AI attacks this week: DIVD sees indications of an AI agent in its breach (week 40/2026)

Reporting period: 28 September to 4 October 2026.
DIVD: indications of an AI agent
An attacker first accessed the systems of the Dutch Institute for Vulnerability Disclosure (DIVD) on 21 September, and DIVD noticed the activity on 22 September. This week the organisation set out in its case file how the attack unfolded.
The attackers got in through two previously unknown vulnerabilities in the helpdesk software Zammad. According to DIVD, together they allowed session hijacking, remote code execution and privilege escalation to root on the server. According to DIVD, this enabled the attackers to access other services and exfiltrate data.
DIVD says it knows for sure that volunteer data left the organisation, such as DIVD email addresses and possibly contact details. On 2 October CISA added both flaws (CVE-2026-102489, CVE-2026-102490) to its Known Exploited Vulnerabilities catalog.
Role of AI: DIVD writes that the modus operandi indicates an attack by an AI agent. As evidence it cites notes in the attacker's scripts in which the agent justifies its own actions. According to DIVD, the agent worked automatically and decided each next step itself, quickly and on sloppy logic. DIVD sees no link to a publicly known threat actor.
How well established: The victim itself confirms the breach, and CISA confirms that the flaws were exploited. Attributing the attack to AI is DIVD's assessment based on its own forensics. Which model was involved, and whether the agent found the flaws itself, has not been published.
Victoria: police reports describe voice cloning
Victoria Police in Australia is warning about calls from fake doctors, aimed mainly at Mandarin-speaking people of Chinese background. Ten reports have come in since early September. In two recent cases the victims lost 50,000 and 40,000 Australian dollars.
Role of AI: According to the police, the use of AI voice cloning is described in several reports. In one case the caller mimicked the voice of a professional the victim knew.
How well established: The police confirm the fraud series. The cloned voice rests on what victims reported; the police have not published a finding of their own on it. Whether the two cases with stated losses involved voice cloning remains open.
Custom GPTs as a lure for malware
Huntress describes a campaign in which attackers disguised Custom GPTs on the genuine ChatGPT domain as product offerings. Victims who searched Google for "chatgpt" reached them through a sponsored result. The Custom GPT then sent them on to a supposed backup site. A ClickFix lure got victims to run a PowerShell command themselves, which downloaded a remote access trojan (RAT).
Role of AI: small. Huntress responded to at least 40 incidents linked to the Google Sites domain involved. In two of these, Huntress confirmed that the route included a Custom GPT. The AI platform serves as a trusted backdrop; the target is the person.
Huntress notified OpenAI about the first Custom GPT; according to Huntress, it had been taken down by 25 September. On 27 September Huntress discovered another one linked to the same campaign.
How well established: a technical report from Huntress's incident response. We have not seen a statement from OpenAI.
GitLab: escaping the AI Gateway sandbox
GitLab has fixed a critical flaw in its AI Gateway (CVE-2026-90970, CVSS 9.9); the CVE entry was published on 2 October. An authenticated user with Duo Agent Platform access could use a crafted flow configuration to escape the prompt template sandbox. From there they could run arbitrary commands on the gateway.
Self-hosted AI Gateways are affected; GitLab lists 19.2.4, 19.3.2 and 19.4.1 as fixed versions. According to GitLab, customers using a gateway hosted by GitLab do not need to take action.
How well established: confirmed by the vendor. The vendor's publication provides no information about exploitation.
MCP Python SDK: credentials sent to the wrong server
On 28 September the maintainers of the official Python SDK for the Model Context Protocol (MCP) published an advisory (GHSA-qx49-fqc8-xw99, CVSS 7.5). In affected versions a malicious or compromised MCP server could decide where the client sent its OAuth credentials. The fix is in 1.30.0 and 2.2.0.
Users of ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider must also pass the issuer= parameter after upgrading; otherwise nothing changes. The same project published four more advisories during the week.
How well established: confirmed by the maintainers. Their publication provides no information about exploitation.
What follows, in our view
- Running Zammad? According to DIVD, session hijacking affects versions 6.3.0 to 6.5.4 and privilege escalation all versions. DIVD recommends upgrading to version 7 or taking the system offline.
- Check response times. DIVD noticed the breach one day after first access, and according to DIVD the privilege escalation took seconds. We think it is worth checking how quickly your own detection and response would work against such an attack chain.
- Call-back rule for payments. A familiar voice no longer proves anything. Payment requests made by phone should be verified by calling back a known number.
- Inventory agent tooling. Anyone running self-hosted AI Gateways or the MCP Python SDK should check versions. For MCP, users of the two providers named above must also set issuer after upgrading.
- Update awareness training. A well-known domain such as chatgpt.com is no proof of trust. ClickFix instructions to run commands belong in every training session.
Selection and sources
We include reports in which AI was essential to the attack, as a tool, as a target or for deception. Every statement has been checked against the primary source. We distinguish whether an incident has been confirmed by the victim, an authority or the vendor, or has so far only been reported. We welcome reports of errors and make corrections visible.
