Why AI sandbox escapes are cybersecurity’s newest attack surface
Security researchers have spent the past year watching AI accelerate attacks that already exist. A harder question is whether AI can create attack techniques that didn’t exist before. An AI sandbox escape — where an attacker breaks out of the isolated environment meant to contain an AI assistant — is one of the clearest signs […] The post Why AI sandbox escapes are cybersecurity’s newest attack…
In an innovative twist for cybersecurity, researchers have discovered a potential attack vector in AI-powered assistants. An AI sandbox escape – where an attacker breaches the isolated environment meant to contain an AI assistant – serves as a clear indicator that AI can indeed create unseen attack techniques. Joe Hladik, head of Zero Labs, a threat research arm of Rubrik Inc., has been studying backup data, a seldom-explored source.
This year, his focus shifted to how employees utilize AI daily, specifically Microsoft Copilot, used by roughly 20 million individuals and 90% of the Fortune 500. Hladik revealed that backup data emerged as a viable source for actionable intelligence. The discovery of an AI sandbox escape in Copilot was made in February, and Rubrik Zero Labs disclosed the vulnerability to Microsoft at the time, which was subsequently patched by mid-March.
Despite the fix, Hladik emphasized that the underlying technique could extend to other AI copilots. The vulnerability could potentially grant attackers command and control over a vast number of user files, such as those in Azure's backend. The research underscored that only 23% of security leaders have comprehensive visibility into the AI agents operating within their environments.
Rubrik Zero Labs is addressing this visibility gap with the introduction of new AI agent governance tools in line with their mission to enhance security measures around AI agents.
Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written; read the original for the full account.



