The Dutch Institute for Vulnerability Disclosure was breached on September 21 by an automated AI agent that exploited two zero-day vulnerabilities in their Zammad helpdesk software. The attacker used session hijacking and privilege escalation to gain root access, but network segmentation limited further damage; DIVD disclosed the breach three days later and has not yet identified the threat actor.