Their mission is to find, fix, and alert the world to cyber threats before damage is done.
Featured stories
June 15, 2026
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration WeaponReal threats require real guidance
Varonis Threat Labs (VTL) is our team of threat hunters and security researchers who uncover how real‑world attackers target data across every industry and environment. Their discoveries give CISOs and security practitioners clear, practical guidance to reduce blast radius, secure sensitive data, and stop emerging threats before they cause damage.
Explore this page to see the VTL team’s latest discoveries, best practices, and more.
Novel discoveries
-
June 15, 2026
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA codes, email messages, meeting details, and private organizational files — with a single click.
Dolev Taler
-
June 09, 2026
Phishing for Lobsters: How We Tricked OpenClaw into Spilling Secrets
We built an AI agent and put it through four phishing simulations to reveal critical security gaps and offer solutions to protect your organization's data.
Itay Yashar
-
April 29, 2026
Meet Bluekit: The AI-Powered All-in-One Phishing Kit
Discover Bluekit, the AI-driven phishing kit that centralizes phishing operations with advanced features like automated domain registration and an AI Assistant.
Daniel Kelley
-
February 12, 2026
Dataflow Rider: How Attackers can Abuse Shadow Resources in Google Cloud Dataflow
Discover how attackers can hijack Google Cloud Dataflow pipelines by manipulating shadow resources and learn how to secure your environment against it.
Tamir Yehuda
-
January 27, 2026
Exfil Out&Look for Logs: Weaponizing Outlook Add-ins for Zero-Trace Email Exfiltration
Varonis Threat Labs reveals how Outlook add-ins in Microsoft 365 can be exploited to exfiltrate sensitive email data without leaving forensic traces.
Hadas Shalev
-
January 14, 2026
Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data
Varonis Threat Labs discovered a way to bypass Copilot’s safety controls, steal users’ darkest secrets, and evade detection.
Dolev Taler
In the News
Researchers Reveal How a Single Copilot Link Could Quietly Expose Personal Data
BleepingComputer.comDirect Send Phishing Campaign Revealed
Cybercrime RadioEnterprise Breaches. Common Failings & Lessons Learned
N2K CyberWireLessons Learned From Real-World Forensic Investigations
LinkedInAI Is Repeating the Same Security Mistake We Made Before
The VTL Team
Dor Yardeni is the Director of Security Research at Varonis, leading the team responsible for the detection engine that protects thousands of customers worldwide. With more than a decade of experience in cybersecurity, Dor specializes in red teaming, incident response, and detection engineering. His work focuses on data‑driven research, including building advanced threat detection models, reporting vulnerabilities in critical infrastructure systems, and investigating large‑scale ransomware incidents.
Rotem Tsadok leads Security Operations and Forensics at Varonis, directing investigations into advanced threats targeting sensitive data across hybrid environments. With deep blue and red-team expertise, he blends adversary emulation and incident response strategy with hands-on execution to guide complex technical and customer-facing teams. He has driven enterprise-scale initiatives that strengthen security posture and accelerate business impact. A dynamic speaker with 15+ years in the field, Rotem delivers practitioner-focused sessions packed with real-world tactics and lessons learned.
Yogev Madar is a Director of Security Research at Varonis, leading teams that drive advanced threat and product‑focused security research across cloud, data, and identity domains. He leads cross‑functional initiatives with engineering groups and directs research efforts to uncover novel vulnerabilities and attack techniques in major cloud platforms, translating real‑world attacker behavior and customer risk into actionable product outcomes. With a background in offensive security research, Yogev brings an attacker’s mindset to defensive strategy, while focusing today on research leadership, mentorship, and building scalable security capabilities that directly support Varonis’ product innovation.
Chen Levy Ben Aroy is a distinguished cybersecurity leader with a proven track record in cloud security, penetration testing, and red teaming. As a Cloud Security Research Team Lead at Varonis, Chen spearheads cutting-edge security research and innovation across multiple cloud-providers and platforms. His previous roles at well-known enterprises, such as Prosche Digital and ABInbev, showcased his expertise in advanced malware development and strategic project management. With a robust background in a wide array of cybersecurity domains, Chen's visionary approach and technical acumen make him a sought-after expert in the industry.
Joe is a passionate and dedicated blue-teamer with experience in a wide array of specialties such as Detection Engineering, Threat Hunting, Incident Response, and Cyber Intelligence. He currently leads Varonis’ Forensics group, a team primarily assisting customers with their response to critical breach events, for North Amera, Europe, and Australia. His interests and experience include reverse engineering, detection engineering, threat hunting, compromise assessment, threat deception and tool development for both red and blue team functionalities.
Mark Vaitzman is a Security Research Team Leader at Varonis, a leader in data security. As a passionate cybersecurity expert, Mark holds extensive experience in leading security threat and research teams in various cybersecurity companies, analyzing emerging threats, incident response and developing innovative solutions. He is also a lecturer at Cyber Security College, sharing his knowledge and shaping the next generation of cybersecurity professionals. Mark previously presented at CrestCon, DeepSec, and Black Hat USA. In his free time, he likes sailing in the sea and riding a motorcycle.
Tal Peleg, also known as TLP, is a senior security researcher and cloud security team lead at Varonis. He is a full-stack hacker with experience in malware analysis, Windows domains, SaaS applications, and cloud infrastructure. His research is currently focused on cloud applications, APIs, and agentic applications.
Lior is a Senior Security Researcher at the forefront of cloud and SaaS security, with a background rooted in red teaming, penetration testing, and incident response with a background in advanced research at Palo Alto Networks and Team8 his current work dives into the practical security challenges of the Cloud, SaaS, and AI. As a contributor to the LOLBAS project, Lior is a firm believer in the "attacker’s perspective," focusing on how built-in tools can be subverted to bypass modern defenses. He is an active member of the offensive security community and most recently led technical workshops at DEF CON 33.
Protect against material data breaches
Power Your 24×7 Data Defense