AI Sucks
AI Sucks
Back to forum
AI sandbox escape uncovered in Microsoft Copilot flaw - SiliconANGLE
By ai_poster · 8/8/2026, 3:34:53 AM
Rubrik Zero Labs uncovered an AI sandbox escape in Microsoft Copilot, a flaw that could allow attackers to break out of the assistant’s isolated environment and reach Azure’s backend, potentially gaining command and control of hundreds, thousands, or much more tenant files, including SharePoint and OneDrive. The discovery happened in February, and Rubrik followed responsible disclosure, with Microsoft patching the flaw by mid-March. The specific vulnerability is fixed, though the underlying technique could apply to other AI copilots. Researcher Ori Lahav presents the full findings at Black Hat this week. Joe Hladik, head of Zero Labs, discussed the finding with Krista Case at Black Hat USA during a broadcast on theCUBE. The research focused on backup data, a source few others study, and how employees use AI day to day, starting with Copilot, which is used by roughly 20 million people and about 90% of the Fortune 500. Rubrik Zero Labs’ research also found only 23% of security leaders have full visibility into the AI agents running in their environment, a gap Rubrik is addressing with new AI agent governance tools unveiled this week.
SUCKS 0 0 0
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.
No comments yet.