 
    Nitay Bachrach
Nitay is a security researcher based in Tel Aviv, but you might encounter him anywhere in world. He is a cloud security expert, highly experienced in offensive security operations and reverse engineering. Nitay’s expertise also includes IoT devices, Linux, and local network security.
- 
						
							 Threat Research Threat ResearchSep 16, 2024 Data Theft in Salesforce: Manipulating Public LinksVaronis Threat Labs uncovered a vulnerability in Salesforce's public link feature that threat actors could exploit to retrieve sensitive data.   Nitay Bachrach 6 min read 
- 
						
							 Threat Research Threat ResearchFeb 20, 2024 Security Vulnerabilities in Apex Code Could Leak Salesforce DataVaronis' threat researchers identified high- and critical-severity vulnerabilities in Apex, a programming language for customizing Salesforce instances.   Nitay Bachrach 7 min read 
- 
						
							 Threat Research Threat ResearchMay 31, 2023 Ghost Sites: Stealing Data From Deactivated Salesforce CommunitiesVaronis Threat Labs discovered improperly deactivated Salesforce 'ghost' Sites that are easily found, accessible, and exploitable by attackers.   Nitay Bachrach 2 min read 
- 
						
							.png) Threat Research Threat ResearchFeb 08, 2023 Neo4jection: Secrets, Data, and Cloud ExploitsWith the continuous rise of graph databases, especially Neo4j, we're seeing increased discussions among security researchers about issues found in those databases. However, given our experience with graph databases ― from designing complex and scalable solutions with graph databases to attacking them ― we've noticed a gap between public conversations and our security researchers' knowledge of those systems.   Nitay Bachrach 15 min read 
- 
						
							 Threat Research Threat ResearchNov 02, 2021 Einstein's Wormhole: Capturing Outlook & Google Calendars via Salesforce Guest User BugIf your organization uses Salesforce Communities and Einstein Activity Capture, you might have unknowingly exposed your administrator's Outlook or Google calendar events to the internet due to a bug called...   Nitay Bachrach 3 min read 
- 
						
							 Data Security Threat Research Data Security Threat ResearchOct 21, 2021 Abusing Misconfigured Salesforce Experiences for Recon and Data TheftOur research team has discovered numerous publicly accessible Salesforce Experiences (formerly Salesforce Communities) that are misconfigured and expose sensitive information.   Nitay Bachrach 11 min read 
SECURITY STACK NEWSLETTER
Ready to see the #1 Data Security Platform in action?
Ready to see the #1 Data Security Platform in action?
“I was amazed by how quickly Varonis was able to classify data and uncover potential data exposures during the free assessment. It was truly eye-opening.”
Michael Smith, CISO, HKS
"What I like about Varonis is that they come from a data-centric place. Other products protect the infrastructure, but they do nothing to protect your most precious commodity — your data."
Deborah Haworth, Director of Information Security, Penguin Random House
“Varonis’ support is unprecedented, and their team continues to evolve and improve their products to align with the rapid pace of industry evolution.”
Al Faella, CTO, Prospect Capital