DIVD breached by autonomous AI agent in "messy" attack

DIVD breached by autonomous AI agent in "messy" attack

The Dutch Institute for Vulnerability Disclosure (DIVD) has been hit by a cyberattack that it says was carried out by an autonomous AI agent. The nonprofit called the intrusion "loud and very very messy." Investigators have found evidence that the attacker got in through a vulnerability, but what the attacker wanted and how much damage was done are still unclear.

DIVD is run by volunteer security researchers. They scan the internet for systems exposed to known vulnerabilities, alert the owners of those systems, and share guidance on how to reduce the risk.

First incident in seven years

The organization disclosed the breach late last week. It said this was the first time it had been hacked in seven years of operations. According to DIVD, the attack stood out less because it was a first and more because of how it was carried out.

"This is an attack we have not seen before. Not because it's our first, but because the modus operandi indicates that this is an agentic AI-powered attack," DIVD explained.

After discovering the intrusion, DIVD opened an investigation. It reported the incident to the police, to the Autoriteit Persoonsgegevens (the Dutch data protection authority), and to the National Cyber Security Center (NCSC).

An agent that explained too much

DIVD shared more details in an update on Monday but held some information back. It said it did not want to affect the investigation or expose other potential victims to further risk.

According to the organization, the attacker first exploited a "technical vulnerability" in a system it has not named. DIVD did say that the affected system was not Citrix NetScaler, a product line that is currently facing mass exploitation attempts. Once the attacker had initial access, an automated AI agent handled the post-exploitation phase.

"The attack itself was loud and very very messy. We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern," DIVD said.

The agent moved through DIVD's network on its own and chose each next step itself. It also left comments that over-explained the reasoning behind its decisions.

The researchers said the agent did "some pretty dumb things." In one case, it disrupted its own adversary-in-the-middle attack by running password spraying at the same time.

DIVD believes the agent was badly trained and poorly configured for this kind of operation. That helped the defenders, because the agent left enough traces behind for the team to reverse-engineer the incident.

More details promised

DIVD said it will publish a more detailed update on October 1. It also plans to contact other organizations that may be exposed to the same vulnerability as soon as it can.

BleepingComputer asked DIVD what kind of flaw was exploited and whether it has been patched. It had not received an answer at the time of its report.

Our Take

The DIVD case adds to a growing list of incidents in which AI agents do the hands-on work of an intrusion. Guy Fawkes News recently covered OpenAI agents breaching an Australian Medicare statistics portal and the Carbonato malware, which uses AI agents to hijack Docker hosts. Together, these cases suggest that attackers are testing how much of an operation they can hand over to automation.

The clumsiness in this case is not necessarily reassuring. A sloppy agent that acts at machine speed can still reach sensitive systems, and better-configured agents may leave far fewer traces. For defenders, fast and noisy bursts of activity, such as password spraying running alongside other techniques, could become a useful detection signal.

The entry point was a vulnerability, not the AI itself. That puts the focus back on patching internet-facing systems quickly. It is worth watching whether DIVD's October 1 update names the flaw and whether other organizations turn out to be affected. The fact that a group dedicated to finding exposed systems was itself breached shows that no organization is exempt.