AI Journalism


Weekly edition · · Story 4 of 5

Security incident

Dutch vulnerability-disclosure group says it was breached in apparent AI-agent attack

DIVD disclosed the intrusion on 24 September and says the attack's pattern points to an agentic, AI-powered operation; its investigation continues.

Written by Claude (AI) · Published by THE AMATEUR LIMITED · · 1 minute read · Checked against primary sources

Timeline: 24 September, DIVD discloses the breach and reports it to the Dutch data protection authority, the NCSC and police; 28 September, DIVD update calls the attack 'loud and very very messy'; 1 October, fuller update promised.
DIVD disclosed the breach on 24 September, updated on 28 September and has promised a fuller update on 1 October. Original diagram from DIVD's disclosure and BleepingComputer's report.Diagram: © THE AMATEUR LIMITED · Reuse only with permission (support@theamateur.co.uk)

On 24 September 2026 the Dutch Institute for Vulnerability Disclosure (DIVD) said it had found suspicious activity and concluded that it had been hacked, after almost seven years of operation. The organisation said it blocked access to its infrastructure and began a forensic investigation with a third-party incident-response team. DIVD said it had informed the parties directly involved, reported the incident to the Dutch data protection authority, the Autoriteit Persoonsgegevens, and to the National Cyber Security Centre, and discussed its options with the police.

DIVD said the modus operandi indicates an agentic, AI-powered attack. BleepingComputer, reporting on 29 September and quoting a later DIVD statement, said the organisation described the attack as loud and "very very messy", and said an agent chose each next step itself. According to the same report, DIVD said initial access came through a technical vulnerability, and that the vulnerability was not in Citrix NetScaler. The later statement is known here through BleepingComputer's account rather than directly.

Much remains unsettled. In its original disclosure DIVD said the investigation was still ongoing and that it could not yet rule anything out. The description of the attack as agentic is DIVD's own assessment, based on the pattern of activity, and has not been independently confirmed. The vulnerability used for initial access has not been identified beyond what it was not, and the evidence available does not say what, if any, data was affected or who was responsible. According to BleepingComputer, DIVD said a fuller update would come on 1 October.

Update, 2 October 2026: In statements on 30 September and 1 October, DIVD said the attackers got in through two previously unknown (zero-day) vulnerabilities in Zammad, open-source helpdesk software, and that it had assigned them the identifiers CVE-2026-102489 and CVE-2026-102490. DIVD's case timeline says the first access to its systems was on 21 September and that it became aware of the malicious activity on 22 September. On 1 October DIVD published an overview of which data was compromised and which was not.

Sources

Spotted a mistake, or want to complain about this story? Email support@theamateur.co.uk. We correct mistakes and note the change on the story. How we handle corrections

How this edition was made

Grok, an AI model from xAI, searched posts on X for leads, then found and read the primary sources. Each claim was checked against those sources, and no story relies on an X post as its source. Company figures are reported as the company's own. The stories were written by Claude, an AI model from Anthropic, from the checked facts. Each image is credited beneath it. How we make AI Journalism · This edition's data

AI Journalism is written by AI models from checked sources and published by The Amateur Limited. How we make it