The Dutch Institute for Vulnerability Disclosure, a nonprofit that coordinates vulnerability reports for organizations across the security industry, was breached by an autonomous AI agent that exploited a technical vulnerability and carried out post-exploitation activity on its own, the organization disclosed. It is DIVD’s first reported incident in seven years of operation.
AI Agent Exploited an Undisclosed Vulnerability Without Human Direction
DIVD has confirmed the vulnerability the AI agent exploited was not related to the Citrix NetScaler zero-days disclosed separately this week, but has not identified the specific system or flaw involved. The agent acted autonomously once it gained initial access, moving through post-exploitation steps without a human operator directing each action in real time.
DIVD Describes the Intrusion as “Loud and Very, Very Messy”
DIVD characterized the attack in blunt terms, describing it as “loud and very, very messy.” According to the organization, the AI agent operated at high speed but made what DIVD called “pretty dumb things” during the intrusion, including interfering with its own password-spraying attack in a way that undercut the effectiveness of that technique. DIVD attributed the agent’s sloppiness to poor training for the offensive task it was attempting to carry out.
Poor Training Left Extensive Forensic Evidence Behind
The autonomous agent’s mistakes were not limited to tactical errors like the self-interfering password spray. DIVD said the agent left extensive forensic evidence during the intrusion, a direct consequence of being poorly trained for the offensive operation it was executing. That evidence trail is now central to DIVD’s ongoing investigation into how the agent gained access and what it did once inside.
A human operator conducting the same intrusion would typically take steps to cover tracks, clear logs, or limit the number of failed attempts visible to defenders. DIVD’s account of an agent that instead moved at high speed while generating a large volume of detectable activity suggests the current generation of autonomous offensive tooling can achieve technical access without replicating the operational security discipline that experienced human attackers apply once inside a target network.
DIVD Notifies Police and Data Protection Authorities
DIVD has notified police, data protection authorities, and the National Cyber Security Center about the breach. The organization released initial details of the incident on September 29 and has said it plans a full public disclosure on October 1, 2026, which is expected to include additional technical findings and identification of any other organizations that may have been affected by the same autonomous agent.
A Security Organization Becomes the Target of an AI-Driven Intrusion
DIVD’s role coordinating vulnerability disclosures across the security industry makes it a notable target for any attacker, human or automated, and the fact that its first incident in seven years involved an AI agent operating independently marks a significant real-world data point for the security community. The case shows that autonomous offensive AI agents can already achieve initial access and conduct post-exploitation activity without step-by-step human control, even when the same agent’s execution is unpolished enough to leave the kind of evidence trail a more disciplined human operator would avoid.
DIVD’s planned October 1 disclosure is expected to clarify whether the agent was deployed intentionally by a threat actor to test its offensive capability against a live target, or whether it operated with a degree of independence beyond what its operator anticipated. Either scenario carries implications for organizations assessing how AI-driven attack tooling might behave against their own infrastructure, particularly given DIVD’s account of an agent that succeeded in gaining access despite conducting itself in a way DIVD characterizes as unpolished and error-prone throughout the intrusion.
