AI Agent Autonomously Hacked Dutch Cybersecurity Nonprofit DIVD
The Netherlands Institute for Vulnerability and Disclosure (DIVD) has been targeted in an AI-powered cyberattack that the cybersecurity nonprofit described as “noisy and extremely troubling.”
Evidence uncovered during an ongoing investigation indicates that the attacker exploited a vulnerability, although the purpose and impact of the intrusion remain unknown.
AI agent carried out autonomous post-exploitation activity
DIVD is a nonprofit organization made up of volunteer security researchers. The group scans the Internet for systems affected by known vulnerabilities, notifies their owners, and provides guidance on reducing the associated risks.
After seven years of peaceful operation, DIVD announced late last week that it had been hacked. The organization said the intrusion was carried out autonomously by an AI agent.
DIVD described the attack as “loud and extremely troubling.” Although the incident left behind substantial evidence that could help researchers reconstruct what happened, the organization emphasized that it was nevertheless serious.
“This is an attack we’ve never seen before, not because it’s the first, but because the modus operandi indicates that this is an agent-based AI attack,” DIVD said.
The organization launched an investigation and notified the police, the Autoriteit Persoonsgegevens (Data Protection Authority), and the National Cyber Security Center (NCSC).
DIVD provided additional information in an update on Monday but withheld technical details to avoid interfering with the investigation or putting additional victims at risk.
“The attack itself was loud and very nasty. We could see that the agent was operating in an automated manner, because after every action, it was deciding the next step on its own with sloppy logic and patterns at the speed of light,” DIVD said.
Attackers exploited undisclosed technical vulnerabilities
The attackers exploited “technical vulnerabilities” in undisclosed systems and then used automated AI agents to perform post-exploitation activities. DIVD specifically said that the affected systems were not Citrix NetScaler devices.
According to the researchers, the AI agent made several mistakes, including disrupting its own man-in-the-middle attack while carrying out password spraying.
The agents operated autonomously on DIVD’s network, selecting their next steps without direct human intervention and explaining their decisions in comments.
DIVD believes the agent was poorly trained and configured for the operation. Its actions also left behind enough information to help researchers reverse engineer the incident.
DIVD to provide more information about the incident
The organization said it plans to publish a more detailed update on October 1 and will notify other potentially affected parties as soon as possible.
BleepingComputer contacted DIVD to learn more about the undisclosed vulnerability involved in the attack and its patch status but had not received a response at the time of publication.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



