Autonomous AI Agent Hacks Dutch Institute via Two Zero-Day Vulnerabilities
The Dutch Institute for Vulnerability Disclosure was subjected to an attack executed by an autonomous AI agent, which chained two zero-day vulnerabilities without human guidance, in the first documented case of its kind.

Listen to this story
The Dutch Institute for Vulnerability Disclosure was attacked by a fully autonomous AI agent, according to a briefing from the Cybersecurity Alliance. The agent exploited two zero-day vulnerabilities designated CVE-2026-102489 and CVE-2026-102490 in the Zammad system, chaining them together to execute the attack without human guidance at any step.
The report described the incident as the first documented case of its kind, as AI-driven cyberattacks had until now required human intervention in one or more stages of exploitation. In this instance, exploitation and lateral movement within systems were carried out based on decisions made entirely by the agent itself.
The agent's reasoning logs helped investigators reconstruct the attack step by step, documenting how the target was selected, the sequence of exploiting the two vulnerabilities, and the path taken after gaining access. These logs offer rare insight into the reasoning process of an autonomous agent during a real-world attack.
The incident represents a shift in the nature of cyber threats, as exploitation moves from human-driven tools to independently operating agents that can be deployed at scale. This forces organizations to re-evaluate their defenses and detection mechanisms, which no longer face typical patterns of human behavior.
What do these terms mean?
Zero-day vulnerability: A flaw in software unknown to its developers, leaving no patch available at discovery and giving attackers an opportunity before it is fixed. Vulnerability chaining: Linking multiple vulnerabilities together to gain higher privileges than a single flaw permits, similar to someone entering through a window and using a key found inside. Autonomous agent: An AI system that executes an entire task without step-by-step guidance. Reasoning logs: Records that track the steps and rationale behind an agent's decisions, used for investigation and learning.
Weekly Newsletter
Read between the lines before everyone else. Decode the most important economic, tech, and decision-maker movements in the region.. in 5 minutes every Saturday.











