BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 30, 2026 · 2 min read · Original story

DIVD says Zammad zero-days enabled AI-driven network breach

DIVD says Zammad zero-days enabled AI-driven network breach

The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system.

Previously, the nonprofit organization of volunteer security researchers said the attack was “loud and very, very messy,” driven by an AI agent that moved autonomously and decided its next steps without external intervention or direction.

DIVD retrieved extensive details about the attack because the AI agent left behind clear explanations of its decisions, allowing the organization to reconstruct the incident.

According to the cybersecurity nonprofit, the two flaws, now identified as CVE-2026-102489 and CVE-2026-102490, enabled session hijacking, remote code execution, and escalation to root privileges.

After exploiting the vulnerabilities, the attacker was able to access other services, read and exfiltrate data from DIVD's systems, all actions performed in a matter of seconds, thanks to AI automation.

“Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack,” DIVD says.

Due to network segmentation and incident response actions, the threat actor did not move deeper into the network. However, the investigation is still underway.

Zammad is an open-source AI-powered helpdesk and support ticketing platform used to manage customer inquiries, IT support requests, and internal ticketing.

The solution is available as a self-hosted or hosted service, and Zammad claims on its website that it has over 2,000 customers and 55,000 users, including De’Longhi, Amnesty International, and NextCloud.

DIVD discovered the zero-day vulnerabilities in collaboration with Merlon Security. The organization notified Zammad about the issue and is alerting other users of vulnerable instances.

The nonprofit recommends that Zammad users upgrade to version 7, which is considered safe, or take the instance offline as soon as possible.

DIVD has promised to share additional updates about the incident tomorrow.

References in this story

  1. Automated AI agent used to breach cybersecurity nonprofit DIVD www.bleepingcomputer.com The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy."
  2. #zammad | DIVD Dutch Institute for Vulnerability Disclosure | 11 comments lnkd.in When hackers get hacked, we deal with it in hacker style. While trying to figure out how the attackers got into our own systems, 𝘄𝗲 𝗳𝗼𝘂𝗻𝗱 𝘁𝘄𝗼 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆 𝘃𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀 𝗶𝗻 𝗭𝗮𝗺𝗺𝗮𝗱. Used together, they allowed the attackers…
  3. Customer Stories & Case Studies | Zammad zammad.com How is Zammad actually used in reality? IT-Support, Project Management, Law, or Schools, let our customers inspire you with their amazing success stories!

Guides related to this story

← Back to all news