Executive Summary
Facts Only
* A Dutch cybersecurity non-profit was compromised by an agentic AI attack.
* The attack exploited two zero-day flaws in the Zammad helpdesk platform.
* The exploited flaws were remote code execution bug CVE-2026-102489 and elevation of privileges flaw CVE-2026-102490.
* Chaining these vulnerabilities allowed session hijacking, remote code execution, and privilege escalation to root in seconds via the agentic component.
* The attackers accessed other services and exfiltrated data from the compromised system.
* DIVD contained the threat using network segmentation and incident response actions.
* Volunteer data, including email addresses, was potentially compromised.
* Attack scripts contained notes justifying actions, suggesting an agentic AI involvement.
* Tim Burke warned that AI compresses detection and response timelines.
* Network segmentation was identified as key to limiting damage in such incidents.
Full Take
From the original · InfoSecurity Magazine
A Dutch cybersecurity non-profit has revealed how it was compromised in an agentic AI attack that exploited two zero-day flaws in its helpdesk platform. The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to “make the digital world safer.”Read the full story at infosecurity-magazine.com
Sentinel — Human
The text appears to be a factual report synthesizing an incident, expert commentary, and technical details, exhibiting characteristics of human investigative journalism rather than pure synthetic generation.
