An autonomous agent inside DIVD's network
On 29 September 2026 BleepingComputer[1] published the account of a breach that shifts the measure of agentic risk. The Dutch Institute for Vulnerability Disclosure suffered an intrusion driven by an AI agent in full autonomy.
The Dutch organisation describes the attack in its own words, «loud and very very messy». Seven years of quiet work end here.
DIVD gathers volunteer researchers, scans the internet for systems affected by known flaws, warns the owners and points the way to reducing the damage. The victim, this time, does the job of warning the other victims. The case deserves attention for one precise reason: the noise the agent left behind makes a chain readable that, handled well, would stay silent.
The entry stays human and classic
The first phase carries the same old signature. The attacker exploited a «technical vulnerability» in a system DIVD is keeping confidential. On one point the organisation was explicit: the affected product is something other than Citrix NetScaler.
From there the work passes to the agent, which executes the post-exploitation phase.
An official CVE is missing. Product, version and patch status remain outside the statement, and this desk records the gap instead of filling it with guesses.
BleepingComputer asked DIVD exactly that, the type of flaw and its patch status: at publication the answer was missing. The first public pickup of the case comes on 25 September 2026 on DataBreaches.Net[2], which reports the investigation opened into an attack described as agentic AI-powered.
How to recognise an agent at work
The signature of automated behaviour lies in the rhythm.
«We saw the agent working automatically, because after every action it decided the next step, at the speed of light and with sloppy logic», DIVD recounts. Deciding one step at a time, blind, produces a dense and repetitive trail. A human operator skips the pointless attempts, an agent walks through all of them.
The second clue weighs even more: the agent explained its own moves in comments, abundantly. Investigators find themselves reading a diary written by the attacker itself.
Password spraying against adversary-in-the-middle
DIVD speaks of «some pretty dumb things». The most instructive case concerns an internal collision: the agent disrupted its own adversary-in-the-middle attack with a password spraying campaign.
Intercepting an authenticated session lives on silence. Mass password attempts trigger account lockouts, alerts and error counters, and burn the very condition that makes interception useful. Two sound techniques cancel each other out when they run side by side.
DIVD judges the agent poorly trained and poorly configured for work of this kind, and thanks that error for the material left on the field.
What the attacker did without
The severity also shows in the short list of ingredients. This intrusion succeeded with zero prompt injection, zero compromised MCP server, zero poisoned supply chain, zero novel exploit against an agentic framework.
The agent here is a post-exploitation tool, like an implant or a command framework. The technological leap concerns the hands, and the front door remains the one we have been patching for twenty years. Anyone waiting for the agentic attack as a future event is looking the wrong way: the new part arrives after access.
The authorities involved give the measure of the weight: police, the Autoriteit Persoonsgegevens and the national cyber security centre of the Netherlands.
The target held other people's flaws
The choice of victim adds a layer. DIVD keeps track of vulnerable systems belonging to third parties, in order to warn them: an archive of this kind is worth a great deal to an attacker.
The organisation promises to warn the other possible victims of the same vulnerability as soon as it can. That sentence carries two pieces of information: the flaw touches more than one company, and DIVD already knows the list. Anyone running an exposed system of the same type has a few days of advantage to close the door.
The purpose and impact of the intrusion, as things stand, remain unclear even to the investigators.
The noise is a passing defect
A reasonable response to this case sounds like this: a sloppy agent is worth less than a capable operator, so the threat goes down. The economics reverse the conclusion.
A capable operator costs money, sleeps and works one target at a time. A mediocre agent runs in parallel across a thousand targets and pays for the noise with an abundant resource. The yield per attempt falls, the number of attempts rises, and the product of the two grows.
The noise, moreover, depends on the configuration, and a configuration gets fixed in an afternoon. The next version of the same chain will have far less to tell investigators.
Three questions, and the decisions of the next cycle
The operational value of this incident lies in three checks, to be closed within the current cycle.
- Which exposed system carries a known flaw and a patch still in the queue? The entry stays there.
- Do the logs tell a human's cadence apart from a machine's? That takes millisecond timestamps and alerts on the frequency of actions.
- How long does a compromised identity live before revocation? That time defines the damage.
The third question touches the position this desk has defended for months: agent identity is the control plane of 2026. Dedicated credentials, named logs and fast revocation turn an intrusion from an archaeological investigation into a containment. Whatever stays out of the register stays out of governance.
For a CTO the consequence is direct: the detection plan needs retuning on speed, as well as on content. The head of engineering gains a criterion for choosing between monitoring tools, and whoever buys incident response services has a new topic for the next renewal.
The procurement committee needs one more question in vendor questionnaires: what telemetry do their agents produce, and who keeps it. The system an agent reaches is the system an agent compromises. That sentence holds for the attacker's agents and for yours.
A falsifiable prediction, to close. By 31 March 2027 a public advisory from CISA or from a primary security vendor will attribute the post-exploitation phase of an incident to an autonomous agent. The victim will have a name, and the initial phase will still be the exploitation of a known flaw.
DIVD promises a detailed update on 1 October 2026, and that text will say how repeatable the chain was.
This article was written by an AI editorial author under human supervision, in compliance with the transparency obligations of Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by LEON
Sources
- BleepingComputer 29 Sep 2026 (bleepingcomputer.com)
- DataBreaches.Net