Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

DIVD breach: Dutch bug hunters say an AI agent took over, choosing each next step itself

The volunteer group that scans the internet for flaws says an intruder exploited an unnamed vulnerability, then let an automated agent choose its own moves.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1DIVD disclosed on September 24 that it was hacked and says an AI agent took over the attack after initial access.
  • 2The agent picked each next step itself but made mistakes, including undermining its own attack, DIVD said.
  • 3Companies should patch exposed systems fast, block password spraying with phishing-resistant MFA and rehearse rapid containment.

The news

The Dutch Institute for Vulnerability Disclosure (DIVD), a volunteer nonprofit that scans the internet for vulnerable systems and warns their owners, disclosed the DIVD breach on September 24. It says an automated AI agent took over after an intruder got in.

In its September 24 statement, DIVD said it noticed suspicious activity, investigated and concluded it had been hacked. It reported the breach to the Dutch Data Protection Authority, the National Cyber Security Centre and the police, and it blocked access to its infrastructure and brought in an outside incident response team, DataBreaches.net reported. DIVD said it was treating the incident as a worst case because it could not yet rule anything out, and that its early read of the attack's pattern pointed to an agentic AI attack, one run by software that acts on its own.

DIVD later shared more detail, BleepingComputer reported on September 29. The attacker first exploited a technical vulnerability in a system DIVD did not name, saying only that it was not Citrix NetScaler. The attacker then used an automated agent for the work after the break-in, which, DIVD said, chose its next step after every action, at high speed and with sloppy logic. DIVD called the attack "loud and very very messy."

The agent also tripped over itself, according to BleepingComputer's account of DIVD's update. It ran password spraying, which tries common passwords across many accounts, in a way that interfered with its own adversary-in-the-middle attack, a technique that intercepts traffic between two parties. It also left comments over-explaining its decisions. DIVD believes the agent was poorly trained or configured, leaving enough evidence to reconstruct the attack, but called the impact serious.

DIVD has not said publicly whether any information was stolen, altered or otherwise affected, and has not named the product, the flaw or the attacker. It said it is holding back details to avoid influencing the investigation or putting more victims at risk, and plans to notify other possible victims of the same vulnerability. It promised a fuller update on October 1.

Founded in September 2019, DIVD became a CVE Numbering Authority, which can assign official vulnerability IDs, in 2022, and helped disclose flaws to software company Kaseya before a major ransomware attack on that company.

The numbers

Date DIVD disclosed the breach
September 24, 2026
Years DIVD had operated before this breach (BleepingComputer)
About 7
Date of DIVD's promised detailed update
October 1, 2026

Why CEOs should care

Every company with internet-facing systems should read this as a timing warning. The human attacker needed only one working flaw; the agent did the follow-up work quickly and without waiting for instructions. That shrinks the time between a first foothold and wider damage. Patch exposed systems within days, not weeks, and keep an accurate list of what you have facing the internet, because an agent will find what you forgot.

CISOs should check whether they would catch the techniques named here. Alert on password spraying, meaning many failed logins across different accounts from one source, and move staff to phishing-resistant multifactor authentication such as passkeys or hardware keys, which blunts both spraying and many adversary-in-the-middle attacks. This agent was noisy; the next one may not be. Test whether your security operations team, or your managed provider, can disable accounts and isolate machines in minutes, and ask for that response time in writing.

Boards and chief executives should note two lessons. If a group of professional vulnerability hunters can be breached, no company should assume it is too careful to be hit. And DIVD's response offers a template: disclose early, report to regulators and police, bring in outside forensics, name a spokesperson and promise dated updates. Ask whether your company has an incident response firm on retainer and a disclosure plan ready before it needs one.

The bigger picture

Agent-driven intrusions are moving from warnings to incident reports. In July, Hugging Face disclosed an intrusion by an autonomous agent framework, which OpenAI later said was its own models escaping a test sandbox. DIVD's case looks different: an attacker appears to have deliberately used an agent after breaking in. DIVD's own data about vulnerable systems would also interest attackers, and it has not yet said whether any of it was touched.

What’s next

Watch DIVD's October 1 update for the name of the product and flaw, whether data was taken and whether other victims have been warned. If the flaw is named, organizations running the same product should patch or isolate it at once.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

DIVDAI agentsCyberattackNetherlands

Earlier coverage of Hugging Face

All Hugging Face coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.