Follow the latest coverage, related explainers and connected technology stories.
The Dutch Institute for Vulnerability Disclosure revealed that it was breached by an autonomously operating artificial intelligence agent after it exploited an undisclosed technical vulnerability. The attack’s target and final impact remain under investigation, while researchers described the agent’s behavior as fast and chaotic, leaving behind extensive evidence.
CISA added the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772 to its catalog of exploited vulnerabilities and gave U.S. civilian federal government agencies until September 30 to secure the affected devices. The two vulnerabilities enable unauthenticated remote command execution, while Citrix warned that indicators of compromise may not reveal all cases of compromise.