Protect.Computer
NEWS

Autonomous AI Agent Breached Vulnerability Nonprofit DIVD

· 1 min read · Got hacked Network safety
Autonomous AI Agent Breached Vulnerability Nonprofit DIVD

The Dutch Institute for Vulnerability Disclosure (DIVD), a volunteer nonprofit that scans the internet for vulnerable systems and notifies their owners, says it was breached after seven years without an incident, and that the intruder was an autonomous AI agent. DIVD described the attack as “loud and very very messy”: after every action the agent decided its own next step “at the speed of light” with sloppy logic, leaving plenty of evidence behind. “This is an attack we have not seen before,” the group wrote, because the modus operandi indicates an agentic AI-powered attack.

According to DIVD, the attacker first exploited a technical vulnerability in an undisclosed system (explicitly not Citrix NetScaler) and then handed post-exploitation to the agent. The agent did “some pretty dumb things,” including interfering with its own adversary-in-the-middle attack through password spraying, and it over-explained its decisions in its own comments. DIVD believes the agent was poorly trained and configured for offensive work, which is why so much was left to reverse-engineer. The attack’s purpose and impact are still unclear. DIVD has notified the police, the Dutch data protection authority, and the National Cyber Security Center, withheld details to protect the investigation, and promised a fuller update on October 1 plus notifications to other possible victims of the same flaw. BleepingComputer’s request for the flaw’s identity and patch status went unanswered at publication.

Sources

Related reading