Skip to content

DIVD says AI agent carried out cyberattack through software flaw

DIVD says AI agent carried out cyberattack through software flaw

The Dutch Institute for Vulnerability Disclosure, a nonprofit organization of volunteer security researchers, said an autonomous AI agent was used in a cyberattack against its infrastructure.

DIVD scans internet-connected systems for known vulnerabilities, contacts affected organizations and provides information on mitigating security risks.

After almost seven years without a successful intrusion, the organization disclosed last week that attackers had gained access to its systems.

The investigation remains active, and DIVD hasn’t disclosed the full scope or purpose of the attack. Evidence examined so far indicates the threat actor exploited a technical vulnerability in an undisclosed system and then used an AI agent for post-exploitation activity. DIVD specifically said the vulnerability wasn’t related to Citrix NetScaler.

DIVD described the incident as an agentic AI-powered attack, based on how activity unfolded after the initial compromise.

The organization said the agent appeared to choose its next action after each previous step rather than following a fixed sequence prepared in advance.

AI agent operated autonomously inside DIVD network

Researchers described the intrusion as unusually noisy and messy, which left substantial evidence behind for forensic analysis. According to DIVD, the automated agent moved through the environment quickly but followed sloppy logic and made mistakes that exposed details of its behavior.

One example involved the agent interfering with its own adversary-in-the-middle operation by carrying out password spraying at the same time. DIVD said the behavior suggested the system had been poorly trained or configured for offensive security work.

The agent also left comments explaining many of its actions. Those traces are giving investigators more material to reconstruct how the attack developed and study the decision process behind the automated activity.

DIVD hasn’t identified the attacker or disclosed what system contained the vulnerability used for initial access. The organization also hasn’t established publicly whether information was stolen, altered or otherwise affected.

Investigation reported to Dutch authorities

After detecting suspicious activity, DIVD blocked access to parts of its infrastructure and began a forensic investigation with support from an external incident response team. The organization said it was treating the incident as a worst-case scenario while investigators determine the extent of the compromise.

DIVD reported the incident to the Dutch Data Protection Authority, the National Cyber Security Centre and police. It also contacted parties directly involved in the incident while keeping its infrastructure isolated during the forensic work.

The organization has withheld some technical details because releasing them during the investigation might interfere with the response or expose other organizations using the same vulnerable technology.

Other possible victims could be notified

DIVD said the same technical weakness might affect other organizations. Researchers plan to contact potential victims as soon as they have enough information to do so safely.

The organization expects to provide another public update on Oct. 1 with more information from its investigation. Until then, the affected product, vulnerability and attacker remain undisclosed.

The incident gives DIVD an unusual position in the security community. Its normal work involves locating vulnerable systems before criminals exploit them and notifying their owners. This time its own infrastructure became the target.

The available evidence doesn’t establish how sophisticated the underlying AI system was or how much human direction remained behind the operation. DIVD’s assessment is based on the observed behavior after exploitation, including autonomous sequencing of actions, machine-generated comments and mistakes made during the attack.

For now, investigators are working through the evidence left by the agent and trying to determine what happened after initial access. The noisy execution might have made the attack less efficient, but it also produced a detailed forensic trail for DIVD to examine.