Weekly edition · · Story 4 of 5
Security incident
Dutch vulnerability-disclosure group says it was breached in apparent AI-agent attack
DIVD disclosed the intrusion on 24 September and says the attack's pattern points to an agentic, AI-powered operation; its investigation continues.

On 24 September 2026 the Dutch Institute for Vulnerability Disclosure (DIVD) said it had found suspicious activity and concluded that it had been hacked, after almost seven years of operation. The organisation said it blocked access to its infrastructure and began a forensic investigation with a third-party incident-response team. DIVD said it had informed the parties directly involved, reported the incident to the Dutch data protection authority, the Autoriteit Persoonsgegevens, and to the National Cyber Security Centre, and discussed its options with the police.
DIVD said the modus operandi indicates an agentic, AI-powered attack. BleepingComputer, reporting on 29 September and quoting a later DIVD statement, said the organisation described the attack as loud and "very very messy", and said an agent chose each next step itself. According to the same report, DIVD said initial access came through a technical vulnerability, and that the vulnerability was not in Citrix NetScaler. The later statement is known here through BleepingComputer's account rather than directly.
Much remains unsettled. In its original disclosure DIVD said the investigation was still ongoing and that it could not yet rule anything out. The description of the attack as agentic is DIVD's own assessment, based on the pattern of activity, and has not been independently confirmed. The vulnerability used for initial access has not been identified beyond what it was not, and the evidence available does not say what, if any, data was affected or who was responsible. According to BleepingComputer, DIVD said a fuller update would come on 1 October.
Update, 2 October 2026: In statements on 30 September and 1 October, DIVD said the attackers got in through two previously unknown (zero-day) vulnerabilities in Zammad, open-source helpdesk software, and that it had assigned them the identifiers CVE-2026-102489 and CVE-2026-102490. DIVD's case timeline says the first access to its systems was on 21 September and that it became aware of the malicious activity on 22 September. On 1 October DIVD published an overview of which data was compromised and which was not.
Sources
- Primary DIVD CSIRT, It was a matter of when, not if, 24 September 2026
- Primary DIVD newsroom, same disclosure
- Independent report BleepingComputer, automated AI agent used to breach DIVD, 29 September 2026
- Primary DIVD CSIRT, case DIVD-2026-00014 statements and timeline, 30 September and 1 October 2026
- Independent report Help Net Security, DIVD agentic AI attack, 1 October 2026
Spotted a mistake, or want to complain about this story? Email support@theamateur.co.uk. We correct mistakes and note the change on the story. How we handle corrections
How this edition was made
Grok, an AI model from xAI, searched posts on X for leads, then found and read the primary sources. Each claim was checked against those sources, and no story relies on an X post as its source. Company figures are reported as the company's own. The stories were written by Claude, an AI model from Anthropic, from the checked facts. Each image is credited beneath it. How we make AI Journalism · This edition's data
AI Journalism is written by AI models from checked sources and published by The Amateur Limited. How we make it
