threat_intelligence1600 wordsRead on Arc Codex

Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news

Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user’s chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security.Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA.Segment Resources:- Find more research from Rubrik Zero Labs - Rubrik Zero Labs' Black Hat session - Demo of the ChatMate attack in action Topic Segment - AI Notetakers and Recorders AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss.Questions enterprises should be asking:- Are employees recording or transcribing meetings? - Does this policy change if non-employees (external parties) are present? - Is consent asked for/given? - Is the context of the conversation taken into consideration? - Is the geographic/legal/political context of the external party taken into account? - Have you done your due diligence on third parties hosting/storing these recordings and transcriptions? - Was your due diligence a SOC 2, or real, actual evidence-based due diligence? - Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company? News Segment Finally, in the enterprise security news,- we check the vibes - and the funding, and the acquisitions - seriously, don’t mess with the wifi on planes - 181,000 meetings were left wide open - the sandbox escapes are getting ridiculous - research on how reliable AI-generated patches are - research on what attackers do after they get a shell - research on how cybercriminals are using AI agents - research on how vulnerable datacenters are - and finally, what’s a “mouthpad”? - Stick around till the end of the news segment to find out! Joe Hladik is a cybersecurity leader with over two decades of experience in threat intelligence, threat emulation, incident response, and cyber resilience. As the Head of Zero Labs at Rubrik, he is dedicated to uncovering emerging cyber threats, analyzing attacker methodologies, and translating complex security challenges into actionable insights. His work focuses on strengthening organizational defenses against modern cyber risks, particularly in data security and cloud-based threat landscapes. - If you’ve invested in threat intel and still can’t tie it to real risk reduction, you’re not alone. A lot of programs are collecting intel, but not operationalizing it across detection, response, or the business.So what’s actually working?At the Threat Intelligence Virtual Cybersecurity Summit on August 26th, you’ll hear how mature teams are turning intel into action and making it measurable.Security Weekly listeners can register for free at https://securityweekly.com/threatintel using the promo code: CSS26-SW - InfoSec World brings cybersecurity professionals together across industries, from healthcare and financial services to government and the Fortune 500. Join the community in Orlando, October 12–14, for practical education, new perspectives, and cybersecurity research unveiled live. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026. Adrian Sanabria - FUNDING/M&A, courtesy of the Security, Funded newsletter #256 – Full Byte Black Hat VIBE CHECK Who wins the non-human identity land grab? - 67% - IAM incumbents bolting it on - 11% - Data security platforms buying it - 11% - Dedicated NHI-only startups - 11% - Frontier AI Labs - 0% - Cloud providers - 0% - Other (tell me) FUNDING - Horizon3.ai, a United States-based autonomous penetration testing and threat exposure management platform, raised a $250.0M Series E from NightDragon and New Enterprise Associates. - Unicorn Alert! - Zenity, an Israel-based AI agent governance platform, raised an $115.0M Series C from Norwest and an additional $10.0M Secondary Market. - Obsidian Security, a United States-based SaaS security posture management (SSPM) platform, raised an $85.0M Series D from Crescent Cove Advisors. - Unicorn Alert! - Oligo Security, an Israel-based runtime application security platform for open source libraries, raised a $60.0M Series C from Ballistic Ventures, Canon Capital, Eyal Waldman, Greenfield Partners, Lightspeed Venture Partners, Red Dot Capital Partners, and TLV Partners. - Information Security Media Group (ISMG), a United States-based cybersecurity news, marketing, and media group, raised an undisclosed Private Equity round from Peak Rock Capital. ACQUISITIONS - BioCatch, an Israel-based AI-driven behavioral biometrics for cybersecurity, was acquired by Visa for $2.4B. BioCatch had previously raised $323.6M in funding. - Lansweeper, a Belgium-based attack surface management (ASM) platform, was acquired by Bridgepoint for an undisclosed amount. Lansweeper had previously raised $149.8M in funding. - Permiso Security, a United States-based identity and access runtime visibility platform for the cloud, was acquired by Okta for an undisclosed amount. Permiso Security had previously raised $28.5M in funding. - Clarity, a United States-based trust and safety platform for defending against deepfake attacks, was acquired by Deel for an undisclosed amount. Clarity had previously raised $16.0M in funding. <-- not to be confused with ClarOTy, an OT security company! - Enkrypt AI, a United States-based secure web gateway for AI applications, was acquired by Anaconda for an undisclosed amount. Enkrypt AI had previously raised $2.4M in funding. - CYBERCRIME: WA man set up fake free wifi at Australian airports and on flights to steal people’s data, police allege Over 7 years for hacking Wi-Fi, but this guy was prolific - this is not a single incident like the DEF CON dunce coming home via a Delta flight inbound to Atlanta. - BREACHES: tl;dv (Too Lazy; Didn’t Validate): 181,874 Meetings Left Wide Open This is basically a supply chain incident. If you had a meeting with someone using tl;dv (e.g. a vendor's sales team), you might be recorded in the leaked files/videos. - BREACHES: The Hugging Face hack is a PR crisis that’s costing OpenAI millions Easily the most talked about incident at Black Hat and DEF CON. Black Hat gave the stage to two OpenAI engineers to go into more details about how their agent did crimes. The confession was recorded and published on YouTube. The biggest question still seems to be, "this can't be legal, right?" Especially as Anthropic, Meta, and others have confessed in quick succession after OpenAI's admission. Admitting to sandbox escapes instantly turned into a meme, which was fun. - RESEARCH: Why AI-generated vulnerability patches still require expert human review Hands down, the most interesting research I saw at Black Hat, BSLV & DEF CON. Friend and past host at Security Weekly, Keith Hoodlet now leads the research team at 1Password's new independent lab, Off-by-1. Their first research aims to determine how good AI is at creating patches for vulnerabilities. This research couldn't come soon enough, as the Cloud Security Alliance and many vendors are telling practitioners that letting AI code the patches is the only way to keep up with the massive influx of AI-discovered vulnerabilities. I published my own take on the research on my Substack. - RESEARCH: After the Shell: What Attackers Do After They Land a Shell at the Internet’s Edge This report goes along with a new product called "Tactics" from GreyNoise. A few months ago, GreyNoise made it possible for customers (even at the free tier) to deploy their own honeypot sensors for data collection. The idea is that you can put it near your network, or at the edge, to get more information about attacks targeting you. You can make the sensors look like all sorts of different devices, much like a Thinkst Canary, though this is for data collection and analysis, not attack detection. Tactics takes it a step further, turning the sensor into a high-interaction honeypot, giving you insight into what attackers are doing after they successfully hack something. The report details some of what they've found. Super useful for defensive strategy. - RESEARCH: Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks Someone at Unit42 got access to a cybercriminal's AI agent logs! - RESEARCH: BMC vulnerabilities (Lights Out) – runZero Research HD Moore's latest research deep dive. Cracking passwords, finding vulnerabilities, and scanning the Internet for vulnerable BMCs attached to datacenters. - RESEARCH: An Invisible Attack Surface: Thousands of Industrial Control Systems Exposed Near Data Centers HD wasn't the only one researching vulnerable data centers! My friend Stephen Hilt and his colleague Numaan Huq not only found vulnerable devices, but they used Business Insider's investigative journalism on the geo-location of datacenters to zero in on where the vulnerabilities are physically located. - RESEARCH: Largest AI Supply Chain Breach of 2026: LiteLLM Hack Impacts Thousands of Global Enterprises – Claim Your Ethical Disclosure The cascading breach that Trivy started continues! LiteLLM was compromised as a result of Trivy, and a LOT of organizations were apparently using LiteLLM. Now, a ~150GB archive of data and cloud credentials stolen from LiteLLM has been spotted. This is one of those situations where there's so much leaked data, it almost helps the victims, because it's impossible for attackers to target them all (maybe?) - SQUIRREL: MouthPad is now available A trackpad for your tongue!

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.