Rubrik Zero Labs’ cover photo
Rubrik Zero Labs

Rubrik Zero Labs

Technology, Information and Media

We deliver actionable, vendor-agnostic insights to reduce data security risks and advance cyber resilience.

About us

Rubrik Zero Labs delivers actionable, vendor-agnostic insights to reduce data security risks and to advance cyber resilience for global organizations.

Website
https://go.rbrk.co/whsd3o4s
Industry
Technology, Information and Media
Company size
5,001-10,000 employees
Specialties
Threat Research, Data Security, AI Security, Cyber Resilience, and Cybersecurity

Updates

  • Krista Case (Macomber) Case at THECUBE Research recently covered comments from head of Rubrik Zero Labs Joseph Hladik on where today's real cyber risk lives. It's not AI alone, but the combination of human tradecraft and new AI-enabled capbilities. The piece also cites Zero Labs researcher Ori Lahav's sandbox escape finding in a widely deployed enterprise AI assistant, responsibly disclosed and patched, as a case in point. Check out the full analysis linked in the comments.

    • No alternative text description for this image
  • Recent Expert Insights research explores a self-contained Windows batch file receiving zero detections from 61 antivirus engines on VirusTotal. Instead of downloading its payload, the loader embedded and encrypted it inside its own source, then leaned on legitimate Microsoft tooling to launch it, leaving scanners with almost nothing to flag. Varadharajan Krishnasamy's original Rubrik Zero Labs analysis shows why that evasiveness isn't limited to one loader. Both samples share configuration fingerprints, including the /api/health beacon path and a scheduled task named UpdateTask, confirming AZALEA's operators run it as malware-as-a-service unbound to any single delivery method. For defenders, this means clean, static-scan verdicts means little once evasion is engineered this deep into the malware itself. Behavior and downstream activity are more durable signals. Full RZL research linked in the comments.

  • Relevant, high-impact research from Rubrik Zero Labs is emerging at an impressive clip. We are proud to announce that Kirtar Oza, CISSP GCFA will be onstage at Black Hat India 2026 to present a new study. Kirtar's research exposes a class of attack most defenders haven't yet encountered, which entails the silent poisoning of an AI agent's episodic memory, demonstrated live against a production Mem0-backed security advisor. He will also introduce EIDOLON-M, the first forensic framework built to investigate this attack class, which he's releasing open source at the conference. Register to join us through the link below.

    View organization page for Black Hat India

    2,950 followers

    Black Hat India Briefing Reveal: Do NOT Isolate: Forensic Investigation of AI Agent Episodic Memory Corruption Black Hat India Briefings Registration Link: https://lnkd.in/dr8gQheC Presented by Kirtar Oza, CISSP GCFA, this Briefing exposes how AI agents' episodic memory, stored in vector databases with no write audit trail, can be silently poisoned by attackers in under 30 seconds. The session demonstrates a live attack against a production Mem0-backed AI security advisor, where 15 false memories corrupt its institutional knowledge until it wrongly clears an active C2 connection as harmless, with no trace visible on direct database inspection. It then presents EIDOLON-M, the first forensic framework built to investigate this class of attack, using a six-layer detector stack to reconstruct the timeline and prove memory corruption caused the bad advice. EIDOLON-M will be released open source at Black Hat India. Kirtar Oza, CISSP GCFA is a cyber defence researcher and security engineering leader with over 20 years of experience in threat hunting, DFIR, and detection engineering. He currently serves as a Staff Security Researcher at Rubrik Zero Labs, focused on Agentic AI Security and emerging attack techniques targeting autonomous AI systems. Previously at Microsoft, he played a key role in establishing the company's Managed Detection & Response (MDR) service. Black Hat India 2026 | Briefings | October 29–30 | Bengaluru #BlackHatIndia #BHIndia #InfoSec #BlackHat2026

    • No alternative text description for this image
  • Head of Rubrik Zero Labs Joseph Hladik recently joined Enterprise Security Weekly from SC Media to unpack "Remote Prompt Execution," a novel vulnerability class enabling full session takeovers of Microsoft Copilot through sandbox escapes. The conversation traces the technical path behind eight critical CVEs, what sandbox escapes in AI assistants mean more broadly for enterprise security teams, and the patch to earning a $48,000 bug bounty. Full episode linked in the comments.

    • No alternative text description for this image
  • Identity and administrative credentials now represent the primary attack surface in supply chain attacks, involved in approximately 39% of the incidents analyzed in a new Rubrik Zero Labs report. This new research examined more than 400 software supply chain incidents between January and July 2026, corroborated by backup telemetry across Rubrik customer environments. Findings confirm that threat actors are focusing their efforts on sprawling supply chain attacks, and identity and administrative credentials represent the primary attack surface—involved in approximately 39% of software supply chain incidents. Credential and secret theft appeared in 52.5% of incidents with a confirmed attack behavior, outpacing every other objective, including backdoor deployment, self-propagating worm activity, and ransomware. AI agent marketplaces like Hugging Face and ClawHub are also emerging as a critical component of these attacks, likely due to relatively immature security controls. Our study notes more than 575 compromised "skills" deployed across these platforms. Overall, findings point to the modern software supply chain threat functioning as a vehicle for credential compromise. Full research linked in the comments.

    • No alternative text description for this image
  • AI assistants introduce attack surface that most security teams haven't yet learned to baseline. Head of Rubrik Zero Labs Joseph Hladik spoke with Alan Shimel of Techstrong TV at Black Hat 2026 about how a sandbox escape discovered by Rubrik Zero Labs researchers could have allowed an attacker to break out of Microsoft Copilot into the tool's underlying infrastructure. Hladik also describes how Zero Labs pairs AI-driven analysis and reverse engineering with human tradecraft to separate signal from noise, and argues recovery and incident response should operate as one workflow, not two. Watch the full conversation through the link in the comments.

    • No alternative text description for this image
  • We were honored to host a luncheon at Black Hat last week that allowed attendees to dive deeper into research findings by Ori Lahav. The multi-stage sandbox escape from Microsoft Copilot he demonstrated led to the company issuing a CVE and pushing a fix, protecting the more than 30 million users of that product from potential stealthy takeover by hostile actors. You can find a link to a full write up of the research, including demos, in the comments below. Rubrik Kyle Fiehler Joseph Hladik Amit Malik Kirtar Oza, CISSP GCFA Sushant Paithane Varadharajan Krishnasamy

    • No alternative text description for this image
  • AI assistants are built on code interpreters that present an immense attack surface. Rubrik Zero Labs researchers discovered an exploit chain using a booby-trapped Word document to escalate privileges, escape an AI assistant's sandbox, and open a bidirectional channel letting an attacker prompt the victim's live session using the victim's own credentials without generating malware alerts. The research will presented in full this week at Black Hat USA 2026. Full research linked in the comments.

  • Rubrik Zero Labs is hosting a roundtable luncheon at Black Hat USA 2026 where we will be exploring "Remote Prompt Execution," a new class of AI-based threats characterize by sandbox escape and exploit chaining to gain the ability to run arbitrary code on a victim's machine. Key components of these findings are being shared for the first time at Black Hat, and a primary researcher will be on-hand to discuss the findings. If you'll be in town for the conference, you can signal your interest in joining us here: https://lnkd.in/gc3Ywk9C

    • No alternative text description for this image
  • Rubrik Zero Labs identified BeepRAT — a previously undocumented .NET remote access trojan — delivered through HFY 号码魔方, a Chinese telephone number management utility containing over 517,000 records of mobile number prefix data. The infection chain is technically sophisticated and Varadharajan Krishnasamy explores each step in full. Rubrik Zero Labs assesses with medium confidence that BeepRAT operates within a broader China-nexus ecosystem. The research includes YARA detection rules, network and file IOCs, and full MITRE ATT&CK mapping. Full technical analysis: https://lnkd.in/gKMqpKkg

Affiliated pages

Similar pages