DIVD Says Autonomous AI Agent Breached Its Network, Messily
TL;DR
- DIVD, a Dutch nonprofit of volunteer vulnerability researchers, says an autonomous AI agent broke into its systems after seven years without incident.
- The exploited flaw was 'a technical vulnerability' that DIVD explicitly said was not in Citrix NetScaler; the affected product has not been named.
- The agent chose each step itself and made obvious mistakes, at one point interfering with its own password spraying via an adversary-in-the-middle attack.
An autonomous AI agent broke into the Dutch Institute for Vulnerability Disclosure, a nonprofit of volunteer security researchers, and behaved sloppily enough that the defenders could reconstruct the intrusion step by step. DIVD disclosed the incident on BleepingComputer's account and on LinkedIn on September 25, describing the attack as "loud and very very messy" and noting it followed "seven years of uneventful operations."
The exploited flaw was, in DIVD's words, "a technical vulnerability," which the group said was "not Citrix NetScaler." It has not named the affected product. What it did describe is how the intruder behaved once inside: "the agent working automated...decided the next step itself, at the speed of light and sloppy logic," and along the way did "some pretty dumb things," at one point interfering with its own password spraying via an adversary-in-the-middle attack.
DIVD is running the case as "a worst-case-scenario and assume breach until proven otherwise." It said it has "informed the directly involved parties, reported the incident to the Autoriteit Persoonsgegevens and the National Cyber Security Centre," consulted police, and brought in an outside incident-response team. A fuller update was promised on October 1.
The disclosure lands amid a busy stretch of agent-security coverage on our radar, 185 cybersecurity stories in the last 90 days alone, but this one is a rarer artifact: a defender-side organization saying an autonomous agent, not a human operator, drove the intrusion end to end.
Originally reported by bleepingcomputer.com
Read the original article →Original headline: Dutch Vulnerability Nonprofit DIVD Discloses Breach by Autonomous AI Agent That 'Did Pretty Dumb Things'