Executive Summary
Facts Only
* The Dutch Institute for Vulnerability Disclosure disclosed a breach.
* The breach involved two zero-day vulnerabilities in the ticketing system.
* The attack utilized Zammad, an open-source helpdesk platform used internally by DIVD.
* The vulnerabilities were tracked as CVE-2026-102489 and CVE-2026-102490.
* Chaining the vulnerabilities allowed session hijacking, remote code execution, and privilege escalation to root access in seconds.
* An AI agent was involved in the attack, enabling autonomous decision-making for subsequent steps.
* Attackers accessed other services and exfiltrated data after gaining root privileges.
* Network segmentation and response teams prevented further movement by attackers.
* Zammad has over 2,000 customers and 55,000 users.
* The recommended fix is updating to Zammad version 7 or taking the system offline.
Full Take
From the original · Security Affairs (Pierluigi Paganini)
The Dutch Institute for Vulnerability Disclosure, a nonprofit organization of volunteer security researchers whose whole job is finding and responsibly disclosing vulnerabilities in other people’s software, just disclosed that it got breached through two zero-days in its own ticketing system. The attackers got in through Zammad, an open-source helpdesk platform that DIVD used internally.Read the full story at securityaffairs.com
Sentinel — Human
The text reads like a factual report synthesizing details from an incident response, characterized by direct attribution and practical advice rather than pure speculative exposition.
