The Thread
The common thread in the recent breach log is not the target, but the entry point. Bitget lost $387.5 million after a zero-day in third-party security products, the Dutch Institute for Vulnerability Disclosure was breached by an automated AI agent, and analysts are warning that agentic security itself is shrinking the window defenders have to react. In each case the attacker did not defeat the victim's own defenses; the attacker used the victim's trusted tools, agents or credentials to walk through them.
The Perimeter Moved Into the Supply Chain
Bitget's disclosure, as BleepingComputer reported, is the clearest example. The exchange lost $387.5 million last week, and the attackers got in by exploiting a zero-day flaw in third-party security products. That detail matters more than the dollar figure. Security vendors sell themselves as the layer that catches what everything else misses, which is why their software is granted privileged access across customer environments. A zero-day in that layer converts a defensive purchase into an offensive foothold, and it does so across every customer running the vulnerable product at once.
For US technology companies, the practical consequence is that vendor risk is no longer a procurement formality. A single upstream flaw can compromise an entire customer base before any individual security team has a signature or a patch. The exposure is not proportional to how well a company hardens its own network; it is proportional to how much privileged software it has installed from someone else.
The Attacker Is Now Automated
DIVD's experience, also reported by BleepingComputer, adds a second dimension. The nonprofit described the AI-driven attack as "loud and very, very messy," which is a useful description because it inverts the usual assumption that sophisticated intrusions are quiet. An automated agent does not need to be stealthy to succeed. It needs to be fast, persistent and cheap enough to run repeatedly.
That changes the economics of defense. Human attackers scale with headcount and patience. Automated agents scale with compute. A small organization like DIVD, which exists to disclose vulnerabilities in the public interest, has neither the budget nor the staff to absorb a high-volume, low-finesse assault that never tires. The same asymmetry applies to any US company whose security operations center is staffed for human-paced threats.
Agents Act on Legitimate Instructions
SiliconANGLE's analysis of agentic security strategy supplies the third piece. The point there is not that agents are malicious, but that they can act on legitimate instructions in unexpected ways. An agent with credentials can call tools and choose its own route toward a goal, and that expands the number of paths security teams must monitor. The risk materializes even when nobody instructs the agent to cause harm.
This is where the breach beat and the emerging agentic conversation converge. Bitget was breached through a product, DIVD through an automated agent, and both illustrate the same structural weakness: the systems inside the perimeter are increasingly capable of independent action, and independent action is hard to constrain with controls designed for deterministic software.



