The DIVD breach shows how autonomous agentic activity can accelerate an intrusion after initial access, even when the attacker’s actions remain noisy, inconsistent, and imperfect.
DIVD identified two Zammad zero-days as the entry point and observed autonomous decision-making, extensive agent commentary, and password-spraying activity during the intrusion.
Defenders should correlate suspicious execution, authentication attempts, and network activity, validating attacker commentary against system evidence rather than dismissing failed actions.
Hexnode XDR supports process investigation and analyst-led containment, while Hexnode UEM can help identify endpoint compliance gaps alongside separate vulnerability and identity remediation.
The DIVD breach highlights how attackers can use autonomous agents after gaining access to an organization. The Dutch Institute for Vulnerability Disclosure says its investigation indicates an agentic AI attack. Investigators observed rapid decisions, inconsistent actions, and extensive comments that helped reconstruct the intrusion.
For security administrators and SOC teams, the incident raises a practical concern: noisy activity still demands urgent investigation. An attacker’s mistakes can create useful evidence without eliminating the threat. Teams should prepare to investigate suspicious execution, authentication attempts, and network activity together.
What happened in the DIVD breach?
DIVD’s case timeline places the attacker’s first access on September 21, 2026. The organization detected malicious activity the following day, blocked access to its datacenter systems, and started a forensic investigation with Merlon Security.
Its initial public statement described the attack as potentially agentic and confirmed an ongoing investigation. DIVD reported the incident to the Dutch data protection authority and National Cyber Security Centre, and discussed its options with police.
DIVD’s September 30 update identifies two Zammad zero-days as the entry point. CVE-2026-102489 enabled session hijacking leading to code execution as the Zammad user. CVE-2026-102490 allowed that local user to escalate privileges to root. DIVD assigns individual CVSS scores of 8.7 and 8.5, respectively, and rates the chained attack at 9.4.
According to DIVD, the attackers chained these flaws to reach root privileges within seconds. Their subsequent noisy, inconsistent behavior did not prevent rapid server compromise. DIVD credits network segmentation and incident response with preventing deeper access to its environment.
Featured Resource
Cybersecurity kit
Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.
DIVD described an agent that selected its next action after each preceding step and documented its decisions extensively. Investigators also observed password spraying that interfered with the agent’s own adversary-in-the-middle activity. These observations support DIVD’s assessment of automated activity, although its investigation remains ongoing.
Password spraying involves testing one password, or a small selection, against multiple accounts. Security teams should examine authentication failures across users and services when investigating this behavior. Looking only at repeated failures against one account can miss the broader pattern.
The available disclosures do not establish that AI independently discovered the vulnerabilities or planned every stage of the intrusion. They describe autonomous activity within an attack whose preparation, operator involvement, and full consequences still require investigation.
Detection lessons from the DIVD breach
The practical lesson is to prioritize observable behavior. Investigators should connect suspicious commands, child processes, outbound connections, and authentication events into a timeline. An agent’s commentary may provide context, but defenders should validate those statements against system evidence.
Review incidents that combine repeated failures with occasional success. A messy sequence can still include a successful login or damaging command. Treat unsuccessful actions as investigative context, rather than evidence that the overall intrusion failed.
During response exercises, assign clear ownership for endpoint containment, account investigation, and affected application recovery. Test whether responders can preserve evidence while acting quickly. Measure the time between confirming malicious activity and initiating containment.
How Hexnode supports endpoint investigation and response
Hexnode XDR gives analysts process context for investigating detected threats. Its process view shows related parent and child processes, while technical details include command lines and file hashes. Analysts can use this information to examine suspicious execution and determine which processes require intervention.
Administrators can initiate Isolate Device to restrict network access while maintaining connectivity to the Hexnode XDR console. Kill Process / Kill Process Tree stops a selected process or its execution branch. Quarantine File moves a malicious file into restricted, encrypted storage. These actions support analyst-led containment; they do not establish detection of the specific DIVD exploit.
Hexnode UEM complements response through device compliance policies. Administrators can configure supported criteria for OS versions, missing applications, and encryption status, then identify devices that violate those requirements. Teams should address the exploited application and compromised accounts alongside endpoint investigation and containment.
Zammad is a web-based helpdesk platform that supports Linux deployments. Hexnode’s endpoint investigation and containment capabilities complement separate protection for the application server. Server administrators must address application vulnerabilities through patching and network segmentation, with appropriate WAF rules providing supplementary protection. Endpoint containment does not patch Zammad or resolve its server-side vulnerabilities.
FAQs
What does an agentic AI attack mean in cybersecurity?
An agentic AI attack involves automated systems that can select and execute subsequent actions based on the results of earlier steps. In the DIVD breach, investigators observed rapid decision-making and extensive commentary, but the available evidence does not establish that AI independently discovered the vulnerabilities or planned the entire intrusion.
Which vulnerabilities were used in the DIVD breach?
DIVD’s September 30 case update identifies CVE-2026-102489 and CVE-2026-102490 in Zammad as the initial entry point. The accompanying advisory describes remote code execution and local privilege escalation vulnerabilities.
Prepare for rapid, imperfect attacks
The DIVD breach offers a concrete reason to rehearse response to rapid, inconsistent attacker activity. Prioritize actionable evidence, preserve investigation records, and establish clear containment decisions. Keep vulnerability remediation, identity response, and endpoint investigation coordinated. An attacker does not need flawless automation to create an incident that demands immediate attention.
Strengthen AI-Driven Threat Response
Detect autonomous attack activity, investigate endpoint behavior, and contain emerging threats faster with Hexnode XDR.
Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.