
Mar 05, 2024
Varonis MDDR introduces a new 24x7x365 threat detection and response service built to stop data breaches.
Speed Data: Film, Foodies, and the Future of Tech With David Ulloa
Feb 27, 2024
Dr. David Ulloa, Chief Security Information Officer at IMC Companies, shares the best line of defense against a sophisticated threat actor.
What’s New in Varonis: Feb 2024
Feb 26, 2024
Improve your data security posture management efforts with this month's updates to the Varonis Data Security Platform.
Varonis joins Marsh McLennan Agency’s Cyber Resiliency Network
Feb 20, 2024
Varonis is teaming up with Marsh McLennan Agency. Together, we'll help organizations improve their cyber resilience with industry-leading DSPM solutions.
Security Vulnerabilities in Apex Code Could Leak Salesforce Data
Feb 20, 2024
Varonis' threat researchers identified high- and critical-severity vulnerabilities in Apex, a programming language for customizing Salesforce instances.
DSPM Report Highlights Risks That Lead to Significant Data Breaches
Feb 14, 2024
Varonis' new DSPM report reveals that typical companies are widening their blast radius by oversharing permissions, excess ghost users, lack of MFA, and more.
Speed Data: Thinking From a Cyberattacker's Perspective With Dalal Alharthi
Feb 13, 2024
Dr. Dalal Alharthi talks about the importance of organizations anticipating a breach and seeing the world through the eyes of an attacker.
Behind the Varonis Rebrand
Feb 12, 2024
Discover the strategy behind Varonis' rebrand that involved a full transition to a hero archetype and the introduction of Protector 22814.
Automatically Remove Salesforce Public Links with Varonis
Feb 06, 2024
Varonis’ least privilege automation capabilities now remove public Salesforce links automatically.
Varonis Delivers Market-leading Salesforce Security
Feb 06, 2024
Varonis delivers market-leading Salesforce security
Speed Data: Hiring the Right Cybersecurity Professionals With Leah McLean
Feb 01, 2024
Cofounder of the nonprofit Whole Cyber Human Initiative, Leah McLean, shares her advice for recruiting teams looking for cybersecurity superstars and why it’s so important for women to have representation in tech.
What’s new in Varonis: Jan 2024
Jan 31, 2024
This month brings you a fresh set of updates designed to improve your cybersecurity journey.
Varonis Introduces Universal Classification Support for Databases
Jan 30, 2024
Integrate Varonis with virtually any network-connected database to discover and classify sensitive data at scale with pinpoint accuracy.
Varonis Expands Coverage to Help Secure Critical Snowflake Data
Jan 24, 2024
Varonis extends DSPM coverage to Snowflake, providing enhanced visibility and data security for critical Snowflake data.
Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes
Jan 18, 2024
Varonis Threat Labs discovered a new Outlook exploit and three new ways to access NTLM v2 hashed passwords.
Speed Data: When Lives Depend on Strong Security With John Mason
Jan 18, 2024
Tempo Technology Services' John Mason shares why strong cybersecurity in healthcare is so critical and how organizations can combat malicious actors.
Varonis Named a Leader in GigaOm’s 2023 Radar Report for Data Security Platforms
Jan 12, 2024
Varonis is proud to be named a Leader in GigaOm’s first-ever Radar Report for Data Security Platforms.
Speed Data: The Principles of GRC With Hannah DeWane
Jan 04, 2024
Hannah DeWane at Varonis shares her day-to-day world of security audits and the wonderful world of risk management.
2024 Cybersecurity Trends: What You Need to Know
Dec 26, 2023
Learn more about data security posture management, AI security risks, compliance changes, and more to prepare your 2024 cybersecurity strategy.
What’s new in Varonis: December 2023
Dec 19, 2023
This month brings you several new features to help security teams manage and secure their critical cloud data.
Straight From the CISO: Top Tips for Today's Cybersecurity Leaders
Dec 14, 2023
We’ve gained massive insight from our conversations with CISOs and other cybersecurity leaders. Now, we're passing along their wisdom to you.
Varonis Joins Salesforce AppExchange
Dec 14, 2023
The Varonis Data Security Platform can now be found on the Salesforce AppExchange
Navigating the Complex Landscape of Data Protection in the Federal Sector
Dec 13, 2023
Varonis' Justin Wilkins and Trevor Brenn highlight the importance of data security for the federal sector, the risks of gen AI, and more.
Is Your Org Ready for Microsoft Copilot?
Dec 12, 2023
Enjoy this step-by-step guide showing you how to deploy generative AI tools safely with Varonis.
Varonis Expands DSPM Capabilities with Deeper Azure and AWS Support
Dec 05, 2023
Varonis is expanding its IaaS coverage to AWS databases and Azure Blob Storage, strengthening the CSPM and DSPM pillars of our Data Security Platform.
Speed Data: The Next Generation of Cybersecurity With Mark Weber
Nov 21, 2023
Executive in Residence for the Catholic University of America Mark Weber shares tips for mentoring future cybersecurity professionals.
How Varonis Helps With Email Security
Nov 20, 2023
Discover how you can proactively reduce your email attack surface, stop data exfiltration, and curb gen AI risk with accurate and automated email security.
Varonis Introduces Athena AI to Transform Data Security and Incident Response
Nov 14, 2023
Using Athena AI, the new gen AI layer for Varonis, natural language, customers can conduct in-depth security investigations and analyses more efficiently.
Varonis Leads DSPM Market on Gartner Peer Insights
Nov 09, 2023
As a leader in data security, Varonis is proud to be rated No. 1 in Gartner’s Data Security Posture Management category.
What's New in Varonis: November 2023
Nov 07, 2023
This month, Varonis’ Data Security Platform gets new features for accelerating investigations, improving your email security posture, and enabling Zero Trust in hybrid environments.
Speed Data: Fusing Empathy and Enterprise With Illena Armstrong
Nov 06, 2023
Illena Armstrong shares her advice for future executives, discusses the importance of teamwork, and explains why empathy is powerful for leaders.
AI At Work: Three Steps To Prepare And Protect Your Business
Oct 31, 2023
Discover how your business can prepare and protect your sensitive data from the risks that generative AI presents.
DSPM vs. CSPM Solutions: Bridging Data and Cloud Security With Varonis
Oct 27, 2023
Explore the essential roles of DSPM and CSPM solutions, and see how Varonis uniquely enables you to bridge the gap between cloud and data security.
Speed Data: The Importance of Asking for Help With Michelle Griffey
Oct 24, 2023
Michelle Griffey, Chief Risk Officer for Communisis, shares the importance of asking for help and how the widespread adoption of AI is a good and bad thing.
What is a Data Risk Assessment and Why You Should Take One
Oct 23, 2023
Conducting a Data Risk Assessment can help your organization map its sensitive data and build out a comprehensive security strategy. Here's how to perform it.
How Varonis’ Data Risk Assessment Works
Oct 13, 2023
Explore how Varonis' free Data Risk Assessment works and what makes it the most-advanced DRA in the industry.
Speed Data: Behind the Scenes of Cyber Insurance Recovery With Scott Godes
Oct 11, 2023
Scott Godes, Insurance Recovery Litigator for Barnes & Thornburg LLP, chats about the importance of cyber insurance, and how data privacy has evolved.
Varonis Launches Data Center in Canada for Cloud-Native Security
Oct 11, 2023
We're excited to announce the opening of our data center in Toronto to support new customers and existing customers moving to Varonis' SaaS offering.
Cybersecurity Maturation Model Certification 2.0: How Varonis Ensures Certification for Defense Contractors
Oct 05, 2023
Varonis can help you achieve compliance and implement the Cybersecurity Maturity Model Certification 2.0 (CMMC) program to safeguard cybersecurity across the government’s DIB.
Speed Data: Why Cybersecurity is an Unceasing Progression With Siwar El Assad
Sep 27, 2023
Siwar El Assad chats about the impact of cybersecurity on modern society, the reality of breaches, and how a chance encounter led Siwar to the industry.
DSPM Deep Dive: Debunking Data Security Myths
Sep 21, 2023
DSPM is the leading acronym in cybersecurity. However, the recent buzz has cluttered the meaning of data security posture management. Let's demystify it.
Varonis Announces Salesforce Shield Integration
Sep 13, 2023
Varonis now integrates with Salesforce Shield to provide deep visibility into Salesforce and help organizations secure their mission-critical data.
Speed Data: Rethinking Traditional Cybersecurity Principles With Rick Howard
Sep 11, 2023
Rick Howard, author, journalist, and Senior Fellow at the CyberWire, chats about his new book on rebooting cybersecurity principles with Varonis' Megan Garza.
The Benefits of Threat and Data Breach Reports
Sep 08, 2023
Threat and data breach reports can help organizations manage security risks and develop mitigation strategies. Learn our three pillars of effective data protection and the benefits from these reports.
The Biggest Security Risks to Your Salesforce Org
Sep 05, 2023
Discover how Salesforce professionals and security teams can combat the most concerning risks in their environments.
Three Ways Varonis Helps You Fight Insider Threats
Sep 02, 2023
Insider threats are difficult for organizations to combat. Varonis’ modern cybersecurity answer uses the data security triad of sensitivity, access, and activity to combat threats.
Speed Data: Tackling Federal Cybersecurity Challenges With AJ Forysiak
Aug 30, 2023
Building networks with military, civilian, and intelligence community leaders is just part of AJ’s day-to-day as the Business Development Executive for the Varonis Department of Defense team.
Varonis Opens UK Data Centre to Support SaaS Customers
Aug 29, 2023
UK expansion will help Varonis customers demonstrate compliance with the U.K.’s Data Protection Act.
Rewards and Risks: What Generative AI Means for Security
Aug 28, 2023
As AI has grown in popularity, concerns are being raised about the risks involved with using the technology. Learn the rewards and risks of using generative AI.
A CISO's First 90 Days: The Ultimate Action Plan and Advice
Aug 23, 2023
Over the last 10 years, the role of the CISO has become pretty complex. By the end of this blog you'll have a solid 90-day plan to step into a new CISO role.
Speed Data: Bringing Resiliency and Passion to Cybersecurity with Kieron Newsham
Aug 15, 2023
Kieron Newsham, Chief Technologist of Cybersecurity for Softcat, shares how his military background helps him in his role and his passion for security.
Copilot Security: Ensuring a Secure Microsoft Copilot Rollout
Aug 08, 2023
This article describes how Microsoft 365 Copilot's security model works and the risks that must be considered to ensure a safe rollout.
What’s new in Varonis: August 2023
Aug 07, 2023
This month brings you several new features to help security teams enforce Zero Trust across their cloud and on-prem environments.
How to Protect Your Cloud Environment From Today’s Top 5 Threats
Aug 04, 2023
Learn the top five cloud threats after your sensitive data and how to protect your organization from them.
SEC Cybersecurity Disclosure Requirements’ Impact on Your Business
Aug 02, 2023
New SEC regulations change how public companies disclose hacks, breaches, and cyber incidents. Here’s everything you need to know.
Is Your Data Insider-Proof? Five Steps To Keep Your Secrets Safe
Aug 02, 2023
This article explains the five steps you can take to see how prepared you are for a nefarious insider or an outside attacker that compromises an insider's account or computer.
Speed Data: The Impact of AI on Attack Vectors With Justin Michael
Jul 25, 2023
Corbin Capital Partners CTO Justin Michael discusses the hot topic of ChatGPT. Justin leads guarding sensitive data for the leading asset management firm.
Taking Microsoft Office by "Storm"
Jul 18, 2023
The “Storm-0978” ransomware group is actively exploiting an unpatched Microsoft Office and Windows HTML remote code execution vulnerability.
Building a Cloud Security Program From the Ground Up
Jul 17, 2023
There’s no one-size-fits-all approach to cloud security, but Varonis has laid out a blueprint to help guide you through the steps and start off strong.
Strengthening Resilience: Data Security vs Data Resilience Tools
Jul 13, 2023
Learn the difference between backup tools and true DSPs and what to look for when you’re choosing a DSP.
Speed Data: The Importance of Data Privacy With Jordan McClintick
Jul 10, 2023
Jordan McClintick, Director of Data Governance and Privacy for Optiv, Inc. talks about how his law degree helps him in his current role in data privacy.
Varonis in the Cloud: Building a Secure and Scalable Data Security Platform
Jul 10, 2023
How we built our cloud-native SaaS platform for scalability and security—without taking any shortcuts.
How the MOVEit Vulnerability Impacts Federal Government Agencies
Jun 29, 2023
Our latest State of Cybercrime episode examines the MOVEit vulnerability and its impact on victims, including federal government agencies.
What’s new in Varonis: June 2023
Jun 28, 2023
This month brings more cloud security features to help you better govern your SaaS and IaaS security posture.
10 Tips to Pay Back Your Salesforce Technical Debt
Jun 22, 2023
Learn best practices for managing and analyzing permissions in Salesforce and how the need for quick solutions can put your organizations data at risk.
Speed Data: The Commoditization of Cybercrime With Matt Radolec
Jun 21, 2023
Matt Radolec at Varonis discusses the future of cybersecurity, the rise of ransomware-as-a-service (RaaS), and what security risks keep him up at night.
Imposter Syndrome: UI Bug in Visual Studio Lets Attackers Impersonate Publishers
Jun 07, 2023
Varonis Threat Labs found a bug in Microsoft Visual Studio installer that allows an attacker to impersonate a publisher and issue a malicious extension to compromise a targeted system
How to Deal With Sensitive Data in Salesforce: A Guide to Data Classification
Jun 06, 2023
Salesforce Ben and the Varonis team up to discuss Salesforce data classification best practices.
Ghost Sites: Stealing Data From Deactivated Salesforce Communities
May 31, 2023
Varonis Threat Labs discovered improperly deactivated Salesforce 'ghost' Sites that are easily found, accessible, and exploitable by attackers.
Speed Data: CISO Leadership Tips With Pat Benoit
May 30, 2023
Pat shared the four leadership rules he follows, what it takes to succeed in cybersecurity, and why he just might be “The Most Interesting Man in the World.”
What's New in Varonis: May 2023
May 30, 2023
Check out the new features that help security teams automatically enforce least privilege and uniformly apply sensitivity labels across their hybrid cloud and on-prem environments.
Meta's $1.3B Fine: What can Happen if you Don’t Monitor Your PII
May 22, 2023
Continuous discovery and data monitoring critical to identify misplaced PII.
What Automation Means For Cybersecurity—And Your Business
May 03, 2023
This article explains how automation can help turn the right information into action, helping to defend against cyberattacks, mitigate risk, shore up compliance and improve productivity.
Salesforce Misconfiguration Causes Sensitive Data Leaks
Apr 28, 2023
Brian Krebs recently reported that an alarming number of organizations—including banks and healthcare providers—are leaking sensitive information due to a misconfiguration in Salesforce Communities.
How Varonis' approach to SSPM helps your company
Apr 26, 2023
Adopt a data-first approach with Varonis' SSPM, securing SaaS apps & reducing risk. Learn how you can get better visibility, automation, and protection.
Varonis Launches Third-Party App Risk Management
Apr 25, 2023
Varonis reduces your SaaS attack surface by discovering and remediating risky third-party app connections.
Data Security Posture Management (DSPM): Best Practices Guide for CISOs
Apr 19, 2023
Master Data Security Posture Management (DSPM) best practices with our CISOs' guide. Learn to select the right tool, maintain compliance, and prevent data breaches.
Your Guide to the 2023 RSA Conference
Apr 13, 2023
Varonis has compiled the top RSAC sessions you won’t want to miss. Follow our handy agenda to take advantage of everything RSAC 2023 has to offer.
Varonis Opens Australia Data Centre to Support SaaS Customers
Apr 11, 2023
Australian expansion allows Varonis customers to achieve automated data security outcomes while following national standards for data privacy.
The Exact Data Security Roadmap We've Used with 7,000+ CISOs
Apr 11, 2023
Explore the Varonis data security roadmap for modern protection, aiding 7,000+ CISOs in compliance and safeguarding valuable data.
Global Threat Trends and the Future of Incident Response
Apr 10, 2023
The Varonis Incident Response team discusses recent global threat trends and shares why proactive IR is the future of data security.
80 Cybersecurity Statistics and Trends [updated 2023]
Mar 29, 2023
We’ve compiled more than 70 cybersecurity statistics for 2023, to give you a better idea of the current state of overall security.
Top Cybersecurity Trends for 2023
Mar 23, 2023
We’ve pulled together top security predictions for 2023 to help you determine where you should heed caution and where you can breathe easily.
Varonis Named a Leader in The Forrester Wave™: Data Security Platforms, Q1 2023
Mar 22, 2023
Varonis Named a Leader in the Forrester Wave™: Data Security Platforms, Q1 2023, receiving the highest score in the strategy category.
A Step-By-Step Guide to California Consumer Privacy Act (CCPA) Compliance
Mar 10, 2023
CCPA Compliance: Everything you need to know about protecting user data under the California Consumer Privacy Act.
HIPAA Compliance: Your Complete 2023 Checklist
Mar 10, 2023
Is your organization ready to comply with 2023 HIPAA updates and changes? Ensure HIPAA compliance with your comprehensive 2023 checklist.
How Varonis Saves Salesforce Admins Hours in Their Day
Mar 08, 2023
Varonis provides industry leading Salesforce management and permission implications capabilities to help save Salesforce admins hours in their day.
HardBit 2.0 Ransomware
Feb 20, 2023
HardBit is a ransomware threat that targets organizations to extort cryptocurrency payments for the decryption of their data. Seemingly improving upon their initial release, HardBit version 2.0 was introduced toward the end of November 2022, with samples seen throughout the end of 2022 and into 2023.
Neo4jection: Secrets, Data, and Cloud Exploits
Feb 08, 2023
With the continuous rise of graph databases, especially Neo4j, we're seeing increased discussions among security researchers about issues found in those databases. However, given our experience with graph databases ― from designing complex and scalable solutions with graph databases to attacking them ― we've noticed a gap between public conversations and our security researchers' knowledge of those systems.
VMware ESXi in the Line of Ransomware Fire
Feb 07, 2023
Servers running the popular virtualization hypervisor VMware ESXi have come under attack from at least one ransomware group over the past week, likely following scanning activity to identify hosts with Open Service Location Protocol (OpenSLP) vulnerabilities.
Varonis Enhances GitHub Security Offering With Secrets Discovery and Data Classification
Feb 07, 2023
Varonis is extending our world-class data classification capabilities to discover secrets, keys, and other sensitive data embedded in your GitHub repositories and source code.
Varonis Announces Proactive Incident Response for SaaS Customers
Jan 31, 2023
Varonis offers the brightest minds in offensive and defensive security, watching your data for threats.
Introducing Automated Posture Management: Fix Cloud Security Risks with One-Click
Jan 26, 2023
Varonis launches Automated Posture Management to effortlessly fix cloud Security risks with a simple click of a button
CrossTalk and Secret Agent: Two Attack Vectors on Okta's Identity Suite
Jan 23, 2023
Varonis Threat Labs discovered and disclosed two attack vectors on Okta's identity suite: CrossTalk and Secret Agent.
Introducing Least Privilege Automation for Microsoft 365, Windows, Google Drive, and Box
Jan 17, 2023
Varonis announces least privilege automation for Microsoft 365, Google Drive, and Box.
Varonis Launches Customizable Data Security Posture Management (DSPM) Dashboard
Jan 03, 2023
Varonis introduces a new customizable DSPM dashboard to help improve data security posture management
Australian Privacy Act 2022 Updates
Dec 19, 2022
A series of stunning data breaches in 2022 has prompted lawmakers to begin making changes to the 1988 Australian Privacy Act in the form of the new Privacy Legislation Amendment (Enforcement and Other Measures) Bill 2022.
Varonis adds file analysis to cloud data classification capabilities
Dec 01, 2022
We’re excited to announce that Data Classification Cloud now includes robust file analysis for verifying classification results across your cloud environment.
Four Must-Know Cyber Tips for Your Business
Dec 01, 2022
The real story behind today’s breaches is never about an isolated bad decision—it’s about the many decisions made long before a sleepy network administrator gets a call from an attacker.
Varonis Threat Labs Discovers SQLi and Access Flaws in Zendesk
Nov 15, 2022
Varonis Threat Labs found a SQL injection vulnerability and a logical access flaw in Zendesk Explore, the reporting and analytics service in the popular customer service solution, Zendesk.
The Logging Dead: Two Event Log Vulnerabilities Haunting Windows
Oct 25, 2022
You don’t have to use Internet Explorer for its legacy to have left you vulnerable to LogCrusher and OverLog, a pair of Windows vulnerabilities discovered by the Varonis Threat Labs team.
Automate Data Security With Varonis Data-centric Insights and Cortex XSOAR
Oct 24, 2022
Discover how to leverage Varonis data risk insights with Cortex XSOAR to accelerate investigations.
What is IDOR (Insecure Direct Object Reference)?
Oct 14, 2022
Insecure Direct Object References (IDOR) are common, potentially devastating vulnerabilities resulting from broken access control in web applications.
Azure Managed Identities: Definition, Types, Benefits + Demonstration
Oct 05, 2022
Use this guide to learn about Azure managed identities: What they are, how many types there are, and what benefits they offer, plus how they work.
SaaS Risk Report Reveals Exposed Cloud Data is a $28M Risk for Typical Company
Oct 04, 2022
The Great SaaS Data Exposure examines the challenge CISOs face in protecting data across a growing portfolio of SaaS apps and services such as Microsoft 365.
The 12 PCI DSS Requirements: 4.0 Compliance Checklist
Oct 03, 2022
Version 4.0 of the Payment Card Industry Data Security Standard (PCI DSS) is right around the corner. Prepare with our PCI DSS compliance checklist.
Varonis Adds Secrets Discovery for On-Prem and Cloud Data Stores
Sep 27, 2022
Varonis can help you scan your environments for rogue secrets exposed in files and code stored on-prem and in the cloud.
Change These 7 Security Settings After Creating a New AWS Account
Sep 16, 2022
Use these seven AWS security best practices for simple configuration changes on a new AWS account.
Fighting Golden Ticket Attacks with Privileged Attribute Certificate (PAC)
Sep 15, 2022
Learn how and why to control the Active Directory Environment state with PACRequestorEnforcement, the implications of doing so and how to detect Golden Ticket attacks happening in your network.
Compare Salesforce user permissions with ease
Sep 13, 2022
DatAdvantage Cloud now enables admins to compare two Salesforce users’ effective permissions side-by-side with a simple click of a button.
What Is a Data Leak? Definition and Prevention
Sep 09, 2022
Learn why data leaks can be devastating for companies and how you can defend against them.
What Is Zero Trust? Architecture and Security Guide
Sep 09, 2022
Zero trust is a security model that protects against both malicious insiders and external attacks that have breached your perimeter.
U.S. Privacy Laws: The Complete Guide
Sep 02, 2022
This guide breaks down the entirety of the U.S. privacy law ecosystem to help you understand the rights and obligations of citizens and businesses.
SOC 2 Compliance Definition & Checklist
Aug 26, 2022
System and Organization Controls (SOC 2) compliance requires adherence to specific guidelines. This detailed definition and checklist can get you started.
What is Mimikatz? The Beginner's Guide
Aug 26, 2022
Mimikatz is an open-source application that allows users to view and save authentication credentials like Kerberos tickets.
Anatomy of a SolidBit Ransomware Attack
Aug 22, 2022
Solidbit is a ransomware variant derived from Yashma and containing elements of LockBit. Discover how Solidbit's capabilities, execution, what file types it targets, and how to tell if you're been infected.
How to Use Wireshark: Comprehensive Tutorial + Tips
Aug 19, 2022
Learn how to use Wireshark, a widely-used network packet and analysis tool. This tutorial has everything from downloading to filters to packets.
Your Sales Data Is Mission-Critical: Are You Protecting It?
Aug 18, 2022
If you’re like many executives, you might assume your data is secure within those cloud applications. That’s a dangerous assumption, though. Cloud providers are responsible for everything that delivers their application (e.g., their data center); it’s your responsibility to protect the data inside it.
Varonis Maps Cloud Security Alerts to MITRE ATT&CK
Aug 17, 2022
In Varonis’ latest update of DatAdvantage Cloud, we’re layering MITRE ATT&CK tactics and techniques over cloud alerts to aid in faster incident response.
SecurityRWD - How Amazon S3 Object-Tagging Can Put Form Around Flat Storage
Jul 28, 2022
Your favorite Varonis team members Ryan O'Boyle and Kilian Englert will explain how unlike classic storage arrays or traditional file servers, S3 buckets are a linear, flat storage solution, offering data object-tagging to create a sense of hierarchy.
How to Create S3 Buckets in AWS with CloudFormation: Step-by-Step Guide
Jul 22, 2022
Use AWS CloudFormation to create resources such as S3 buckets. Infrastructure as code enables a repeatable, reliable deployment process. Learn more here.
What Is SQL Injection? Identification & Prevention Tips
Jul 22, 2022
SQL injection is a serious open web application security project (OWASP) vulnerability. Learn more about how to combat injection attacks in this article.
What Is a Privacy Impact Assessment (PIA)?
Jul 22, 2022
A privacy impact assessment (PIA) helps firms protect data. Find out about this robust approach to data loss prevention and how to implement your own PIA.
161 Cybersecurity Statistics and Trends [updated 2023]
Jul 08, 2022
These cybersecurity statistics for 2023 are grouped by category and include breaches, costs, crime type, compliance, industry-specific stats, job outlook.
Data Lifecycle Management (DLM): Everything You Need to Know
Jul 08, 2022
Data lifecycle management (DLM) is the process of managing data from creation to deletion. In this article, we’ll cover how DLM works and why you need it.
What is the CIA Triad?
Jul 08, 2022
Learn how the CIA triad can be used to classify, secure, and protect your data.
What Is Network Access Control? Explaining NAC Solutions
Jul 07, 2022
Explore network access control (NAC), a technology aimed at giving organizations more control over who can access their network and with what permissions.
Ransomware Statistics, Data, Trends, and Facts [updated 2023]
Jul 05, 2022
Ransomware is one of the most common types of malware used in cyberattacks. Check out these comprehensive ransomware statistics, plus prevention tips.
What is SSPM? Overview + Guide to SaaS Security Posture Management
Jul 01, 2022
SaaS security posture management (SSPM) is an automated solution that helps bolster the protection of all SaaS applications used by organizations.
SOX Compliance Checklist & Audit Preparation Guide
Jun 30, 2022
The Sarbanes-Oxley Act (SOX) requires public U.S. companies meet strict reporting and security standards. Here’s what you need to know to comply with SOX.
IDS vs. IPS: What Organizations Need to Know
Jun 30, 2022
We explore IDS vs. IPS and break down the differences between the two cybersecurity systems. Read on to evaluate using them in your network.
How a Doggo Can Teach You the Difference Between Salesforce Objects and Records
Jun 30, 2022
What can Fido teach you about Salesforce? Kilian Englert and Ryan O'Boyle from the Varonis Cloud Architecture team host a special, goodest boy guest to explain the difference between objects, fields, and records in the popular CRM.
DNS over HTTPS as a covert Command and Control channel
Jun 30, 2022
Learn how DNS over HTTPS (DoH) is being actively used as a Command and Control (C2) channel by threat actors.
What is Red Teaming? Methodology & Tools
Jun 29, 2022
Red teaming simulates real-world hacks on your organization’s data and networks and spotlight vulnerabilities that help organizations strengthen security.
What is a Security Policy? Definition, Elements, and Examples
Jun 29, 2022
A security policy is a document that spells out principles and strategies for an organization to maintain the security of its information assets.
What is Open XDR? Benefits and Security Comparisons
Jun 29, 2022
Learn all about the new open XDR solution and whether it’s the right fit for your organization’s security needs.
What is Traceroute? How It Works and How to Read Results
Jun 25, 2022
Traceroute is a tool to trace the path of an IP packet as it traverses routers locally or globally. It is primarily used for diagnostic and troubleshooting purposes.
Ryuk Ransomware: Breakdown and Prevention Tips
Jun 25, 2022
Ryuk ransomware targets large organizations and spreads with deadly speed. Learn about the strain and how to prevent your company from becoming a victim.
What is an Insider Threat? Definition and Examples
Jun 24, 2022
Insider threats are internal risks to cybersecurity and data — learn more about insider threats, indicators, and how to detect them and prevent breaches.
Evil Twin Attack: What it is, How to Detect & Prevent it
Jun 24, 2022
The evil twin attack takes advantage of public WiFi connections. Learn how to prevent it from reaching you and your devices.
How to Paint the Complete Picture of Salesforce Objects and Fields
Jun 22, 2022
Kilian Englert and Ryan O'Boyle from the Varonis Cloud Architecture team explain why — when it comes to understanding what Salesforce objects and fields a user can access — all levels of entitlements need to be taken into consideration to gain a holistic view of what the user can do (or cannot) do in Salesforce.
Anatomy of a LockBit Ransomware Attack
Jun 17, 2022
A detailed case study of the exact techniques and methods that threat actors used in a real-life ransomware attack.
What is Cyber Espionage? Complete Guide with Protection Tips
Jun 16, 2022
Cyber espionage is the unauthorized use of computer networks to access privileged information. Read on to learn more about this growing worldwide problem.
Rogue Shortcuts: LNK'ing to Badness
Jun 16, 2022
Learn how threat actors continue to manipulate Windows shortcut files (LNKs) as an exploit technique.
Varonis Adds Data Classification Support for Amazon S3
Jun 15, 2022
Varonis bolsters cloud security offering with data classification for Amazon S3.
Group Policy Objects (GPOs): How They Work & Configuration Steps
Jun 15, 2022
Group Policy Objects (GPOs) let system admins control and implement cybersecurity measures from a single location. Learn about GPOs and how they work here.
Data Protection Guide: How To Secure Google Drive for Your Business
Jun 15, 2022
Does your company store, handle, or transmit confidential data in Google Drive? Learn about security, encryption, and data protection in Google Workspace.
So I Creep: Aggregating Salesforce Permissions Can Add up to Excessive Risk
Jun 10, 2022
Salesforce entitlements go beyond object and record access — they can give users the ability to perform actions within Salesforce as well. Kilian Englert and Ryan O'Boyle from the Varonis Cloud Architecture team discuss how the combination of Salesforce profiles, permission sets, and permission set groups can grant users far greater rights than were intended.
What Is Data Governance? Framework and Best Practices
Jun 07, 2022
Data Governance helps organize, secure, and standardize data for all types of organizations. Learn more about data governance frameworks here.
ISO 27001 Compliance Guide: Essential Tips and Insights
Jun 03, 2022
Looking to earn ISO 27001 compliance? Learn about this widely known information security standard, what’s in it, and how to become certified in this post!
NIST 800-53: Definition and Tips for Compliance
Jun 03, 2022
Learn best practices for adopting and implementing the NIST 800-53 framework, a compliance standard for federal agencies and partners.
NIST 800-171 Compliance Checklist and Terminology Reference
Jun 02, 2022
Government contractors who handle Controlled Unclassified Information (CUI) must be NIST 800-171 compliant. Use this checklist as a complete reference.
How to Prepare for a Salesforce Permissions Audit
Jun 02, 2022
In this post, I'll walk you through what a Salesforce audit is, how permissions work, and provide tips on how you can prepare.
Spoofing, and SaaS Vanity URLs, and Social Engineering... Oh My!
May 25, 2022
Kilian Englert and Ryan O'Boyle discuss the recent discovery by Varonis researchers of risks in vanity URL validation, and share what to do to prepare your organization for if (or more likely when) a user accidentally discloses credentials.
84 Must-Know Data Breach Statistics [2023]
May 20, 2022
These 2022 data breach statistics cover risk, cost, prevention and more — assess and analyze these stats to help prevent a data security incident.
SecurityRWD – Getting Started With Salesforce Entitlements
May 19, 2022
Kilian Englert and Ryan O'Boyle from Varonis dive into the Salesforce interface, cover the basics of navigation, and share what to look for when performing a manual Salesforce entitlement review.
Why Every Cybersecurity Leader Should ‘Assume Breach’
May 16, 2022
Any system, account or person at any time can be a potential attack vector. With such a vast attack surface, you need to assume attackers will breach at least one vector.
Spoofing SaaS Vanity URLs for Social Engineering Attacks
May 11, 2022
SaaS vanity URLs can be spoofed and used for phishing campaigns and other attacks. In this article, we’ll showcase two Box link types, two Zoom link types, and two Google Docs link type that we were able to spoof.
Bad Rabbit Ransomware
May 06, 2022
Bad Rabbit is a ransomware strain that spread via hacked websites, infected systems via a fake Adobe installer and held encrypted files for Bitcoin.
SecurityRWD - Salesforce as a file server? You bet.
Apr 25, 2022
Did you know Salesforce isn't limited to just, well, sales? This leading CRM platform can function as a data repository for critical industries ranging from healthcare to finance. Listen in as Kilian Englert and Ryan O'Boyle from the Varonis Cloud Architecture team share their reasoning for thinking about Salesforce as a data store, and tell you what you should consider if tasked with securing it.
Hive Ransomware Analysis
Apr 19, 2022
Learn how Hive ransomware exploits public servers, spreads through your network, encrypts sensitive files, and exports victims for cryptocurrency.
SecurityRWD - Introduction to AWS Lambda
Apr 12, 2022
Join Kilian Englert and Ryan O'Boyle from the Varonis Cloud Architecture team as they discuss AWS's serverless computing platform, Lambda. Find out what the Lambda functions allow for, see an everyday example of how it all comes together, and learn why it's so important for organizations to monitor Lambda's behavior within the entire Amazon Web Service ecosystem.
How to Use Volatility for Memory Forensics and Analysis
Apr 12, 2022
This article will cover what Volatility is, how to install Volatility, and most importantly how to use Volatility.
CCSP vs. CISSP: Which One Should You Take?
Apr 07, 2022
Get an overview of the CCSP and CISSP exams and learn which certification is best for you and your career.
SecurityRWD – GitHub Secret-Scanning Could Create False Sense of Security
Apr 07, 2022
Microsoft recently announced they would be adding another layer of security to their popular code repository, GitHub, by scanning for "secrets" (API tokens, access keys, etc. inadvertently saved in the platform). However, as Kilian Englert and Ryan O'Boyle from the Varonis Cloud Architecture team discuss, this positive first step shouldn't lull developers into a false sense of security. Listen in to hear why it's so important not to let your guard down when securing critical cloud apps and data.
SecurityRWD - Introduction to AWS Elastic Compute Cloud (EC2)
Apr 07, 2022
Concerning headlines about threat groups targeting major security and technology vendors are keeping more than a few security and IT professionals up at night. Kilian Englert and Ryan O'Boyle from the Varonis Cloud Architecture team discuss why advanced attackers target technology like SSO and why organizations must "assume" breach. Watch now for helpful tips to harden your environment and protect your data.
What is the NIST Cybersecurity Framework?
Apr 06, 2022
Learn how you can implement the NIST cybersecurity framework within your own organization.
12 Group Policy Best Practices: Settings and Tips for Admins
Apr 04, 2022
Group Policy configures settings, behavior, and privileges for user and computers. In this article, you’ll learn best practices when working with Group Policy.
Your Guide to Simulated Cyberattacks: What is Penetration Testing?
Mar 31, 2022
Penetration testing simulates a real-world cyber-attack on your critical data and systems. Here’s what penetration testing is, the processes and tools behind it, and how pen testing helps spot vulnerabilities before hackers do.
What is Terraform: Everything You Need to Know
Mar 30, 2022
Terraform is an infrastructure-as-code (IaC) solution that helps DevOps teams manage multi-cloud deployments. Learn about what is Terraform, the benefits of IaC, and how to get started.
Defending Your Cloud Environment Against LAPSUS$-style Threats
Mar 29, 2022
Varonis breaks down the recent LAPSUS$ hacks and provides best practices for defending your cloud environment against LAPSUS$ style threats
How to Use Ghidra to Reverse Engineer Malware
Mar 21, 2022
An overview of the malware analysis tool Ghidra. This article covers how to install and navigate the Ghidra interface.
What Is a Botnet? Definition and Prevention
Mar 18, 2022
Learn why botnets can be so dangerous and what your organization can do to protect your IoT devices and network.
SecurityRWD - Introduction to AWS Simple Storage Service (S3)
Mar 17, 2022
Kilian Englert and Ryan O'Boyle from the Varonis Cloud Architecture team compare and contrast Amazon Web Services S3 to traditional on-prem storage systems. Listen in as the team discusses how AWS S3 goes beyond basic data storage, and enables programmatic access to apps and services inside and outside the AWS environment.
Is this SID taken? Varonis Threat Labs Discovers Synthetic SID Injection Attack
Mar 11, 2022
A technique where threat actors with existing high privileges can inject synthetic SIDs into an ACL creating backdoors and hidden permission grants.
ContiLeaks: Ransomware Gang Suffers Data Breach
Mar 04, 2022
Conti, a prolific ransomware group, has suffered a leak of both internal chat transcripts and source code being shared by a reported Ukrainian member
SecurityRWD - Introduction to AWS Identity and Access Management (IAM)
Mar 04, 2022
Kilian Englert and Ryan O'Boyle from the Varonis Cloud Architecture team compare and contrast Amazon Web Services Identity and Access Management against a traditional on-prem setup with Active Directory. Listen in as the team discusses how AWS IAM goes beyond simple user and group management to creating an entire network and defining access to network resources and infrastructure.
SecurityRWD - Introduction to AWS Services
Mar 01, 2022
Kilian Englert and Ryan O'Boyle from the Varonis Cloud Architecture team kick off a new series diving into the various services found under the AWS umbrella. In this video, they introduce and provide an overview of some of the core services including IAM, S3, and EC2.
Ransomware-as-a-Service Explained: What is RaaS?
Feb 25, 2022
Ransomware as a service (RaaS) is an emerging and potent cybersecurity threat to all organizations. If you’re unaware of how RaaS works, your system is potentially at risk. What RaaS is and how to guard against it.
Common Types of Malware
Feb 25, 2022
This piece covers the various types of malware that are available and their characteristics.
Try Varonis free.
Deploys in minutes.