-
AI Security Threat Research
Sep 10, 2025
AI-Generated Phishing: How One Email Triggered a Global NPM Supply Chain Crisis
A massive phishing-led NPM attack compromised popular packages with 2.67B weekly downloads, hijacking crypto wallets via stealthy AI-generated emails.
Varonis Threat Labs
5 min read
-
AI Security Threat Research
Sep 08, 2025
SpamGPT: The AI Tool Elevating Email Security Threats for Enterprises
SpamGPT is a new AI-powered email attack tool that is changing the way businesses address email security issues. Learn how this technology makes phishing attacks more effective and how to protect your company's email systems ahead of time.
Daniel Kelley
3 min read
-
Threat Research
Sep 04, 2025
Cyber Resilience Assessment: Identifying Detection Gaps and Strengthening Security
Validate your security tools with a real-world attack simulation that reveals detection gaps and boosts your cyber resilience.
Seth Priestner
2 min read
-
Threat Research
Aug 29, 2025
Hidden in Plain Sight: A Misconfigured Upload Path That Invited Trouble
A misconfigured upload path exposed a Linux web server to attack. Varonis Threat Labs reveals how it happened and how to prevent future breaches.
Siddharth Jain
5 min read
-
AI Security Threat Research
Aug 14, 2025
Understanding and Defending Against the Model Context Protocol DNS Rebind Attack
As organizations increasingly rely on MCP servers to bridge AI capabilities with business systems, understanding and defending against threats is critical.
Varonis Threat Labs
6 min read
-
Cloud Security Threat Research
Aug 11, 2025
Rusty Pearl: Remote Code Execution in Postgres Instances
Varonis uncovers an RCE vulnerability in PostgreSQL via PL/Perl and PL/Rust. Learn how AWS RDS responded and how to secure your Postgres environment.
Tal Peleg
6 min read
-
Data Security Microsoft 365 Threat Research
Aug 05, 2025
Varonis Incident Response: Stopping Microsoft 365 Direct Send Abuse
Learn how Varonis Threat Labs uncovered a critical Microsoft 365 Direct Send exploit, and how organizations leveraged Varonis Incident Response to protect themselves from attack.
Brian Walsh
2 min read
-
Cloud Security Threat Research
Jul 25, 2025
What Salesforce Organizations Need to Know About ShinyHunters and Vishing
Learn about the vishing and recent attacks from ShinyHunters' targeting Salesforce environments and how your org can stay protected from data breaches and extortion.
Varonis Threat Labs
6 min read
-
Microsoft 365 Threat Research
Jul 21, 2025
ToolShell: A SharePoint RCE chain actively exploited
ToolShell is a critical SharePoint RCE exploit chain. Learn how it works, who’s at risk, and how to protect your environment before it’s too late.
Varonis Threat Labs
4 min read
-
Cloud Security Threat Research
Jul 17, 2025
Copy-Paste Pitfalls: Revealing the AppLocker Bypass Risks in The Suggested Block-list Policy
A subtle versioning error in Microsoft’s AppLocker block list exposes a bypass risk — learn how to spot and fix this overlooked security gap.
Dolev Taler
2 min read
-
Microsoft 365 Ransomware Threat Research
Jul 16, 2025
Take it Easy: How Attackers use AI and No-Code Tools with M365 for "Native Phishing"
A real-world look at how attackers use OneNote, OneDrive, and AI/no-code tools like Flazio for phishing, and practical steps to defend your organization today.
Tom Barnea
3 min read
-
Cloud Security Threat Research
Jul 16, 2025
Behind the Making of Operation Frostbyte: The First Snowflake GOAT
Complete Operation Frostbyte, an interactive mission created by Varonis Threat Labs to test the cybersecurity community’s Snowflake data security knowledge.
Lexi Croisdale
4 min read
SECURITY STACK NEWSLETTER
Ready to see the #1 Data Security Platform in action?
Ready to see the #1 Data Security Platform in action?
“I was amazed by how quickly Varonis was able to classify data and uncover potential data exposures during the free assessment. It was truly eye-opening.”
Michael Smith, CISO, HKS
"What I like about Varonis is that they come from a data-centric place. Other products protect the infrastructure, but they do nothing to protect your most precious commodity — your data."
Deborah Haworth, Director of Information Security, Penguin Random House
“Varonis’ support is unprecedented, and their team continues to evolve and improve their products to align with the rapid pace of industry evolution.”
Al Faella, CTO, Prospect Capital