-
Cloud Security Threat ResearchAug 11, 2025
Rusty Pearl: Remote Code Execution in Postgres Instances
Varonis uncovers an RCE vulnerability in PostgreSQL via PL/Perl and PL/Rust. Learn how AWS RDS responded and how to secure your Postgres environment.
Tal Peleg
6 min read
-
Data Security Microsoft 365 Threat ResearchAug 05, 2025
Varonis Incident Response: Stopping Microsoft 365 Direct Send Abuse
Learn how Varonis Threat Labs uncovered a critical Microsoft 365 Direct Send exploit, and how organizations leveraged Varonis Incident Response to protect themselves from attack.
Brian Walsh
2 min read
-
Cloud Security Threat ResearchJul 25, 2025
What Salesforce Organizations Need to Know About ShinyHunters and Vishing
Learn about the vishing and recent attacks from ShinyHunters' targeting Salesforce environments and how your org can stay protected from data breaches and extortion.
Varonis Threat Labs
6 min read
-
Microsoft 365 Threat ResearchJul 21, 2025
ToolShell: A SharePoint RCE chain actively exploited
ToolShell is a critical SharePoint RCE exploit chain. Learn how it works, who’s at risk, and how to protect your environment before it’s too late.
Varonis Threat Labs
4 min read
-
Cloud Security Threat ResearchJul 17, 2025
Copy-Paste Pitfalls: Revealing the AppLocker Bypass Risks in The Suggested Block-list Policy
A subtle versioning error in Microsoft’s AppLocker block list exposes a bypass risk — learn how to spot and fix this overlooked security gap.
Dolev Taler
2 min read
-
Microsoft 365 Ransomware Threat ResearchJul 16, 2025
Take it Easy: How Attackers use AI and No-Code Tools with M365 for "Native Phishing"
A real-world look at how attackers use OneNote, OneDrive, and AI/no-code tools like Flazio for phishing, and practical steps to defend your organization today.
Tom Barnea
3 min read
-
Cloud Security Threat ResearchJul 16, 2025
Behind the Making of Operation Frostbyte: The First Snowflake GOAT
Complete Operation Frostbyte, an interactive mission created by Varonis Threat Labs to test the cybersecurity community’s Snowflake data security knowledge.
Lexi Croisdale
4 min read
-
Cloud Security Threat ResearchJul 09, 2025
Count(er) Strike – Data Inference Vulnerability in ServiceNow
Varonis Threat Labs discovered a high severity vulnerability in ServiceNow’s platform that can lead to significant data exposure and exfiltration.
Neta Armon
10 min read
-
Threat ResearchJun 26, 2025
Ongoing Campaign Abuses Microsoft 365’s Direct Send to Deliver Phishing Emails
Varonis Threat Labs uncovered a phishing campaign with M365's Direct Send feature that spoofs internal users without ever needing to compromise an account.
Tom Barnea
5 min read
-
Cloud Security Threat ResearchJun 19, 2025
Why Kerberoasting Still Matters for Security Teams
Sometimes the old ones are best... avoided. Explore Kerberoasting and how it remains a relevant attack method.
Simon Biggs
3 min read
-
Threat ResearchJun 18, 2025
The Jitter-Trap: How Randomness Betrays the Evasive
Discover how Varonis researchers detect stealthy beacon traffic by analyzing jitter patterns, turning evasion tactics into powerful behavioral detection signals.
Masha Garmiza
6 min read
-
Data Security Threat ResearchJun 05, 2025
Decoding ‘ClickFix’: Lessons from the Latest Browser-Based Phish
ClickFix tricks users into running malware via fake CAPTCHAs. Learn how this phishing tactic works — and how Varonis stops it cold.
Daniel Kelley
5 min read
SECURITY STACK NEWSLETTER
Ready to see the #1 Data Security Platform in action?
Ready to see the #1 Data Security Platform in action?
“I was amazed by how quickly Varonis was able to classify data and uncover potential data exposures during the free assessment. It was truly eye-opening.”
Michael Smith, CISO, HKS
"What I like about Varonis is that they come from a data-centric place. Other products protect the infrastructure, but they do nothing to protect your most precious commodity — your data."
Deborah Haworth, Director of Information Security, Penguin Random House
“Varonis’ support is unprecedented, and their team continues to evolve and improve their products to align with the rapid pace of industry evolution.”
Al Faella, CTO, Prospect Capital