Why AI sandbox escapes are cybersecurity’s newest attack surface
Security researchers have spent the past year watching AI accelerate attacks that already exist. A harder question is whether AI can create attack techniques that didn’t exist before. An AI sandbox escape — where an attacker breaks out of the isolated environment meant to contain an AI assistant — is one of the clearest signs yet that it can.
Joe Hladik (pictured), head of Zero Labs, the threat research arm of Rubrik Inc., the data security firm, built his team’s research practice around backup data — a source few others study. This year that focus turned to how employees use AI day to day, starting with the Copilot assistant used by roughly 20 million people and about 90% of the Fortune 500.
“No one’s looking at backup data,” Hladik said. “We found it to be a viable place to find actual intelligence to act upon.”
Hladik spoke with Krista Case at Black Hat USA, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed the AI sandbox escape Rubrik Zero Labs found in Microsoft Copilot and what it means for defending AI agents. (* Disclosure below.)












