Research by Rubrik Zero Labs reveals a vulnerability in Microsoft 365 Copilot’s infrastructure, highlighting risks of remote prompt execution and the need for broader security measures beyond prompts and application controls.
Rubrik Zero Labs has used its latest research to highlight a risk that sits below the AI assistant itself: the infrastructure it relies on. According to Cyber Defense Magazine, the team tested Microsoft 365 Copilot’s isolation model and found a way beyond the code-execution sandbox, exposing a weakness it describes as Remote Prompt Execution, or RPE. The result matters because enterprise assistants are increasingly linked to sensitive systems and data, so a flaw in the underlying stack can have consequences far wider than a single chat session.
The work was first presented publicly at Black Hat 2026, where Rubrik Zero Labs said an attacker could move from a document-based prompt injection to control of a victim’s Copilot interaction. In its own account of the research, the company said the attack chain could create a bidirectional channel into the user’s session, allowing the assistant to be manipulated on the victim’s behalf. Yahoo’s coverage of the disclosure said the chain involved a path traversal flaw in Azure Kubernetes Service, identified as CVE-2026-32193, which Microsoft patched in its June 2026 security update.
Rubrik says it reported the issue responsibly and that Microsoft deployed a global infrastructure fix without requiring customer action. The company’s researchers have argued that this kind of finding shows why AI security cannot stop at prompt filtering or application-layer controls. Their broader point is that the trust boundary for enterprise AI now extends into cloud and container infrastructure, where an attacker may be able to turn an apparently contained assistant into a route towards connected resources.
The research also points to a wider problem for defenders: seeing AI activity is not the same as understanding whether it is harmful. Joe Hladik, head of Rubrik Zero Labs, has said his team uses backup telemetry to turn operational data into threat intelligence, but he warned that conventional security tools were not built to interpret AI behaviour with enough context. Rubrik’s position is that behavioural and anomaly-based detection will become more important as AI systems act with greater autonomy, because the same request may not always produce the same outcome.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





