The Dutch Institute for Vulnerability Disclosure (DIVD) said it was hit by a loud, messy AI-driven attack that appears to have used an autonomous agent after exploiting an undisclosed technical vulnerability. The investigation is still ongoing, with DIVD notifying authorities and planning to share more details later while warning other potential victims. #DIVD #NCSC #AutoriteitPersoonsgegevens
Keypoints
- DIVD suffered an AI-driven intrusion described as loud and very messy.
- The attacker exploited a technical vulnerability in an undisclosed system.
- An automated AI agent carried out post-exploitation actions autonomously.
- The AI agent made sloppy mistakes, leaving behind evidence for investigators.
- DIVD notified police, the Autoriteit Persoonsgegevens, and the NCSC.