Security & AI news

AI-driven attacks · By FireAI Security & Research Team · Published

Dutch vulnerability nonprofit DIVD says an autonomous AI agent carried out the post-exploitation phase of its breach

DIVD reports its first breach in seven years: an attacker used an autonomous AI agent after exploiting a flaw, and the agent’s clumsy password spraying made the intrusion noisy.

An AI agent icon and the FireAI detective mascot, next to the words “An AI agent ran the DIVD intrusion.”

The Dutch Institute for Vulnerability Disclosure (DIVD) announced on 29 September 2026 that its systems were breached and that the attacker used an autonomous AI agent for the activity that followed the initial compromise, BleepingComputer reported. DIVD said this was its first breach in seven years of operation [1].

Background

DIVD is a nonprofit that finds vulnerabilities and notifies the organisations that run the affected systems. An intruder's work after the first foothold, called post-exploitation, usually consists of exploring the network, collecting credentials and moving between systems. When an AI agent performs this work it decides each next step itself, without an operator typing commands.

What the report describes

DIVD said the attacker first exploited a vulnerability that it has not disclosed, and it stated explicitly that the flaw was not in Citrix NetScaler. An automated agent then took over. DIVD described the intrusion as noisy and disorderly, and said the agent chose every following action on its own and at high speed, with sloppy logic [1].

As an example of that sloppiness, DIVD reported that the agent's password spraying failed and interfered with the attacker's own attempts. DIVD read this as a sign of poor training and configuration of the agent [1]. That reading is DIVD's inference from the traces, and the report does not give a technical account of how the conclusion was reached.

DIVD said it had notified the Dutch data protection authority, the National Cyber Security Center and the police. It has not said what data was accessed, in order to avoid influencing the investigation or endangering other potential victims. It promised a detailed update on 1 October and said it would notify other organisations exposed to the same vulnerability once it identifies them [1].

Implications for Mac users

The report concerns an institution, and it does not say that personal data of DIVD's contacts was taken [1]. The general point is that an attacker's agent works quickly, and fast automated activity tends to leave traces: repeated failed logins, unusual connections and bursts of traffic. Those traces are most useful when someone looks at them soon after they appear.

Recommendations

  1. Use a unique password for each account and turn on two-step verification, which limits the value of password spraying.
  2. Keep operating systems and internet-facing software updated, as the initial flaw was a known class of entry point.
  3. Review the list of apps and devices that connect from your network from time to time.
  4. For an organisation, watch for many failed logins from one source and alert on them.

Relevance to FireAI

FireAI protects a Mac, not an institution's servers, and it cannot detect a password-spraying campaign against a remote service. On a Mac it shows each app's connections in Activity, the world map shows where they go, and an upload to a country far above its usual rate is flagged as an upload spike. FireAI does not block a spike on its own.

Limitations

The report rests on DIVD's own statement and on one press account. The vulnerability, the data affected and the technical evidence for an autonomous agent are not yet public, and DIVD's promised update of 1 October may change the picture.

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. BleepingComputer, 29 September 2026: Automated AI agent used to breach cybersecurity nonprofit DIVD