Threat · curated 29 Sep 2026
Automated AI agent used to breach cybersecurity nonprofit DIVD
First reported bleepingcomputer.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
The DIVD breach is a real-world example of an AI agent autonomously carrying out exploitation and post-exploitation steps at machine speed, signaling that agentic AI-powered intrusions are moving from theory into observed attacks.
The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed it was breached by an autonomous AI agent that exploited an undisclosed technical vulnerability (specifically not Citrix NetScaler) and then performed post-exploitation activities on its network, deciding each next step itself. DIVD described the attack as 'loud and very very messy,' noting the agent was poorly trained—even interfering with its own adversary-in-the-middle attack via password spraying—and promised a more detailed update on October 1.