-
Data Security Speed Data
Oct 02, 2024
Speed Data: The Dangers of Data Poisoning With Avi Yoshi
Welcome to Speed Data: Quick Conversations With Cybersecurity Leaders. Like speed dating, our goal is to capture the hearts of CISOs with intriguing, unique insight in a rapid format for security professionals pressed for time.
Megan Garza
2 min read
-
Cloud Security
Sep 30, 2024
Breaks in the Cloud: Protecting Against Top LLM Risks
Modern technology relies heavily on the cloud, and as companies migrate to SaaS, they increasingly use advanced features and tools like generative AI.
Megan Garza
3 min read
-
Threat Research
Sep 26, 2024
New CVEs in OpenPrinting CUPS Software
A series of vulnerabilities in CUPS were recently disclosed by Simone Margaritelli, who is known as “evilsocket” on X (Twitter). OpenPrinting CUPS (Common UNIX Printing System) is an open-source printing software that is often included by default in various Linux distributions.
Varonis Threat Labs
3 min read
-
Varonis Products
Sep 25, 2024
What's New in Varonis: September 2024
This month, Varonis released new updates to help organizations remediate permissions risks, streamline security operations, and improve security posture.
Nathan Coppinger
1 min read
-
Data Security
Sep 20, 2024
The Attacker’s Playbook: Security Tactics from the Front Lines
While security pros are already familiar with terms like data breaches, exploits, and misconfigurations, these phrases are also becoming known to organizations and non-tech leaders as cybersecurity becomes an essential part of business operations.
Lexi Croisdale
2 min read
-
Data Security Speed Data
Sep 19, 2024
Speed Data: The Basics of Cybersecurity With Mark Wigham
Welcome to Speed Data: Quick Conversations With Cybersecurity Leaders. Like speed dating, our goal is to capture the hearts of CISOs with intriguing, unique insight in a rapid format for security professionals pressed for time.
Megan Garza
2 min read
-
Salesforce Varonis Products
Sep 17, 2024
Varonis Enhances Salesforce Security With High-Risk Permissions Remediation
Today, we’re excited to announce new Salesforce remediation features that help organizations proactively find and revoke high-risk user permissions.
Nathan Coppinger
1 min read
-
Threat Research
Sep 16, 2024
Data Theft in Salesforce: Manipulating Public Links
Varonis Threat Labs uncovered a vulnerability in Salesforce's public link feature that threat actors could exploit to retrieve sensitive data. By manipulating the API calls sent to the undocumented Salesforce Aura API — combined with SOQL subqueries — hackers could commit a blind SOQL injection attack to retrieve customer information, including PII. Varonis Threat Labs informed Salesforce of the vulnerability January 4, 2024. In February 2024, Salesforce patched the vulnerability for blind SOQL injection. Given the severity and the potential of this exploit to expose and leak sensitive information, Varonis researchers intentionally waited to release their findings. The vulnerability we identified applied to virtually any public link generated by Salesforce, making the potential impact widely detrimental. Because of the ubiquitous nature of public sharing links, most — if not all — Salesforce environments would likely have been vulnerable to some level of exposure, which could lead to data theft or leakage. Varonis recommends that organizations revisit the Salesforce Permission Sets granted to users to limit the creation of public links, remediate them where feasible, and monitor access activity. In this blog, we’ll explain how Salesforce public links work, how we discovered this vulnerability, and how attackers could exploit it to retrieve sensitive data.
Nitay Bachrach
6 min read
-
Data Security Speed Data
Sep 12, 2024
Speed Data: Military Information Security With Mike Taylor
Welcome to Speed Data: Quick Conversations With Cybersecurity Leaders. Like speed dating, our goal is to capture the hearts of CISOs with intriguing, unique insight in a rapid format for security professionals pressed for time.
Megan Garza
3 min read
-
AI Security Salesforce Speed Data
Sep 09, 2024
Speed Data: Unpacking Gen AI With Yohan Kim
Welcome to Speed Data: Quick Conversations With Cybersecurity Leaders. Like speed dating, our goal is to capture the hearts of CISOs with intriguing, unique insight in a rapid format for security professionals pressed for time.
Megan Garza
3 min read
-
DSPM Data Security
Sep 06, 2024
Data Security in the Cloud: Key Use Cases for DSPM
All industries rely on data, and this data is increasingly stored in dynamic cloud environments. For organizations handling sensitive data in the cloud, data security posture management (DSPM) is essential for ensuring security and compliance.
Nolan Necoechea
3 min read
-
Varonis Products
Sep 05, 2024
Protecting Salesforce: Remediating Misconfigured Sites
Organizations worldwide use Salesforce Sites to provide information and services to partners and customers. However, when configuring these sites, something as simple as a missed checkbox can expose sensitive and regulated data to unauthenticated, anonymous guest users — effectively exposing the information publicly.
Nathan Coppinger
1 min read
SECURITY STACK NEWSLETTER
Ready to see the #1 Data Security Platform in action?
Ready to see the #1 Data Security Platform in action?
“I was amazed by how quickly Varonis was able to classify data and uncover potential data exposures during the free assessment. It was truly eye-opening.”
Michael Smith, CISO, HKS
"What I like about Varonis is that they come from a data-centric place. Other products protect the infrastructure, but they do nothing to protect your most precious commodity — your data."
Deborah Haworth, CISO, Penguin Random House
“Varonis’ support is unprecedented, and their team continues to evolve and improve their products to align with the rapid pace of industry evolution.”
Al Faella, CTO, Prospect Capital