Skip to content
Security & Trust

DIVD says a flaw let an intruder in, then an AI agent ran the attack

A security nonprofit reports an agent-driven intrusion. The agent's errors helped investigators, but they are no defence plan.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
DIVD says a flaw let an intruder in, then an AI agent ran the attack

AI-generated image for WebPulse. About our images

Key finding

Time before DIVD was breached: Almost 7 years (Source: DIVD, "When no if" (September 2026))

A security nonprofit becomes the victim

Security teams often say the question is not whether you will be breached, but when. The Dutch Institute for Vulnerability Disclosure (DIVD) now says its own turn has come. The nonprofit scans for systems with known flaws and warns their owners. It says it took almost seven years for someone to get in.

The more useful part of its account is how the intrusion looked. DIVD says the attacker first used a technical vulnerability to get access. An automated AI agent then handled the activity that followed. DIVD says the pattern of activity points to an agentic attack. That means software that chooses its own next step, not a person typing commands.

Almost 7 years
Time before DIVD was breached
Source: DIVD, "When no if" (September 2026)

What DIVD has said so far

DIVD says it noticed suspicious activity, investigated and concluded it had been compromised. It blocked access to its infrastructure and started a forensic investigation with a third-party incident response team. It says it cannot rule anything out yet. It is treating the case as a worst-case scenario and assuming the breach is real until shown otherwise.

DIVD told the parties directly involved. It reported the incident to the Autoriteit Persoonsgegevens, the Dutch data protection authority, and to the National Cyber Security Centre (NCSC). It also discussed its options with the police. Marieke Rijken is the named spokesperson.

In a Monday update, DIVD said the flaw sat in an undisclosed system and was not in Citrix NetScaler. The attacker then used an automated agent for what happened after entry. DIVD withheld full details so it would not affect the investigation or put other victims at risk.

The attack's purpose and impact remain unclear. BleepingComputer asked DIVD what kind of flaw it was and whether a fix existed. No reply had arrived by publication.

2
Authorities formally notified
Source: DIVD, "When no if" (September 2026): the data protection authority and the NCSC

How an agent-driven intrusion works

A human intruder plans a route, tries it and adjusts. An agent replaces that loop with software. After each action, it reads the result and picks the next move by itself.

DIVD describes exactly this. It says the agent chose each step on its own, "at the speed of light", with sloppy logic. It also says the agent explained its decisions at length in its comments.

The agent also blundered. DIVD says its password guessing got in the way of its own interception attack. In that kind of attack, the intruder sits between a user and a service to capture what passes through. Password spraying tries common passwords across many accounts. The two techniques worked against each other.

DIVD's judgment is that the agent was not well trained or set up for this kind of work. It called the attack "loud and very very messy". That left enough evidence for researchers to reverse-engineer what happened.

The lesson: noise helped this time

The lesson here is about what helped the investigators. It was not a control. It was the attacker's clumsiness. The agent talked too much and tripped over itself, so DIVD could rebuild events.

The sources do not say how a better-configured agent would behave. That is unknown, and this story does not guess. But leaders can ask whether their own detection depends on intruders being careful, slow or quiet. This agent acted at machine speed and narrated its reasoning. Agents may leave a different kind of trail.

There is also a human cost. DIVD lists looking after its volunteers, who have spent years working toward a safer digital society, among its priorities. Even a well-run security organisation now spends its time on forensics and notifications.

Questions for your team

First, can your logs show a sequence of actions happening faster than a person could type them? Ask whether anyone reviews for that pattern.

Second, how quickly can you isolate infrastructure? DIVD isolated its systems and brought in a third-party response team. Check that your own retainer and contacts exist before you need them.

Third, who do you notify, and in what order? DIVD informed the data protection authority and the NCSC, and discussed options with the police. Confirm your own list.

Fourth, how fast do you patch flaws in exposed systems? DIVD says the way in was a technical vulnerability. It has not said whether a patch existed for this flaw, but the question is worth asking regardless. Ask for the patch state of every internet-facing system, not an average.

DIVD has scheduled a fuller update for October 1. It also plans to warn other organisations that may share the same flaw, as soon as it can. Until then, the details are limited. The core point stands: DIVD says a vulnerability gave the intruder access and an agent took over from there. Its mistakes gave investigators something to work with.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Dutch Institute for Vulnerability Disclosure (DIVD).

Share this insight