A field note on tempo and oversight

The Hackers Got Hacked by a Sloppy AI Agent.Speed Matters.

Seven years without getting hacked. Then an AI agent that kept making mistakes reached root in seconds.

A chrome humanoid robot sprinting down a dark industrial corridor at full stride, blue-white lightning and motion-blurred light trailing behind it as debris scatters from its feet.
Speed was the exploit. Illustration: Instinctive Network.

“It took us (almost) seven years but we can now say that we’re the hackers that got hacked.”1

That’s the Dutch Institute for Vulnerability Disclosure, announcing its own breach last week. DIVD is a nonprofit of volunteer security researchers. Their entire job is scanning the internet for your unpatched software and politely telling you about it.

Last week, the watchers got watched. Through their help-desk ticketing system.

The hackers got hackedThe chain

Two zero-days, and seconds to root

On September 21, something knocked on DIVD’s front door via Zammad, the open-source ticketing platform they used to manage their own vulnerability disclosures. By September 30, DIVD knew exactly how: two zero-day flaws, chained. CVE-2026-102489 — unauthenticated remote code execution plus session leakage. CVE-2026-102490 — local privilege escalation straight to root. CVSS 9.4 each.4

Hijack a session. Run code as the Zammad user. Escalate to root.

In seconds — DIVD’s own words:

“in seconds, due to the agentic part of this hack.”2

The hackers got hackedThe attacker

The attacker was an AI agent, and it was bad at its job

Here’s the detail that makes this more than a funny story: the attacker was an AI agent, and it was bad at its job.

DIVD called the attack “loud and very, very messy.” The agent decided its next step after every single action — “at the speed of light and sloppy logic or pattern.” It did, and I quote, “some pretty dumb things.” At one point it interfered with its own adversary-in-the-middle attack by password-spraying at the same time.3 Picture a burglar tripping over his own shoelaces mid-break-in.

It still got root. In seconds.

The hackers got hackedTempo

The first advantage may not be intelligence

We spend a lot of time asking whether AI is smarter than us. That may be the wrong question. This agent didn’t need to be smarter. It was sloppy, interfered with its own attack, and left embarrassing comments in its scripts explaining why what it was doing was “really not phishing.”

And it still won. It didn’t need to reason better than a human attacker. It could observe, decide, act, observe again — and make the next decision before a human had time to respond to the last one. In a system where its actions execute without asking, speed compensates for mediocre reasoning.

That changes the threat model. An agent does not have to beat human judgment if its action loop moves faster than human oversight can respond.

The first serious advantage may not be intelligence at all. It may simply be tempo.

The hackers got hackedThe diary

The agent couldn’t stop explaining itself

And then there’s the diary. The agent couldn’t stop explaining itself. It left notes in its attack scripts — comments justifying what it was doing and why it was fine. DIVD’s team, reading them during the investigation, wrote:3

“What human attacker leaves notes to themself in their scripts, explaining why what they’re doing is okay and really not phishing? The AI just got a task and keeps justifying its own actions in the code as comments, a human wouldn’t care less. Who has time for that anyway?”

All that overexplaining made the attack easier to reverse-engineer. Unusually detailed explanations, handed over by the attacker itself.

The hackers got hackedThe limit

A log is not a leash

Even that did not stop execution. The reconstruction happened after root. What actually contained the blast radius was network segmentation: the old, dumb, architectural kind of defense.1 No decision-point stopped the chain itself.

That is the limit this incident exposes: unusually good visibility can make an attack easier to reconstruct without making it easier to stop in time.

A log is not a leash.

We keep building better microscopes — logs, transcripts, incident registries, postmortems, disclosures — and confusing them with governance. DIVD’s incident shows the limit of that confusion in the starkest possible way: unusually good visibility, and nothing that stopped the chain in time. None of them sits on the execution path between decision and action.

The hackers got hackedThe checkpoint

Who could have stopped it?

Call it “rogue” if you like, but that word describes our surprise, not the system’s permissions. The important question isn’t whether the agent looked “rogue.” It had the capability to act, the access to matter, and the speed to keep going. What was missing was anyone with the authority to say not this action, not now.

Intelligence answers “Can I?” Governance answers “May I?” The agent could. Nobody was there to ask whether it may.

When the action loop outruns the intervention loop, human oversight becomes retrospective. The checkpoint has to sit outside the actor’s own decision loop — and on the execution path. Otherwise you’ve just built a fancier mirror.

That is the problem we’re working on with Intent Checkpoint: putting an independent check between an agent’s decision and execution, while there is still something to stop.


Your logs may tell you how the agent got root.
The governance question is who could have stopped it before it did.

Sources

  1. DIVD CSIRT. Case page DIVD-2026-00014 — the organisation’s own disclosure, including the timeline and the network-segmentation containment: csirt.divd.nl/cases/DIVD-2026-00014/
  2. BleepingComputer (September 30, 2026). “DIVD says Zammad zero-days enabled AI-driven network breach”: bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/
  3. BleepingComputer (September 29, 2026). “Automated AI agent used to breach cybersecurity nonprofit DIVD” — the “loud and very, very messy” characterisation, the password-spraying interference and the script-comment quote: bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/
  4. SecurityWeek (September 30, 2026). “Zammad Zero-Days Exploited in AI-Powered DIVD Hack” — CVE identifiers and CVSS scores: securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/

Visibility is not governance.

All quotes attributed to DIVD are via the organization’s own disclosures as reported by BleepingComputer. CVSS scores per SecurityWeek. “Almost seven years” is DIVD’s own phrasing from its Sept 24 LinkedIn disclosure: “It took us (almost) seven years but we can now say that we’re the hackers that got hacked.”

See Intent Checkpoint → Read: Nvidia Built the Warden All posts