Dutch cybersecurity nonprofit DIVD breached by autonomous AI agent

An autonomous AI agent was used to break into the Dutch Institute for Vulnerability Disclosure (DIVD), the nonprofit said, describing the intrusion as the first agentic AI-powered attack it has logged in seven years of scanning the internet for vulnerable systems. The agent moved through DIVD’s network on its own, choosing each next step without a human directing it, and left enough evidence for researchers to reconstruct what happened.
What DIVD has confirmed so far
DIVD is a nonprofit group of volunteer security researchers that scans the internet for systems affected by known vulnerabilities, notifies the owners, and shares guidance on how to mitigate the risks. Late last week, the organization disclosed that it had been hacked after seven years of uneventful operations, and that the intrusion was carried out by an AI agent acting on its own.
In a Monday update, DIVD added that the attack was, in its characterization, loud and very, very messy, which made it easier to investigate. The attacker first exploited a technical flaw in an undisclosed system, which DIVD specifically said was not Citrix NetScaler, and then handed the post-exploitation work to an automated AI agent.
What the AI agent actually did
According to DIVD’s write-up, the agent decided each next move itself, ran at machine speed, and used sloppy logic and patterns. The organization said the agent did some pretty dumb things, including interfering with its own adversary-in-the-middle attempt while running a password-spraying attack, and over-explaining its own decisions in the comments it left behind.
DIVD’s working theory is that the agent was poorly trained and poorly configured for operations like this, which is why it left enough traces for the researchers to reverse-engineer what had happened on the network. The exact type and patch state of the undisclosed vulnerability have not been released.
Who has been informed
DIVD said it has notified the Dutch police, the Autoriteit Persoonsgegevens (the country’s data protection authority), and the National Cyber Security Center (NCSC). The organization is withholding full technical details to avoid tipping off other attackers and to keep from putting more potential victims at risk.
The nonprofit promised a more detailed update on October 1 and said it will notify other possible victims of the same vulnerability once it has finished verifying them.
Why an agentic attack is different
An agentic AI attack is one in which a software agent, given a goal, picks its own path through a target system rather than following a fixed script written by a human operator. That changes the speed at which an intrusion can unfold and the kind of evidence it leaves, since the agent’s choices are visible in logs and in the commands it ran.
DIVD framed the incident as a new modus operandi rather than a new breach type: the techniques were familiar, but the autonomous decision-making at every step is what the organization has not documented before on its own network.
What defenders can take from this
The practical lesson from DIVD’s account is that an attacker who hands the post-exploitation phase to an AI agent still needs a working initial-access vulnerability to get in. Patching known flaws and watching for the kind of noisy, fast, repetitive behavior that DIVD described remain the controls defenders can apply today.
FAQ
What is DIVD?
The Dutch Institute for Vulnerability Disclosure is a nonprofit organization of volunteer security researchers that scans the internet for systems affected by known vulnerabilities, notifies the owners, and publishes mitigation guidance.
What happened to DIVD?
An attacker exploited a vulnerability in an undisclosed system on DIVD’s network and then used an autonomous AI agent to perform post-exploitation activities. DIVD described the attack as loud and very, very messy and said the agent decided each next step itself.
Has DIVD said which vulnerability was used?
No. DIVD said the flaw is not Citrix NetScaler and that it is withholding full details until it can notify other possible victims, with a more detailed update promised for October 1.
This article summarizes reporting from bleepingcomputer.com.