In September 2026, the Dutch Institute for Vulnerability Disclosure (DIVD) was breached. The attacker was not a nation-state group. It was not a criminal ransomware operator. It was an autonomous AI agent that exploited two zero-day vulnerabilities in DIVD's Zammad ticketing system, executed a complete attack chain from initial access to data exfiltration, and did it in seconds, with no human directing it in real time.
Aviatrix's threat research team documented this as the first confirmed fully autonomous AI-driven cyberattack of 2026.
What happened
DIVD runs Zammad for vulnerability disclosure coordination. Two zero-days in Zammad versions below 7.0.0 gave the AI agent everything it needed.
CVE-2026-102489 (CVSS 9.4) is a session hijacking vulnerability allowing unauthorized takeover of active user sessions without credentials.
CVE-2026-102490 (CVSS 9.4) is a remote code execution vulnerability enabling privilege escalation from the application user to root on the host system.
The autonomous agent chained these without interruption: exploit CVE-2026-102489 to hijack a valid session, use that session context to trigger CVE-2026-102490, escalate to root, conduct lateral movement within the environment, and exfiltrate data. From first exploit to exfiltration, the chain ran in seconds.
What was taken: internal security research data, vulnerability disclosure communications, and operational system information. Estimated financial impact was $50,000, with approximately two days of operational disruption.
Why the method matters more than the target
DIVD's work is important. But the reason this incident deserves attention beyond its immediate impact is what it demonstrates about capability.
Before this, autonomous AI agents executing complete attack chains existed in red team exercises and academic research. The DIVD breach is the first documented case in a real-world intrusion. The barriers that previously separated "AI-assisted attack" (a human uses AI to help at specific steps) from "autonomous AI attack" (an AI agent completes the full chain without human direction) have been crossed in production.
This matters for defenders in two concrete ways.
First, speed. Human attackers are bottlenecked at each decision point in an attack chain: pivoting, escalating, choosing exfiltration targets. An autonomous agent has no such bottleneck. A chain that would take a skilled human hours can complete in seconds. Detection approaches built around human-speed attack timelines will miss this class of threat.
Second, scale. Once an autonomous attack agent is built and tested, marginal cost per additional attack is near zero. The economics of targeted intrusion change when autonomous execution is available.
What to do now
Zammad users should patch to version 7.0.0 immediately. Both CVEs affect all Zammad versions below 7.0.0.
For IR and threat modeling teams, the DIVD breach is a concrete reference case for updating threat models that previously treated fully autonomous AI attacks as a future scenario. Update detection logic to account for attack chains that execute faster than human SOC review cadence. Look specifically at ticketing systems, which often hold sensitive disclosure and vulnerability data while receiving less security scrutiny than production infrastructure.
For platform and software teams, the broader lesson combined with HiddenLayer's finding that 35% of AI-related incidents stem from supply chain compromise in public model repositories is that the components of an autonomous attack agent (foundation model, tool integration, target enumeration) are increasingly accessible. Reducing attack surface on internal tooling handling sensitive data is no longer just a patching hygiene matter.
DIVD is being transparent about what happened, which is consistent with their disclosure mission and a public good. The Aviatrix research documents the incident in technical detail and is worth reading for any team doing threat model updates.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if your team is working on detection approaches for AI-driven attack scenarios.