An autonomous AI agent breached the Dutch Institute for Vulnerability Disclosure (DIVD) by chaining two previously unknown vulnerabilities in the Zammad helpdesk platform, hijacking an authenticated session and escalating to root access within seconds. DIVD, a volunteer-run nonprofit whose Zammad software is used by over 2,000 organizations, said network segmentation prevented the intrusion from spreading further, though some unauthorized access was confirmed. The agent left extensive self-explanatory comments in its own code and made several operational mistakes, including an uncoordinated password-spraying attempt that disrupted its own credential harvesting. It is the second publicly disclosed, fully autonomous AI-agent-driven breach in under three months.