Automated AI agent used to breach cybersecurity nonprofit DIVD
DIVD says an autonomous AI agent exploited a flaw and performed a messy intrusion on its network.
The Dutch Institute for Vulnerability Disclosure (DIVD) said it was hacked by an autonomous AI agent after seven years without incident. The attacker exploited an undisclosed technical vulnerability, which DIVD said was not Citrix NetScaler, and the agent then performed post-exploitation on its own. DIVD described the activity as loud and messy, including password spraying that interfered with the agent's own adversary-in-the-middle attack. It notified Dutch police, the data protection authority, and the NCSC; the attacker's goal and impact remain unclear, with a fuller update promised for October 1.