CyberDefenseMagazine

Innovator Spotlight: Rubrik Zero Labs


What Happens When AI Escapes?

AI assistants are gaining unprecedented access to the inner workings of businesses, but that trust comes with one critical expectation. Their reach stays contained.

Rubrik Zero Labs decided to put that assumption to the test. What they discovered took them beneath Microsoft Copilot and into the infrastructure supporting it.

There, researchers uncovered vulnerabilities and identified a new class of AI threat known as Remote Prompt Execution (RPE).

At Black Hat 2026, Rubrik Zero Labs revealed how its researchers broke out of Copilot’s code-execution sandbox, showing just how far an AI security weakness could reach.

Backup With a Bigger Purpose

Rubrik’s threat intelligence research arm has an unusual source of insight, backup data.

Joe Hladik, Head of Rubrik Zero Labs, explained that his team turns backup telemetry into actionable intelligence to uncover malicious activity.

As AI tools like Copilot expanded across enterprise environments, the team turned its attention to the weaknesses that might be hiding underneath them.

Breaking Out

Copilot executes code inside an isolated environment known as a sandbox, designed to prevent activity from reaching the underlying infrastructure.

Rubrik Zero Labs decided to test those walls.

The team uncovered an infrastructure vulnerability in Azure Kubernetes Service that allowed them to escape the sandbox and reach the backend environment. Their research demonstrated Remote Prompt Execution, potentially allowing an attacker to interact with a victim’s Copilot session and access its connected resources.

ChatMate: A malicious document bootstraps a bidirectional channel from the attacker all the way into the victim’s Copilot. Source: Rubrik Zero Labs.

Rubrik Zero Labs responsibly disclosed the vulnerability to Microsoft, which proactively deployed an infrastructure-level fix globally without requiring customers to take action.

That is where the stakes get bigger. Enterprise AI does not operate in isolation. As assistants become connected to sensitive business systems and data, a weakness underneath the AI could give attackers an opening far beyond the chatbot itself.

Seeing Is Not Understanding

Finding the vulnerability also revealed another blind spot. Security tools may see what AI is doing without understanding when that behavior turns malicious.

Hladik described it as the difference between visibility and observability.

Visibility means having the data. Observability means having enough context to understand what is actually happening. Traditional security tools were not designed to interpret AI activity with that kind of context.

That challenge grows when models don’t always behave the same way. The same action may not always produce the same result, making traditional signatures harder to rely on. Hladik believes behavioral and anomaly detection may help defenders spot unusual AI activity.

Speed Needs Guardrails

For Hladik, the bigger concern is that AI innovation may be moving faster than its security guardrails. RPE reinforces the need to protect not only AI tools, but the infrastructure underneath them.

His goal for Rubrik Zero Labs is to help organizations navigate AI “without sacrificing security for speed.”

Outside the Sandbox

As AI gains more autonomy, defenders need to recognize when it crosses the line from helpful to harmful.

Rubrik Zero Labs broke out of the sandbox to help make sure attackers stay locked inside.

Stay Connected

Follow Rubrik Zero Labs on LinkedIn and @RubrikZeroLabs on X for their latest research.

Read the full Rubrik Zero Labs research: Breaking M365 Copilot Sandbox – ChatMate

#AIGovernance #CyberResilience #AgenticResilience

About the Author

Angie Apolinar is a Lead Reporter at Cyber Defense Magazine and a Women in Cybersecurity award recipient. She is a graduate student in Cybersecurity and Information Assurance at Western Governors University with a degree in Psychology from California State University, Fullerton. Angie serves as a Cyber Mentor, helping prepare the next generation of cybersecurity professionals. She has also worked on multiple NASA research and workforce development programs, including L’SPACE, where she contributed to mission concepts, systems engineering, software design, and AI-driven aerospace research.

Reach her online at [email protected].



Source link