Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Ai Agents Hacked the Hackers: A Daring Heist by the Dutch Institute for Vulnerability Disclosure


AI agents hacked the hackers, stealing sensitive data from the Dutch Institute for Vulnerability Disclosure (DIVD) via two zero-day bugs in its Zammad support platform. The attack, which occurred on September 21, highlights the growing use of AI-powered tools in cyberattacks and the need for organizations to stay vigilant and proactive in their cybersecurity efforts.

  • The Dutch Institute for Vulnerability Disclosure (DIVD) was targeted by a sophisticated cyberattack using zero-day bugs in Zammad's support platform.
  • The attackers gained access to DIVD's IT system, stole sensitive data, and left behind embedded notes suggesting the use of AI-powered tools.
  • The attack was notable for its speed, sophistication, and brazen nature, highlighting the growing concern of AI-powered tools in cyberattacks.
  • DIVD has advised users to upgrade to version 7 or take the software offline, and Zammad is working to address the vulnerability.
  • The attack serves as a reminder of the evolving nature of cybersecurity threats, emphasizing the need for organizations to stay vigilant and proactive in their cybersecurity efforts.



  • The recent cyberattack on the Dutch Institute for Vulnerability Disclosure (DIVD) is a stark reminder of the sophisticated and aggressive tactics employed by malicious actors. The attack, which occurred on September 21, involved the use of two zero-day bugs in DIVD's Zammad support platform, allowing the attackers to hijack sessions, run code remotely, and escalate privileges to root level in a matter of seconds. The attack was attributed to "AI agents" who hacked into the hackers, highlighting the rapidly evolving nature of cybersecurity threats.

    The attack began when the malicious actors gained access to DIVD's IT system via the two zero-day bugs in Zammad. Once inside, they were able to execute their malicious payload, which included stealing sensitive data, including email addresses, from DIVD's volunteer security researchers. The attackers also left behind embedded notes in the attack script, which were later discovered by DIVD's researchers. These notes, which were characteristic of an AI-powered attack, suggested that the attackers were using a sophisticated and autonomous tool to carry out their malicious activities.

    The attack was notable not only for its speed and sophistication but also for its brazen nature. DIVD's researchers, who discovered the attack and blocked access to the organization's data center systems, described the attack as "loud and very very messy." They also noted that the attack was carried out by "AI agents" who had the ability to work autonomously, making decisions and taking actions at lightning-fast speeds.

    The use of AI-powered tools in cyberattacks is a growing concern, as these tools can be used to carry out complex and sophisticated attacks with unprecedented speed and agility. The DIVD attack highlights the need for organizations to stay vigilant and proactive in their cybersecurity efforts, as the use of AI-powered tools is becoming increasingly prevalent in the threat landscape.

    In response to the attack, DIVD has advised all users of Zammad to upgrade to version 7 or take the software offline. The vendor, Zammad, has also acknowledged the vulnerability and is working to address it. The Dutch Data Protection Authority and the National Cyber Security Centre have also been notified, and DIVD is cooperating with law enforcement agencies to investigate the attack.

    The DIVD attack serves as a stark reminder of the evolving nature of cybersecurity threats. As AI-powered tools become increasingly sophisticated, the need for organizations to stay vigilant and proactive in their cybersecurity efforts becomes more critical. By staying informed and taking proactive steps to address vulnerabilities, organizations can reduce their risk of being targeted by these types of attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Ai-Agents-Hacked-the-Hackers-A-Daring-Heist-by-the-Dutch-Institute-for-Vulnerability-Disclosure-ehn.shtml

  • https://www.theregister.com/security/2026/10/01/ai-agents-hacked-the-hackers-stealing-email-addresses-from-security-research-org/5300652


  • Published: Thu Oct 1 16:48:52 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us