Rubrik Turns Backup Data Into AI Threat Intelligence
Backup Data Becomes a Security Signal
Alan Shimel speaks with Joe Hladik of Rubrik Zero Labs during Techstrong TV’s Black Hat 2026 coverage. Their conversation explores AI threat intelligence and the changing role of backup data in enterprise security. Hladik explains that Rubrik Zero Labs looks at anonymized telemetry and metadata to find patterns that can help defenders understand modern attacks.
Hladik brings more than two decades of experience across security intelligence, red team operations, incident response and architecture. That background shapes the way he views recovery and resilience. In his view, backup and recovery should not sit outside the incident response process. They need to be part of the same operational workflow.
Rubrik Zero Labs Uses AI With Human Tradecraft
The interview also looks at how Rubrik Zero Labs uses AI internally. Hladik says AI can help with logical analysis, malware reverse engineering and large-scale prioritization. The human team then adds the tradecraft. Researchers use experience to decide what is meaningful, what is benign and what deserves deeper review.
That balance matters because AI threat intelligence is not only about automation. It is about giving skilled researchers better ways to sort signal from noise. Rubrik Zero Labs uses that model to study threat actor tactics, tools and techniques across a wide set of security data.
Copilot Research Highlights New AI Risks
Hladik also discusses Rubrik Zero Labs research into Microsoft Copilot. The team examined how AI assistants process files, handle prompts and interact with back-end infrastructure. That research led to a sandbox escape finding that Rubrik responsibly disclosed to Microsoft before public discussion at Black Hat.
The specific issue was patched before the finding became public. Still, Hladik says the broader lesson remains important. AI assistants and agents create new paths for attackers. Security teams need to understand normal AI behavior before they can detect abnormal activity.
Context Matters More Than Basic Visibility
The discussion closes with a practical point for defenders. Many organizations already have logs from AI providers and platforms. The harder problem is context. Teams need baselines that show how AI systems normally behave, so they can spot malicious or unusual activity.
For technology leaders, the message is direct. Recovery, resilience, threat intelligence and AI security are becoming connected disciplines. Rubrik Zero Labs is positioning AI threat intelligence as a way to connect those areas and help enterprises respond faster when threats evolve.
Transcript
Hey everyone. We're back here at our Black Hat coverage, off of that crazy floor that's chaotic, up here in our little media room where we have an actual Black Hat background, and thank you for joining our continuing coverage. My next guest is Joe Hladik.
He's with Rubrik Labs. Is it Rubrik? Zero Labs.
Zero Labs, excuse me. Mm-hmm. And Joe, first of all, welcome to Techstrong TV.
It's great to have you on here. Yeah, thanks for having me. We rescued you from the chaos of the floor there and brought you up here.
I appreciate you coming up. Why don't we start with you a little bit? I mentioned you're director of the Zero Labs, but give people a sense of your credentials, if you will.
Okay. Your background. So I've been in and around the security intelligence community now for over 20 years.
I started my career as a software engineer, like a lot of people. Mm-hmm. And then I ventured my way into red team operations.
And that's how I sort of got my start into security many years ago. But back then, we did a lot of physical engagements. Right.
It's not like red teaming now, is a lot different than it was- It absolutely is ... back then. It was a lot more social engineering.
Yeah. That kind of thing. It was a lot of fun.
Yeah, it was. Yeah. There's a lot of good stories could come out of it.
I'm sure. It's probably not the forum, but we can talk. Yes.
But then I got a job at Mandiant, where I was- Mm-hmm ... an investigator doing incident response. I was there for many years.
I've worked with Sony as an architect. Really? Moving on from that, I was also a part of a couple of startups here and there, and then I eventually made my way to Rubrik about two years ago, where I've taken on the mantle as head of Rubrik Zero Labs.
And here I started as an individual contributor. And over the last two years, we've grown into a full team with multiple threat researchers globally, including not just the US, but India and Israel. Right.
And that's ultimately why we're here today with you, is we're presenting on a topic- Sure ... we'll get into later. So look, Rubrik's not a new company on the scene.
It's been around. I think a lot of people in our audience are familiar, but there may be a few people who are not familiar. So Joe, I realize it's kind of outside of your- Mm-hmm ...
sweet spot, but for people who don't know Rubrik, how would you explain it to them? In short, I would basically describe them as enterprise recoverability and resilience. And the reason why I also mention resilience is because you're starting to see a merging of a multi-domain aspect to response.
Recovery is now becoming a big part of that whole process. It's not just, "Oh, we've detected a threat. " Well, recovery, backup, all that type of stuff is always getting pushed to the side historically.
Because of the speed at which things are moving now, you need them all to be part of the same process- Yep ... and procedures. And Rubrik's platform and technology is designed for that.
It's designed to be part of that whole incident response methodology. I agree. Let me flip it a little bit.
Mm-hmm. There are a lot of people out here, they practice cyber. We've got people who are software developers and cloud native engineers, platform engineers.
They may not be familiar with the ins and outs of a security research lab. Mm-hmm. Because that's kind of a very specialized- Yes ...
piece of the broader cyber solution space. What's the charter of a lab like Zero Lab? Great question.
So when I was hired, I worked with Bipul, our CEO. Mm-hmm. And he basically gave me a strategic mandate of, like, "We have all this data.
" I personally saw a huge opportunity, because working in security operations for so long in my life, I never thought to look at backup data as another source for threat intelligence, see. Sure. So that's what drew me to this role, is like, I want to build something new.
Right. It's backup data. No one's ever looked at it that way.
Right. So that's really the mission that I've created, and the charter of my team is to basically turn the Rubrik telemetry and the data that we're backing up and everything. Obviously, everything's anonymized, and we mostly look at metadata.
But we have turned it just like NDRs and EDRs and our partners that we have in those spaces. We've effectively and proven that backup data is also a viable source of threat intelligence. I love it.
Now, we're going to talk specifically, you guys recently made an announcement about some research you did that uncovered some bugs, vulnerabilities, whatever you want to call them today. But before we zero in on that, let's take a 50,000 foot picture of, as you said, you've got all this backup data, and you're anonymizing it, and we look at the metadata. How valuable, how many bugs, how many vulnerabilities, what kind of juicy stuff have you been discovering in, was it about two years now?
Mm-hmm So, I will say this. We primarily focus on the tactics and techniques of threat actors. Mm-hmm.
Like the tools they use and things like that. So, I'll start there, where for the last two years, we've been building out a threat intelligence platform using AI, in the sense of, well, how do we properly use AI? We have an opportunity where we don't have all these legacy processes, procedures, technologies that a lot of these other companies have.
We have a green field. We can build whatever we want. So, we decided to take the approach of well, what is AI good at?
There's the science, and then there's the tradecraft. Sure. The art, I will say.
Right? So the AI is really good at figuring things out from a logical perspective. So a lot of the reverse engineering of malware and things like that, we hand off to AI.
We've built a platform that produces all those interesting findings for us, and then we use the team's expertise to actually pick out all the things that are interesting, and then they bring in the art of it, of the expertise, the experience of like, I know that's bad, even though it may look normal or benign to somebody else. We have the ability now to, one, prioritize these things, funnel up the interesting things amongst all the false positive and sort of garbage data. So that's one aspect.
The vulnerabilities which we're presenting here this week, that's another thing that we do. So we basically had the hypothesis of, okay, well, everybody's going to be using AI, especially the Copilots. Mm-hmm.
Whether it's just a simple ask a question, get an answer, or do some research for me, whatever the use case is. Well, Microsoft has a huge footprint. I believe it's like 20 million seats for Copilot users or something like that, which equates to- I think that's- ...
like 90% of the Fortune 500. I think that's conservative. Yeah.
That's the number I'm aware of. Probably. 20 million seats because Copilots- Probably more ...
now ship with every Office 365. Right. So it's way more, right?
So we looked at that. I would think. I don't know for sure.
Like you said. This is also going back like- Okay ... several months when we were originally looking at this.
So that's where it began. It's like well, the footprint is huge here. Mm-hmm.
We should maybe experiment with it and find out what we can do. And ultimately, Ory Lav, who's going to be presenting his findings tomorrow, he discovered how to basically break out of the sandbox and gain access to the back-end infrastructure. I love it.
Yeah. Now, when you say he discovered. Mm-hmm.
Yeah, because this is another thing. People have this image of some dude in a hoodie with the gloves with the fingers sticking out. Yeah.
You have training glove working. I do wear it on occasion. Well, we all do, right?
And he was hacking and he- Yeah ... discovered it, but that's not the true- No. How did this one go down?
Well, I think the best way to think about it is well, think about how everybody uses AI, right? You ask it a question, maybe you give it a file to analyze or several files to analyze. From our perspective, it's like, okay, these are all capabilities.
I can upload a file. It will read the file. Right.
Where does it take the data? How does it analyze the data? Where does it store the data?
Those are all sort of back-end mechanisms that occur, right? So with our line of thinking, and I can't directly speak for Ory, but we're in the same sort of club, so to speak, right? So all I can say is our line of thinking is more like, well, how can we break those features?
So if we insert, say, a line of code that might maybe break a guardrail that exists or skirt around guardrails, maybe gain access to answers that we shouldn't normally get access to. Well, maybe let's do it through a document rather than directly through a prompt. So that's kind of how it begins.
You just sort of experiment with all these different little things, tweaks. Oh, that didn't work. I'll try something else.
Maybe I'll try a different line. Maybe I'll fix my prompt. So it's not as simple as sitting down to the keyboard and just writing an exploit.
No. You have to really... It's a lot of time.
And it's a lot of testing, and that can be grueling over- No doubt ... and then finally, you get to that point where I did it. Yeah.
That type of moment. Now, I would be negligent if I didn't ask you, how's AI changing that? That's a big question.
So I think about AI at this point last year and now where we are today. Last year, we pretty much had generative AI. We all know what that is now.
Everybody uses it. And agentic AI was kind of this future thought of like, we know we're going there, but what is it really going to be capable of? Mm-hmm.
And now we're here. Instead of generative AI being advertised everywhere, all you see is agentic. Right.
Right? So the hard part, I think, especially from a security perspective, is knowing what's going to come next. And that's a scary thing because especially working in threat intelligence for so long, there's a certain level of predictability that has always existed.
Mm-hmm. Especially, I've worked a lot with nation state threat actors, working intimately, directly with my other former life, former employer In the teams I've worked in, just tracking the same actors for years on end, and how they changed. Yeah.
Right? Now, with these capabilities, anybody can do it. Yeah.
They have nation state capabilities- It's crazy ... with the hooded person in the basement. Yeah, no.
It's crazy, yeah. There could be that kid with the hoodie in the basement doing this with, especially the open sourced versions of OpenClawn and things like that. Open-weight stuff- Yeah ...
and these agents. No, look, if you're not scared, you're not paying attention, right? Right.
That's almost the piece of it. Let's go back now to the Microsoft disclosure or the Microsoft bug that you guys found, or vulnerability, let's call it. People don't like to use the word bug.
I thought open disclosure was a well-settled principle of security research. Maybe it's because we have all these amateurs- Yeah ... coming in with AI and all of this, that we're seeing what was well-settled procedure being not followed.
What do you think about that? So, I think there's-- Well, one, I just want to highlight the vulnerabilities we discovered, we followed the correct procedures. You're not an amateur, right?
Yeah, exactly. We did it the right way. We discovered in February.
We worked with Microsoft immediately, and I believe they patched and fixed it by mid-March. Okay, it's not bad at all. I don't have the exact dates.
No, but that's pretty fast, right? And then, yeah, it is. And we worked together to figure out, okay, well, what's the public disclosure going to look like?
And of course, we wanted to present our findings at Black Hat. But there's a process to get there. There is.
" There's probably 30 steps of things that happened to lead up to that point. So we did all of that. And obviously now, I also have to say this, too, the things that we found are no longer a threat.
So that's good news. Yeah. But that's part of the whole responsible disclosure- Yes ...
that by the time people are finding out about this- Mm-hmm ... it's been patched, it's been done. Yeah.
Right? And that's important. And I'd say the next part of this is Glasswing, I think is another, I'd say, large scale effort to try to-- It's an attempt to basically keep this process in place, right?
Absolutely. Because with something like Mythos or Fable, everybody has access to this. And by holding back the release of it to the public and having Glasswing as sort of getting ahead of it, you could get all the companies together to handle this responsibly and roll it out in an effective way.
And I think, look at today, Mythos or Fable is available to anybody now. Yeah. And the world isn't burning.
I don't want to say it won't tomorrow, but the fears that we all had, I think Glasswing was successful to say the least. I think Glasswing succeeded beyond- Yes ... expectations.
I think the government would be smart to adopt a similar thing, because I know- Yes ... they're looking at stuff right now. What scares me, though, Joe, is these open-weight models that have- Yeah ...
Mythos-like capabilities without the responsible disclosure guardrails built in. Without the Glasswing guardrails built in. What happens when the kid in the hoodie gets ahold of that, right?
Right. And that's the problem. Right.
It's a real problem. And I think this goes into what I normally will say in response to the findings that we have for this vulnerability, is that we really need a... You've probably heard visibility in the security context.
Sure. Like, I need visibility into the endpoints. I need visibility into the network.
I need visibility here and there and everywhere, right? Well, now visibility isn't necessarily the problem. We have visibility because they provide, Microsoft or any of these AI providers, provide the logs.
And so the availability is there, if you want to talk like the CIA triad type of thing. Yeah, sure. It's there.
It's a matter of context. Mm-hmm. How do I detect if something malicious has happened?
Yeah. This is beyond signature-based detection, where I can write a pattern- Absolutely ... of activity and find it.
This is more beha- It's not only behavioral, but you have to understand the behavior of the AI normally before you can figure out what's abnormal. Right. So- So the base patterns and all.
Yep. Look, it's a different complexity. I get it.
Joe, unfortunately, we've got to wrap up. Mm-hmm. But for people who want to stay abreast of what you're doing at Zero Lab, what's the best way to do that?
com. That's probably the best way. com?
com. com. Check it out.
You can probably see it in the bottom third on your screen here. Joe, I appreciate you taking time out of what's a crazy busy Black Hat. Yeah, of course.
Thank you for having me. And does one congratulate when you find a bug that's been closed? Or, but keep up the great work.
Maybe congratulate once it's fixed. Exactly. But keep up the good work, man.
The world needs you. Thank you very much. Thank you.
Appreciate it. Hey, we're going to take a break here at Techstrong TV. We'll be back in a minute.