DIVD suffers from a self-threat type of attack; the first case of AI driving attacks on security organizations
2026-10-06 18:03:02
CoinMeta Data: On September 21, 2026, DIVD (a Dutch vulnerability disclosure research institute) was subjected to an attack initiated by its own threat actors. This is the first publicly recorded attack on a security organization launched by autonomous AI proxies. The attackers exploited two zero-day vulnerabilities in the open-source ticketing platform Zammad used internally by DIVD, and quickly gained full control of the host. This incident exposed volunteer data, including email addresses and contact information from DIVD. Network segmentation measures limited the attackers' ability to penetrate deeper into DIVD's infrastructure; nonetheless, DIVD acknowledges that some damage was caused. CISA has listed these two vulnerabilities in the catalog of known exploited vulnerabilities and has required federal agencies to fix them within 14 days.
Bullish 0
Bearish 0
Source:Forkast
This content is for market information only and does not constitute investment advice.