-
AI Security Threat ResearchAug 18, 2026
CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower
See how meta-hacking got Microsoft Copilot to snitch on itself, exposing CoSnitch, a one-click flaw that silently exfiltrates data.
Lior Adar
10 min read
-
Threat ResearchAug 12, 2026
WS-Trust Autologon Endpoint: Password Spray Without Smart Lockout Blocking
Learn how to mitigate risks tied to a legacy Entra ID endpoint that undermines Smart Lockout, allowing attackers to confirm valid passwords even on MFA-protected accounts.
Hai Vaknin
6 min read
-
AI Security Threat ResearchAug 07, 2026
RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data
With access to Jira, Confluence, Microsoft 365, Google Workspace, Slack, and more, RovoBlast shows how a single link turns AI permissions into a low-friction path for data exposure.
Dolev Taler
7 min read
-
AI Security Threat ResearchJul 29, 2026
When AI Assistant Share Links Become Public Exposure
Explore the risks of AI assistant share links and their potential to expose sensitive data.
Varonis Threat Labs
2 min read
-
AI Security Threat ResearchJul 22, 2026
Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI
Dolphin X, a new Windows stealer and remote access trojan, targets hundreds of applications from browsers to crypto wallets and includes an AI Profiler that helps attackers zero in on victims.
Daniel Kelley
3 min read
-
AI Security Threat ResearchJul 20, 2026
A Look Inside the Hugging Face Breach
Explore the HuggingFace security breach involving an autonomous AI attacker and learn essential strategies to protect your org from similar threats.
Varonis Threat Labs
6 min read
-
AI Security Threat ResearchJul 07, 2026
Rogue Agent: How a Single Code Block Could Hijack Your AI Conversations in Google’s DialogFlow
AI chatbots widen the attack surface. We took over one to steal data and gain toeholds for launching campaigns.
Daniel Reyhanian
6 min read
-
AI Security Threat ResearchJun 25, 2026
Breach At The Beach: The Ultimate Entra ID Training Experience
Discover how Varonis Threat Labs created Breach at the Beach, a unique Entra ID training experience. Enhance your cybersecurity skills through hands-on learning with this CTF.
Lexi Croisdale
4 min read
-
Threat ResearchJun 19, 2026
MyBait: Why We Lured Attackers To Encrypt Our Cloud MySQL
Varonis Threat Labs deployed MySQL honeypots across GCP, AWS, and Azure. Only GCP was compromised. Here’s what it means for cloud database security.
Gil Weizman
4 min read
-
AI Security Threat ResearchJun 15, 2026
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA codes, email messages, meeting details, and private organizational files — with a single click.
Dolev Taler
5 min read
-
AI Security Threat ResearchJun 09, 2026
Phishing for Lobsters: How We Tricked OpenClaw into Spilling Secrets
We built an AI agent and put it through four phishing simulations to reveal critical security gaps and offer solutions to protect your organization's data.
Itay Yashar
6 min read
-
Threat ResearchMay 20, 2026
GitHub Breach via Malicious VS Code Extension: What You Need to Know
GitHub's breach, caused by a malicious VS Code extension, exposed 3,800 internal repositories. Learn how to secure your environment.
Chen Levy Ben Aroy
3 min read
SECURITY STACK NEWSLETTER
Ready to see the #1 Data Security Platform in action?
Ready to see the #1 Data Security Platform in action?
“I was amazed by how quickly Varonis was able to classify data and uncover potential data exposures during the free assessment. It was truly eye-opening.”
Michael Smith, CISO, HKS
"What I like about Varonis is that they come from a data-centric place. Other products protect the infrastructure, but they do nothing to protect your most precious commodity — your data."
Deborah Haworth, Director of Information Security, Penguin Random House
“Varonis’ support is unprecedented, and their team continues to evolve and improve their products to align with the rapid pace of industry evolution.”
Al Faella, CTO, Prospect Capital