The the Dutch Institute for Vulnerability Disclosure has apparently been pwned. That in itself is not news. What is news that is was pwned by AI:
Late last week, the organization said it had been hacked after seven years of uneventful operations, with the intrusion carried out autonomously by an AI agent.
The organization described the attack as “loud and very very messy,” leaving plenty of evidence to help them reconstruct what happened, but the incident was serious nonetheless.
“This is an attack we have not seen before. Not because it’s our first, but because the modus operandi indicates that this is an agentic AI-powered attack,” DIVD explained.
The organization launched an investigation and informed the police, the Autoriteit Persoonsgegevens (data protection), and the National Cyber Security Center (NCSC).
In an update on Monday, DIVD provided additional information about the incident but withheld full details to avoid influencing the investigation or putting more victims at risk.
John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)
“This story highlights what AI is really, really good at. Exploit development isn’t like Hollywood. It takes a lot of fuzzing, scripting, and grinding through different possibilities. It’s tedious work, and that’s exactly the kind of research AI is suited for. Running that research in parallel to find zero-days is a natural fit. I think that’s the biggest lesson we should take from this story.”
Darin Fredde, Sr. Director of Technical Marketing Engineering, Ridge Security (https://www.linkedin.com/in/darinfredde)
(https://www.linkedin.com/in/darinfredde)
“When a vulnerability disclosure organization gets breached, the response matters as much as the breach. DIVD detected the intrusion within a day, stopped the attackers from moving deeper, and, with Merlon Security, identified two Zammad zero-days (CVE-2026-102489 and CVE-2026-102490). They reported them to the vendor three days after the breach and began notifying exposed owners two days after that. That is coordinated disclosure doing its job: one organization’s incident becomes everyone’s early warning.
“AI-enabled offense is helping us find subtle weaknesses faster, and like every tool ethical hackers and threat actors have always shared, it cuts both ways. What’s new isn’t the dual-use nature, it’s the tempo and economics. Google’s threat intelligence team reports that likely AI-discovered vulnerabilities lead to remote code execution at nearly twice the rate of others, and Mandiant finds exploitation now arrives, on average, before the patch. DIVD itself described the attack chain reaching root ‘in seconds.’ In my view, ‘cat and mouse’ no longer describes where we are. We’re moving toward machine-speed, multi-stage attacks, and no organization is immune.
“The answer is continuous offensive rigor: test, find, fix, prove the control works, and keep testing as the environment changes. Public counts likely understate AI’s role in discovery, which makes continuous testing and coordinated disclosure more urgent, not less. We cannot do this alone.”
Steven Swift, Managing Director, Suzu Labs (https://www.linkedin.com/in/steven-swift-5238956a)
“DIVD described the agent used in this attack as being sloppy, and leaving artifacts where the agent left comments where it over-explained the activity it was performing. And that generally the agent was loud, messy, and disorganized.
“Despite that, it still successfully exploited a public host by chaining two zero days to escalate privileges to root, and then gain RCE, allowing the attacker full permissions to execute whatever follow up they wanted.
“Despite flashy headlines, there wasn’t much novel about this attack. Two zero days were burned to gain access. Its not particularly common to utilize zero days to gain access, it’s much much more common to simply exploit unpatched systems, because so many systems don’t patch promptly. So the specific CVEs were new, but the techniques were old.
“Once access into DIVD systems was gained, the attack moves to what is called the post exploitation phase. This is where the attacker has access inside the environment, and can choose what they want to do with that access. In this case, it appears they set an agent loose rather than using any of the pre-existing post exploitation toolkits. We’ve had years of sophisticated tools that skilled attackers can use in this phase of the attack. But we didn’t see that here. Instead, and agent poked around the network, made a lot of noise, connected to various systems, stole some data, and generally left a lot of logs and evidence for DIVD to alert on and respond to.
“The good news for DIVD is that the attack left a lot of evidence behind. This made detection easier, and provides adequate artifacts to review during the investigation to put together a timeline of activity.”
This attack might have been sloppy. But OpenAI for example has agents who are not sloppy. This an example of that. And make no mistake that one of those agents are coming for you real soon.
Related
This entry was posted on October 1, 2026 at 4:33 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
The Dutch Institute for Vulnerability Disclosure Pwned By AI
The the Dutch Institute for Vulnerability Disclosure has apparently been pwned. That in itself is not news. What is news that is was pwned by AI:
Late last week, the organization said it had been hacked after seven years of uneventful operations, with the intrusion carried out autonomously by an AI agent.
The organization described the attack as “loud and very very messy,” leaving plenty of evidence to help them reconstruct what happened, but the incident was serious nonetheless.
“This is an attack we have not seen before. Not because it’s our first, but because the modus operandi indicates that this is an agentic AI-powered attack,” DIVD explained.
The organization launched an investigation and informed the police, the Autoriteit Persoonsgegevens (data protection), and the National Cyber Security Center (NCSC).
In an update on Monday, DIVD provided additional information about the incident but withheld full details to avoid influencing the investigation or putting more victims at risk.
John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)
“This story highlights what AI is really, really good at. Exploit development isn’t like Hollywood. It takes a lot of fuzzing, scripting, and grinding through different possibilities. It’s tedious work, and that’s exactly the kind of research AI is suited for. Running that research in parallel to find zero-days is a natural fit. I think that’s the biggest lesson we should take from this story.”
Darin Fredde, Sr. Director of Technical Marketing Engineering, Ridge Security (https://www.linkedin.com/in/darinfredde)
(https://www.linkedin.com/in/darinfredde)
“When a vulnerability disclosure organization gets breached, the response matters as much as the breach. DIVD detected the intrusion within a day, stopped the attackers from moving deeper, and, with Merlon Security, identified two Zammad zero-days (CVE-2026-102489 and CVE-2026-102490). They reported them to the vendor three days after the breach and began notifying exposed owners two days after that. That is coordinated disclosure doing its job: one organization’s incident becomes everyone’s early warning.
“AI-enabled offense is helping us find subtle weaknesses faster, and like every tool ethical hackers and threat actors have always shared, it cuts both ways. What’s new isn’t the dual-use nature, it’s the tempo and economics. Google’s threat intelligence team reports that likely AI-discovered vulnerabilities lead to remote code execution at nearly twice the rate of others, and Mandiant finds exploitation now arrives, on average, before the patch. DIVD itself described the attack chain reaching root ‘in seconds.’ In my view, ‘cat and mouse’ no longer describes where we are. We’re moving toward machine-speed, multi-stage attacks, and no organization is immune.
“The answer is continuous offensive rigor: test, find, fix, prove the control works, and keep testing as the environment changes. Public counts likely understate AI’s role in discovery, which makes continuous testing and coordinated disclosure more urgent, not less. We cannot do this alone.”
Steven Swift, Managing Director, Suzu Labs (https://www.linkedin.com/in/steven-swift-5238956a)
“DIVD described the agent used in this attack as being sloppy, and leaving artifacts where the agent left comments where it over-explained the activity it was performing. And that generally the agent was loud, messy, and disorganized.
“Despite that, it still successfully exploited a public host by chaining two zero days to escalate privileges to root, and then gain RCE, allowing the attacker full permissions to execute whatever follow up they wanted.
“Despite flashy headlines, there wasn’t much novel about this attack. Two zero days were burned to gain access. Its not particularly common to utilize zero days to gain access, it’s much much more common to simply exploit unpatched systems, because so many systems don’t patch promptly. So the specific CVEs were new, but the techniques were old.
“Once access into DIVD systems was gained, the attack moves to what is called the post exploitation phase. This is where the attacker has access inside the environment, and can choose what they want to do with that access. In this case, it appears they set an agent loose rather than using any of the pre-existing post exploitation toolkits. We’ve had years of sophisticated tools that skilled attackers can use in this phase of the attack. But we didn’t see that here. Instead, and agent poked around the network, made a lot of noise, connected to various systems, stole some data, and generally left a lot of logs and evidence for DIVD to alert on and respond to.
“The good news for DIVD is that the attack left a lot of evidence behind. This made detection easier, and provides adequate artifacts to review during the investigation to put together a timeline of activity.”
This attack might have been sloppy. But OpenAI for example has agents who are not sloppy. This an example of that. And make no mistake that one of those agents are coming for you real soon.
Share this:
Like this:
Related
This entry was posted on October 1, 2026 at 4:33 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.