-
Cloud Security Threat ResearchApr 15, 2025
Burning Data with Malicious Firewall Rules in Azure SQL Server
Exploiting a security gap in firewall rule-naming can suddenly delete entire servers and targeted assets when combined with admin actions.
Coby Abrams
4 min read
-
Cloud Security Threat ResearchApr 15, 2025
Avoid Getting Burned: Identifying and Correcting Common Misconfigurations in Azure Networking and Firewalls
Misconstruing the nuances of Azure Networking and Firewalls can result in security gaps and data exposure.
Coby Abrams
4 min read
-
Cloud Security Ransomware Threat ResearchApr 10, 2025
RansomHub – What You Need to Know About the Rapidly Emerging Threat
RansomHub, the notorious ransomware group, has affected over 200 victims in industries such as IT, healthcare, finance, and more.
Joseph Avanzato
4 min read
-
AI Security Threat ResearchApr 07, 2025
Xanthorox AI — The Next Generation of Malicious AI Threats Emerges
Xanthorox AI is a modular, self-hosted Black-Hat AI tool for cybercrime. Varonis counters it with real-time detection of AI-driven email threats.
Daniel Kelley
3 min read
-
Cloud Security Data Security Ransomware Threat ResearchMar 12, 2025
Mind Games: How Social Engineering Tactics Have Evolved
Instead of using advanced tools or complex scripts, skilled threat actors infiltrate systems and steal data using the most effective weapon of all — words.
Varonis Threat Labs
7 min read
-
Threat ResearchMar 05, 2025
Salt Typhoon: The Threat Group Behind Major Cyberattacks
Varonis Threat Labs profiles Salt Typhoon, an APT group that is responsible for a series of breaches targeting U.S. infrastructure and government agencies.
Joseph Avanzato
5 min read
-
Threat ResearchFeb 13, 2025
Astaroth: A New 2FA Phishing Kit Targeting Gmail, Yahoo, AOL, O365, and Third-Party Logins
Discover how Astaroth phishing kits bypass security, offer bulletproof hosting, and how Varonis protects businesses from advanced cyber threats.
Daniel Kelley
2 min read
-
Threat ResearchJan 29, 2025
Devil-Traff: A New Bulk SMS Platform Driving Phishing Campaigns
Discover how the Devil-Traff bulk SMS platform fuels phishing attacks with spoofing and automation.
Daniel Kelley
2 min read
-
Threat ResearchJan 06, 2025
Meet PhishWP — The New WordPress Plugin That’s Turning Legit Sites into Phishing Traps
Discover how PhishWP, a malicious WordPress plugin, turns trusted sites into phishing traps and how to protect yourself with Varonis.
Daniel Kelley
3 min read
-
Data Security Threat ResearchNov 26, 2024
Caught in the Net: Unmasking Advanced Phishing Tactics
Learn new, advanced phishing tactics being used by attackers and how your organization can combat them.
Tom Barnea
4 min read
-
Threat ResearchNov 14, 2024
Varonis Discovers New Vulnerability in PostgreSQL PL/Perl
Varonis discovered a vulnerability (CVE-2024-10979) in the Postgres trusted language extension PL/Perl that allows setting arbitrary environment variables in PostgreSQL session processes.
Varonis Threat Labs
2 min read
-
Threat ResearchNov 12, 2024
GoIssue — The Tool Behind Recent GitHub Phishing Attacks
Discover how GoIssue targets GitHub users, posing significant risks to developers and organizations.
Daniel Kelley
2 min read
SECURITY STACK NEWSLETTER
Ready to see the #1 Data Security Platform in action?
Ready to see the #1 Data Security Platform in action?
“I was amazed by how quickly Varonis was able to classify data and uncover potential data exposures during the free assessment. It was truly eye-opening.”
Michael Smith, CISO, HKS
"What I like about Varonis is that they come from a data-centric place. Other products protect the infrastructure, but they do nothing to protect your most precious commodity — your data."
Deborah Haworth, Director of Information Security, Penguin Random House
“Varonis’ support is unprecedented, and their team continues to evolve and improve their products to align with the rapid pace of industry evolution.”
Al Faella, CTO, Prospect Capital