This discussion examines adversarial artificial intelligence, referred to as AI, and related research presented at Black Hat 2026 and its security implications for enterprise deployments. Joe Hladik of Rubrik, head of Zero Labs, introduces Rubrik Zero Labs' focus on backup-data intelligence and vulnerability research. Hladik explains how their team discovers a sandbox-escape vulnerability that affects Microsoft Copilot and similar AI orchestration platforms. Krista Case of theCUBE Research, principal analyst and practice lead for cyber resilience and security, guides the conversation on emerging adversarial AI techniques, agentic AI trends and implications for enterprise AI deployments.
Key takeaways include that the specific Copilot vulnerability is patched according to Hladik yet the exploit model—sandbox escaping—remains a class of concern across copilots and orchestration tools. Hladik emphasizes the human-plus-AI tradecraft risk and urges defenders to improve observability for AI logs, establish behavioral baselines, prioritize fixes based on layered protections and maintain a software bill of materials, referred to as SBOM, to inform risk-based remediation.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for Black Hat USA 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Black Hat USA 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to Black Hat USA 2026
Please sign in with LinkedIn to continue to Black Hat USA 2026. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Joe Hladik, Rubrik
This discussion examines adversarial artificial intelligence, referred to as AI, and related research presented at Black Hat 2026 and its security implications for enterprise deployments. Joe Hladik of Rubrik, head of Zero Labs, introduces Rubrik Zero Labs' focus on backup-data intelligence and vulnerability research. Hladik explains how their team discovers a sandbox-escape vulnerability that affects Microsoft Copilot and similar AI orchestration platforms. Krista Case of theCUBE Research, principal analyst and practice lead for cyber resilience and security, guides the conversation on emerging adversarial AI techniques, agentic AI trends and implications for enterprise AI deployments.
Key takeaways include that the specific Copilot vulnerability is patched according to Hladik yet the exploit model—sandbox escaping—remains a class of concern across copilots and orchestration tools. Hladik emphasizes the human-plus-AI tradecraft risk and urges defenders to improve observability for AI logs, establish behavioral baselines, prioritize fixes based on layered protections and maintain a software bill of materials, referred to as SBOM, to inform risk-based remediation.
>> Welcome back to theCUBE. We're here at Black Hat 2026 at Mandalay Bay. I'm Krista Case, and we're talking a lot about adversarial use of AI here at the show this week. And one interesting thing that we're seeing is that there's a potential for AI to introduce actually previously unknown attack techniques. Rubrik Zero Labs actually did some research that uncovered one of these attack techniques using Microsoft Copilot in Azure. So here to discuss that is Joe Hladik, who's head of Rubrik Zero Labs. Joe, thanks so much for joining us today.
Joe Hladik
>> Thanks for having me.
Krista Case
>> Yeah, really appreciate it. So before we dig into the research, Joe, I wanted to talk with you a little bit about Rubrik Zero Labs. your team is in a really interesting position because they look at these emerging attack techniques. So can you comment on what you're seeing, especially these last maybe 4 to 6 months or so as we've seen this adversarial use of AI pick up?
Joe Hladik
>> Sure. Well, I'd like to begin with Rubrik Zero Labs, we have a unique perspective in the sense that with the charter of my organization and the type of research we do, our main point of research is around backup data. And the mission was really to turn, just like you have EDR and NDR type of solutions out there that look at endpoint or host data and network data, no one's looking at backup data. So that one, that's our main source of intelligence is we found it to be a viable place to find actual intelligence to act upon. So that's one thing and that's pretty much our primary driver for a lot of the research we do. On the other hand, we do a lot of research that other labs do as well, which is vulnerability research and things like that. We had an internal discussion around basically prioritization. There's just so much happening with AI. What are the— we know how we're using AI and we wanna better understand, one, how are our adversaries using AI and their methodologies and workflows and things. So we discovered— we decided to look at, well, what are the end users doing? What are they often using? Copilot. I think the number I had, and it's probably much higher now than it was at the time we decided to do this project, it was around 20 million seats and about 90% of the Fortune 500. So it's a large footprint. And that's basically how we prioritize these things. It's like we don't look for, even if it's like really cool, but it only affects 5 people, there's not really a reason to really spend all the time to dedicate to that. So that was pretty much our primary driver is what are people most likely using the most? Let's start there. If there's a prompt and there's tools attached to that prompt, let's figure out a way to break it. That's effectively how we got started.
Krista Case
>> That makes sense, Joe. Like you say, then the impact of your research will be greater because you're studying these potential vulnerabilities that are going to impact a broader cross-section of the enterprise IT user base. So when did you and your team learn or when did you start to realize that you had uncovered this new class of vulnerability?
Joe Hladik
>> So the actual discovery happened back in February. And then we followed the standard disclosure processes, reaching out to Microsoft. Obviously we wanted to talk about our findings publicly, but there, there's a responsible disclosure process that you have to follow when you discover these things. So we engaged Microsoft. Um, they had patched, uh, what we have found, I think by mid-March, so a month later. So one thing I do need to clarify is this is no longer a threat. What we found has been fixed. Patches have been rolled out and it's no longer necessarily a vulnerability. But on a larger scale, that doesn't mean that this vulnerability can't be applied to other, AI copilots or things of that nature, mainly because of the nature of the actual exploit itself, which we were able to basically break out of the sandbox and gain access to the backend infrastructure in Azure.
Krista Case
>> Okay.
Joe Hladik
>> Which would allow you to get command and control of potentially, more than one, probably hundreds, thousands, or, much more depending on the volume of what exists within that tenant of users' files, SharePoint files, OneDrive, whatever. And you have, basically that AI capability. And now you can browse and have basically free access to any of that. So it's a major, major find.
Krista Case
>> It was a major find. It was certainly. And I'm interested in sort of how your team, what led you to believe that it was really a novel type of attack as opposed to just kind of one potential vulnerability that could be exploited. And I imagine it's kind of like you say, the process itself could be replicated. But can you talk a little bit about that?
Joe Hladik
>> Yeah, I mean, one aspect— that's an interesting question, right? It's because it's like, how do you know that this hasn't been discovered before? And there's always that question of like, well, if it was, then it's probably for nefarious reasons because it was never disclosed and made public, right? So I can't really comment if that ever occurred or not. Mainly because one, we haven't observed it, and Microsoft would probably be the only ones that would be able to answer that question, and I'm not equipped to answer that on their behalf. But on the other hand, we obviously pay attention to open source intelligence, other publications, and as far as we know, we were the only ones at the time that were able to make a discovery like this. Since that point, though, there have been numerous other similar discoveries about sandbox escaping, I think is the more official term that's been coined. But I believe we were the first, as far as I know, that at least was publicly disclosed.
Krista Case
>> Yeah. And so I think when we think about it being kind of a novel attack, I like to ask the question, Joe, because A lot of times we hear about AI accelerating the speed and the scale of the attacks, but there's not as much conversation on AI actually creating new types of attacks. So that's why I think this is something important to pay attention to, because again, it does show, as I was saying, kind of the OpenAI commentary does show that that's a possibility.
Joe Hladik
>> That's another interesting point I think I want to expand on a little bit. So there's things that AI is good at, and then there's things that AI is not. So if there's basically a procedural or some type of logical problem to solve, AI is really good at that. And I like to call it the science of the problem. AI is really good at the science of the problem. What they're not good at is the tradecraft, the art of the possible. So if you have a challenge that isn't necessarily logically solved and you need a little creativity in the mix, that's where the human element is vitally important. It's actually the combination of AI and human working together that is the real danger. Because if you have a really creative, intuitive, and someone who's really well-versed in tradecraft or attacker tradecraft merged with a powerful AI model, you have some serious capabilities that probably didn't exist before this era. Right. Maybe at the nation-state level. You're right. But now that level of capability is available to pretty much anybody who is creative enough to put it out
Krista Case
>> there.It's a really important job because I feel like we tend to talk a lot about AI lowering the barrier to entry. But what you're describing, where one plus one equals three is particularly dangerous. So thank you for elaborating on
Joe Hladik
>> that.Yeah. And I'd also like to say too, AI is not necessarily great at creating new styles of attacks. Even with Ori Lahav, who's the researcher that made this discovery, who's presenting tomorrow, he's the artist and he used AI to make the discovery, right? So at the end of the day, that's why I think we need to start looking at this on the offense and defensively as it's not just AI. You need a really capable human behind the AI as well. Right. Because they work hand in hand.
Krista Case
>> They do. They absolutely do.
Joe Hladik
>> Yeah.
Krista Case
>> And I know your research went kind of beyond Microsoft. It sounds like your team also identified some other potentially critical vulnerabilities in some AI orchestration platforms. Can you talk a little bit about that? And then maybe the implications for the industry since we're all kind of gathered here at Black Hat in terms of how to securely build and deploy these AI applications that businesses are just racing to adopt.
Joe Hladik
>> Yeah, so there was a series of vulnerabilities, I believe, and I don't have the documents in front of me, but I believe Langflow, IBM's Langflow was one of them and ChatMate, which were exploited in very similar ways. But I think the important factor to focus on here is how do we defend against this?
Krista Case
>> Yeah, exactly.
Joe Hladik
>> So throughout my life in security, there's always been that challenge of visibility. I need visibility into this network segment, or I need visibility into this host or server or whatever, or log files, right? Well, nowadays it's the visibility for AI copilots and agents is available, Microsoft or whoever, they provide the logs, but it's a matter of observability. What's the context? That's the real challenge because how do you build detection for something like this? Because it's a different medium than we're used to. It's a completely different space. So we almost need our own— there is no product right now that actually solves for that particular case. You almost have to build it yourself. Understand what is normal for the AIs that you're using and then extrapolate from there what becomes abnormal. So you almost have to build that baseline of behavior to understand that, because without it, how are you going to know what's abnormal?
Krista Case
>> Absolutely.
Joe Hladik
>> Right?
Krista Case
>> Absolutely.
Joe Hladik
>> And that's, I think, the main challenge here is you're going to have to, based on the context of these logs and understanding and differentiating between normal and malicious, or let's say abnormal, not even malicious, just something an agent may do unintentionally. Getting ahead of that is certainly a challenge. But I think we have the tools like AI. We have the tools that we need to use AI in the sense of helping us figure out, build out these trends, like what patterns look normal and what don't. And I think just like attackers will be using AI to enhance their own processes, we'll be doing the same on the defense.
Krista Case
>> Yeah, and it's another great point. So like you say, these automated scanners, they didn't detect it. And so the question back to you would be, I know you were talking about the human expertise really helping to understand what exactly that malicious behavior is. When you think about maybe your team or threat researchers in general, can you elaborate a little bit on where you think human expertise is going to be especially critical maybe over the next 12 to 18 months?
Joe Hladik
>> You ask some really good questions. So I've thought about this and what's difficult is I remember thinking about this at this time last year. And at this time last year, generative AI was basically what everybody was talking about. And agentic AI was sort of that lighthouse in the distance, like, this is where we're going to be soon. And at the time, no one really knew when, but we knew soon. Now, agentic is everywhere. It's not generative AI, it's agentic AI. There's a whole new set of capabilities that come along with that. When I get asked where are we gonna be in 18 months and what should we do about it? I think we're at the point right now where we have to literally take it day by day. And as a threat researcher of the human element, the best thing we can do is keep doing what we're doing, but more diligently. And it's like one of those things that's like, well, haven't we been doing this very diligently for 20-plus years or however long? And the landscape is changing. I think the challenge is understanding the landscape.
Krista Case
>> Mm-hmm.
Joe Hladik
>> Because if you're able to understand and keep up with the changes in the landscape, then you can adapt or adopt what you've already learned throughout your career or just your knowledge base in general. And be like, "Oh, I've seen this before." Because at the end of the day, agents are just bots with models. They're a bot that asks a model, and then the model will tell them what to do, and then they act. So, it's new, it's cool, but at the same time, I've seen this before. It's just a new iteration of something that's been done before. So, by having that knowledge of that landscape and reapplying what you know, it's basically the reinterpretation of something that's been done before in a new way. As long as you're able to identify that, I think that's the best way to keep up. Learn your history. If you know your history, then you'll be able to apply that knowledge to the current events.
Krista Case
>> Take the learnings from it and everything like that.
Joe Hladik
>> I don't think there's anything else we can do.
Krista Case
>> Absolutely. So I know your report You had also talked about for every vulnerability that you and your team uncover, there's potentially more that are sitting in these AI tools. So if I'm a security leader attending this show here at Black Hat, it sounds a little doomsday, how concerned should I be or how should I think about that and, potentially preparing for that kind of reality?
Joe Hladik
>> I was talking to a CISO yesterday and he had a really good answer to a very similar question because I was basically asking that too, is how do you prioritize this, especially with the advent of things like Mythos or Fable, which is the public release, right? Glasswing, I think, was a step in the right direction where it was taking the longstanding process of responsible disclosure and applying it to a collective of companies that basically run the backbone of the world and trying to get ahead of the vulnerability discoveries before malicious actors might get there. I think that was great. But in terms of prioritization, when you have something that's able to discover, X number of vulnerabilities in a very short period of time, how do you prioritize it? I think, and this was a really good answer that I heard is that, One, with these, each vulnerability, do they have layers of security already wrapped around them and protecting them? If there's like 10 layers of security wrapping around that vulnerability, then do you need to fix it? Is it more expensive to fix it? And I think that's the kind of way you have to look at it. Because if it's a surface-level vulnerability and there's no protections around it, then yeah, prioritize it. Red, critical, whatever it is, put the money into fixing it. But really understanding your own security posture around the vulnerabilities that are being discovered, I think is the best way to prioritize, especially if you have thousands, if not millions to deal with. Again, I don't think there's a better way at this point right now until we have other tools available to us that might help solve this problem.
Krista Case
>> I agree, Joe. I've been having a number of conversations around the role of security leaders these days is really to sort of understand the risk profile of their organization and understand where tradeoffs need to be made and almost become these arbiters of these decisions.
Joe Hladik
>> Yeah, yeah, exactly. Knowing what you have— and I've heard this too— having an SBOM, right? Not just having it, but using it. Is such a critical thing right now. And most people or organizations, they might have an SBOM, but it's in an archive somewhere, or it's not updated and things like that. I think the basic things that we used to do so long ago, that the government's really good at, for instance, I think that is something I think we need to start paying more attention to again. Back to the basics.
Krista Case
>> Eat your vegetables, right?
Joe Hladik
>> Yes.
Krista Case
>> Yep. Well, Joe, thank you so much for joining. This has been really fascinating. We'll look forward to that threat research. Thanks for coming on theCUBE.
Joe Hladik
>> Thank you for having me.
Krista Case
>> I appreciate it. All right, and thank you so much for watching. Stick around, we'll be back in just a few minutes with more live from Black Hat 2026.
>> Welcome back to theCUBE. We're here at Black Hat 2026 at Mandalay Bay. I'm Krista Case, and we're talking a lot about adversarial use of AI here at the show this week. And one interesting thing that we're seeing is that there's a potential for AI to introduce actually previously unknown attack techniques. Rubrik Zero Labs actually did some research that uncovered one of these attack techniques using Microsoft Copilot in Azure. So here to discuss that is Joe Hladik, who's head of Rubrik Zero Labs. Joe, thanks so much for joining us today.
Joe Hladik
>> Thanks for having me.
Krista Case
>> Yeah, really appreciate it. So before we dig into the research, Joe, I wanted to talk with you a little bit about Rubrik Zero Labs. your team is in a really interesting position because they look at these emerging attack techniques. So can you comment on what you're seeing, especially these last maybe 4 to 6 months or so as we've seen this adversarial use of AI pick up?
Joe Hladik
>> Sure. Well, I'd like to begin with Rubrik Zero Labs, we have a unique perspective in the sense that with the charter of my organization and the type of research we do, our main point of research is around backup data. And the mission was really to turn, just like you have EDR and NDR type of solutions out there that look at endpoint or host data and network data, no one's looking at backup data. So that one, that's our main source of intelligence is we found it to be a viable place to find actual intelligence to act upon. So that's one thing and that's pretty much our primary driver for a lot of the research we do. On the other hand, we do a lot of research that other labs do as well, which is vulnerability research and things like that. We had an internal discussion around basically prioritization. There's just so much happening with AI. What are the— we know how we're using AI and we wanna better understand, one, how are our adversaries using AI and their methodologies and workflows and things. So we discovered— we decided to look at, well, what are the end users doing? What are they often using? Copilot. I think the number I had, and it's probably much higher now than it was at the time we decided to do this project, it was around 20 million seats and about 90% of the Fortune 500. So it's a large footprint. And that's basically how we prioritize these things. It's like we don't look for, even if it's like really cool, but it only affects 5 people, there's not really a reason to really spend all the time to dedicate to that. So that was pretty much our primary driver is what are people most likely using the most? Let's start there. If there's a prompt and there's tools attached to that prompt, let's figure out a way to break it. That's effectively how we got started.
Krista Case
>> That makes sense, Joe. Like you say, then the impact of your research will be greater because you're studying these potential vulnerabilities that are going to impact a broader cross-section of the enterprise IT user base. So when did you and your team learn or when did you start to realize that you had uncovered this new class of vulnerability?
Joe Hladik
>> So the actual discovery happened back in February. And then we followed the standard disclosure processes, reaching out to Microsoft. Obviously we wanted to talk about our findings publicly, but there, there's a responsible disclosure process that you have to follow when you discover these things. So we engaged Microsoft. Um, they had patched, uh, what we have found, I think by mid-March, so a month later. So one thing I do need to clarify is this is no longer a threat. What we found has been fixed. Patches have been rolled out and it's no longer necessarily a vulnerability. But on a larger scale, that doesn't mean that this vulnerability can't be applied to other, AI copilots or things of that nature, mainly because of the nature of the actual exploit itself, which we were able to basically break out of the sandbox and gain access to the backend infrastructure in Azure.
Krista Case
>> Okay.
Joe Hladik
>> Which would allow you to get command and control of potentially, more than one, probably hundreds, thousands, or, much more depending on the volume of what exists within that tenant of users' files, SharePoint files, OneDrive, whatever. And you have, basically that AI capability. And now you can browse and have basically free access to any of that. So it's a major, major find.
Krista Case
>> It was a major find. It was certainly. And I'm interested in sort of how your team, what led you to believe that it was really a novel type of attack as opposed to just kind of one potential vulnerability that could be exploited. And I imagine it's kind of like you say, the process itself could be replicated. But can you talk a little bit about that?
Joe Hladik
>> Yeah, I mean, one aspect— that's an interesting question, right? It's because it's like, how do you know that this hasn't been discovered before? And there's always that question of like, well, if it was, then it's probably for nefarious reasons because it was never disclosed and made public, right? So I can't really comment if that ever occurred or not. Mainly because one, we haven't observed it, and Microsoft would probably be the only ones that would be able to answer that question, and I'm not equipped to answer that on their behalf. But on the other hand, we obviously pay attention to open source intelligence, other publications, and as far as we know, we were the only ones at the time that were able to make a discovery like this. Since that point, though, there have been numerous other similar discoveries about sandbox escaping, I think is the more official term that's been coined. But I believe we were the first, as far as I know, that at least was publicly disclosed.
Krista Case
>> Yeah. And so I think when we think about it being kind of a novel attack, I like to ask the question, Joe, because A lot of times we hear about AI accelerating the speed and the scale of the attacks, but there's not as much conversation on AI actually creating new types of attacks. So that's why I think this is something important to pay attention to, because again, it does show, as I was saying, kind of the OpenAI commentary does show that that's a possibility.
Joe Hladik
>> That's another interesting point I think I want to expand on a little bit. So there's things that AI is good at, and then there's things that AI is not. So if there's basically a procedural or some type of logical problem to solve, AI is really good at that. And I like to call it the science of the problem. AI is really good at the science of the problem. What they're not good at is the tradecraft, the art of the possible. So if you have a challenge that isn't necessarily logically solved and you need a little creativity in the mix, that's where the human element is vitally important. It's actually the combination of AI and human working together that is the real danger. Because if you have a really creative, intuitive, and someone who's really well-versed in tradecraft or attacker tradecraft merged with a powerful AI model, you have some serious capabilities that probably didn't exist before this era. Right. Maybe at the nation-state level. You're right. But now that level of capability is available to pretty much anybody who is creative enough to put it out
Krista Case
>> there.It's a really important job because I feel like we tend to talk a lot about AI lowering the barrier to entry. But what you're describing, where one plus one equals three is particularly dangerous. So thank you for elaborating on
Joe Hladik
>> that.Yeah. And I'd also like to say too, AI is not necessarily great at creating new styles of attacks. Even with Ori Lahav, who's the researcher that made this discovery, who's presenting tomorrow, he's the artist and he used AI to make the discovery, right? So at the end of the day, that's why I think we need to start looking at this on the offense and defensively as it's not just AI. You need a really capable human behind the AI as well. Right. Because they work hand in hand.
Krista Case
>> They do. They absolutely do.
Joe Hladik
>> Yeah.
Krista Case
>> And I know your research went kind of beyond Microsoft. It sounds like your team also identified some other potentially critical vulnerabilities in some AI orchestration platforms. Can you talk a little bit about that? And then maybe the implications for the industry since we're all kind of gathered here at Black Hat in terms of how to securely build and deploy these AI applications that businesses are just racing to adopt.
Joe Hladik
>> Yeah, so there was a series of vulnerabilities, I believe, and I don't have the documents in front of me, but I believe Langflow, IBM's Langflow was one of them and ChatMate, which were exploited in very similar ways. But I think the important factor to focus on here is how do we defend against this?
Krista Case
>> Yeah, exactly.
Joe Hladik
>> So throughout my life in security, there's always been that challenge of visibility. I need visibility into this network segment, or I need visibility into this host or server or whatever, or log files, right? Well, nowadays it's the visibility for AI copilots and agents is available, Microsoft or whoever, they provide the logs, but it's a matter of observability. What's the context? That's the real challenge because how do you build detection for something like this? Because it's a different medium than we're used to. It's a completely different space. So we almost need our own— there is no product right now that actually solves for that particular case. You almost have to build it yourself. Understand what is normal for the AIs that you're using and then extrapolate from there what becomes abnormal. So you almost have to build that baseline of behavior to understand that, because without it, how are you going to know what's abnormal?
Krista Case
>> Absolutely.
Joe Hladik
>> Right?
Krista Case
>> Absolutely.
Joe Hladik
>> And that's, I think, the main challenge here is you're going to have to, based on the context of these logs and understanding and differentiating between normal and malicious, or let's say abnormal, not even malicious, just something an agent may do unintentionally. Getting ahead of that is certainly a challenge. But I think we have the tools like AI. We have the tools that we need to use AI in the sense of helping us figure out, build out these trends, like what patterns look normal and what don't. And I think just like attackers will be using AI to enhance their own processes, we'll be doing the same on the defense.
Krista Case
>> Yeah, and it's another great point. So like you say, these automated scanners, they didn't detect it. And so the question back to you would be, I know you were talking about the human expertise really helping to understand what exactly that malicious behavior is. When you think about maybe your team or threat researchers in general, can you elaborate a little bit on where you think human expertise is going to be especially critical maybe over the next 12 to 18 months?
Joe Hladik
>> You ask some really good questions. So I've thought about this and what's difficult is I remember thinking about this at this time last year. And at this time last year, generative AI was basically what everybody was talking about. And agentic AI was sort of that lighthouse in the distance, like, this is where we're going to be soon. And at the time, no one really knew when, but we knew soon. Now, agentic is everywhere. It's not generative AI, it's agentic AI. There's a whole new set of capabilities that come along with that. When I get asked where are we gonna be in 18 months and what should we do about it? I think we're at the point right now where we have to literally take it day by day. And as a threat researcher of the human element, the best thing we can do is keep doing what we're doing, but more diligently. And it's like one of those things that's like, well, haven't we been doing this very diligently for 20-plus years or however long? And the landscape is changing. I think the challenge is understanding the landscape.
Krista Case
>> Mm-hmm.
Joe Hladik
>> Because if you're able to understand and keep up with the changes in the landscape, then you can adapt or adopt what you've already learned throughout your career or just your knowledge base in general. And be like, "Oh, I've seen this before." Because at the end of the day, agents are just bots with models. They're a bot that asks a model, and then the model will tell them what to do, and then they act. So, it's new, it's cool, but at the same time, I've seen this before. It's just a new iteration of something that's been done before. So, by having that knowledge of that landscape and reapplying what you know, it's basically the reinterpretation of something that's been done before in a new way. As long as you're able to identify that, I think that's the best way to keep up. Learn your history. If you know your history, then you'll be able to apply that knowledge to the current events.
Krista Case
>> Take the learnings from it and everything like that.
Joe Hladik
>> I don't think there's anything else we can do.
Krista Case
>> Absolutely. So I know your report You had also talked about for every vulnerability that you and your team uncover, there's potentially more that are sitting in these AI tools. So if I'm a security leader attending this show here at Black Hat, it sounds a little doomsday, how concerned should I be or how should I think about that and, potentially preparing for that kind of reality?
Joe Hladik
>> I was talking to a CISO yesterday and he had a really good answer to a very similar question because I was basically asking that too, is how do you prioritize this, especially with the advent of things like Mythos or Fable, which is the public release, right? Glasswing, I think, was a step in the right direction where it was taking the longstanding process of responsible disclosure and applying it to a collective of companies that basically run the backbone of the world and trying to get ahead of the vulnerability discoveries before malicious actors might get there. I think that was great. But in terms of prioritization, when you have something that's able to discover, X number of vulnerabilities in a very short period of time, how do you prioritize it? I think, and this was a really good answer that I heard is that, One, with these, each vulnerability, do they have layers of security already wrapped around them and protecting them? If there's like 10 layers of security wrapping around that vulnerability, then do you need to fix it? Is it more expensive to fix it? And I think that's the kind of way you have to look at it. Because if it's a surface-level vulnerability and there's no protections around it, then yeah, prioritize it. Red, critical, whatever it is, put the money into fixing it. But really understanding your own security posture around the vulnerabilities that are being discovered, I think is the best way to prioritize, especially if you have thousands, if not millions to deal with. Again, I don't think there's a better way at this point right now until we have other tools available to us that might help solve this problem.
Krista Case
>> I agree, Joe. I've been having a number of conversations around the role of security leaders these days is really to sort of understand the risk profile of their organization and understand where tradeoffs need to be made and almost become these arbiters of these decisions.
Joe Hladik
>> Yeah, yeah, exactly. Knowing what you have— and I've heard this too— having an SBOM, right? Not just having it, but using it. Is such a critical thing right now. And most people or organizations, they might have an SBOM, but it's in an archive somewhere, or it's not updated and things like that. I think the basic things that we used to do so long ago, that the government's really good at, for instance, I think that is something I think we need to start paying more attention to again. Back to the basics.
Krista Case
>> Eat your vegetables, right?
Joe Hladik
>> Yes.
Krista Case
>> Yep. Well, Joe, thank you so much for joining. This has been really fascinating. We'll look forward to that threat research. Thanks for coming on theCUBE.
Joe Hladik
>> Thank you for having me.
Krista Case
>> I appreciate it. All right, and thank you so much for watching. Stick around, we'll be back in just a few minutes with more live from Black Hat 2026.