Skip to content

Executive Summary

The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed that it was breached through two zero-day vulnerabilities in its own Zammad ticketing system. Attackers exploited these flaws to gain access, which was significantly amplified by the use of an AI agent. The chained vulnerabilities allowed attackers to hijack sessions, execute remote code, and escalate privileges from a standard user account to root access within seconds. Following this initial access, the attackers accessed other services and exfiltrated data, although network segmentation and incident response efforts limited further movement. DIVD advises all Zammad users to update to version 7 or take the system offline immediately. The investigation remains ongoing, with an update scheduled for October 1st.

Facts Only

* The Dutch Institute for Vulnerability Disclosure disclosed a breach.
* The breach involved two zero-day vulnerabilities in the ticketing system.
* The attack utilized Zammad, an open-source helpdesk platform used internally by DIVD.
* The vulnerabilities were tracked as CVE-2026-102489 and CVE-2026-102490.
* Chaining the vulnerabilities allowed session hijacking, remote code execution, and privilege escalation to root access in seconds.
* An AI agent was involved in the attack, enabling autonomous decision-making for subsequent steps.
* Attackers accessed other services and exfiltrated data after gaining root privileges.
* Network segmentation and response teams prevented further movement by attackers.
* Zammad has over 2,000 customers and 55,000 users.
* The recommended fix is updating to Zammad version 7 or taking the system offline.

Full Take

The incident illustrates a critical transition point where automated systems shift from theoretical risk to demonstrable operational threat. The primary pattern emerging is the amplification of vulnerability through synergistic exploitation, moving beyond single flaws to create a decisive chain reaction that bypasses standard human response times. The role of the AI agent is significant; it does not merely facilitate access but acts as an autonomous execution layer, transforming a complex exploit into an immediate privilege escalation event. This suggests that future defense strategies must account for attacks where automated systems can leverage low-level technical flaws sequentially to achieve high-level objectives rapidly. The emphasis on noise—the AI leaving visible traces—as a factor in detection underscores a tension between stealth and observability in adversarial contexts. The implications point toward the need to scrutinize the security posture of foundational infrastructure components, particularly when integrating advanced operational tools like AI. What framework exists for measuring resilience against these automatically chained, speed-optimized attacks? How can organizations ensure that rapid development cycles, which often introduce complexity (like incorporating AI), do not inadvertently create exponentially more exploitable attack surfaces across disparate systems?

From the original · Security Affairs (Pierluigi Paganini)

The Dutch Institute for Vulnerability Disclosure, a nonprofit organization of volunteer security researchers whose whole job is finding and responsibly disclosing vulnerabilities in other people’s software, just disclosed that it got breached through two zero-days in its own ticketing system. The attackers got in through Zammad, an open-source helpdesk platform that DIVD used internally.
Read the full story at securityaffairs.com

Sentinel — Human

Confidence

The text reads like a factual report synthesizing details from an incident response, characterized by direct attribution and practical advice rather than pure speculative exposition.

Signals Detected
low severity: Sentence length variance exhibits some natural variation; the tone shifts between technical reporting and direct advice.
low severity: The text maintains a clear narrative flow connecting the discovery, the mechanism (AI agent), the impact, and the response, suggesting human structuring.
low severity: Attribution is specific (e.g., citing LinkedIn posts) and links directly to named entities (DIVD, Merlon Security), which suggests reliance on primary source reporting.
low severity: The highly specific details regarding CVEs, software versions (Zammad 7), and the exact mechanism described appear grounded in technical reality, reducing fabrication risk.
Human Indicators
The inclusion of direct quotes attributed to the organization's representative on LinkedIn lends a personal, human voice.
The pragmatic focus on immediate remediation (update to version 7) and log checking reflects typical incident response communication.
AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds | Huntaegis