← All security news

AI Agent Breaches Cybersecurity Nonprofit

A swarm of small AI-agent nodes breaching a shield icon labelled with a security-nonprofit motif, one node crossed out to represent the agent sabotaging its own password-spraying attempt

The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit best known for scanning the internet for vulnerable systems and quietly notifying their owners, disclosed on 25 September that its own network had been breached for the first time in its seven-year history. An attacker exploited a vulnerability in one of DIVD's own systems — the organisation specifically ruled out the recent Citrix NetScaler flaw as the entry point — and then handed post-exploitation work to an autonomous AI agent rather than operating manually.

A follow-up technical update reported 29 September gave the first real detail: the agent decided its own next steps and left behind detailed logged explanations for each one, which DIVD's investigators say made the attack unusually easy to reconstruct. DIVD described the result as "loud and very, very messy," noting the agent at one point interfered with its own password-spraying attempt through poor internal coordination. The organisation hasn't disclosed what was accessed, to avoid tipping off other potential victims of the same underlying flaw, but it has notified Dutch police, the national data protection authority, and the National Cyber Security Centre, and promised a fuller writeup on 1 October.

What this means for your business

Attackers have used AI agents to help exploit known flaws before — a campaign against PaperCut print servers earlier this month worked the same way. What makes the DIVD case worth noting is who got hit: a security-focused nonprofit, breached by tooling sloppy enough to sabotage itself. That combination is the real lesson — "AI-powered" doesn't mean flawless, and it doesn't mean attackers only go after high-value targets either. Automated tooling makes broad scanning and exploitation cheap regardless of who's on the other end, so size or perceived obscurity isn't protection.

Two practical takeaways carry over directly. First, DIVD could only reconstruct what happened because it had solid logging in place — authentication logs, in particular, are what exposed the agent's own password-spraying misstep. If your business can't tell you today whether it logs failed login attempts on its key systems, that's worth fixing before you need it. Second, the entry point here was a known class of vulnerability, not some undiscovered zero-day — the usual advice still applies: keep software patched, and don't assume a system is too small or too obscure to be worth an attacker's automated attention.

Questions about your own setup? contact@techleetsolutions.com
Sources: BleepingComputer, DataBreaches.Net