Skip to content

Executive Summary

A Dutch cybersecurity non-profit, the Institute for Vulnerability Disclosure (DIVD), was compromised following an agentic AI attack exploiting two zero-day flaws in its Zammad helpdesk platform. The attackers used these vulnerabilities to hijack sessions, execute remote code, and escalate privileges from a Zammad user to root, facilitated by the agentic nature of the exploit. This access allowed the attackers to reach other services and exfiltrate data. The exploited vulnerabilities were remote code execution bug CVE-2026-102489 and elevation of privileges flaw CVE-2026-102490, both scoring 9.4 when chained together. Despite the compromise, DIVD's security team contained the threat through network segmentation and incident response actions, although some damage occurred. A separate data file indicated that volunteer data, including email addresses, was potentially compromised, raising concerns about impersonation risks. The investigation suggested the attack involved an agentic AI, as attacker scripts included justifications for their actions. Experts emphasize that while AI accelerates attacks, fundamental security practices like segmentation, monitoring, and incident response remain critical.

Facts Only

* A Dutch cybersecurity non-profit was compromised by an agentic AI attack.
* The attack exploited two zero-day flaws in the Zammad helpdesk platform.
* The exploited flaws were remote code execution bug CVE-2026-102489 and elevation of privileges flaw CVE-2026-102490.
* Chaining these vulnerabilities allowed session hijacking, remote code execution, and privilege escalation to root in seconds via the agentic component.
* The attackers accessed other services and exfiltrated data from the compromised system.
* DIVD contained the threat using network segmentation and incident response actions.
* Volunteer data, including email addresses, was potentially compromised.
* Attack scripts contained notes justifying actions, suggesting an agentic AI involvement.
* Tim Burke warned that AI compresses detection and response timelines.
* Network segmentation was identified as key to limiting damage in such incidents.

Full Take

The narrative structure highlights the tension between the speed of modern adversarial capabilities—exemplified by agentic AI attacks—and the necessary, slower requirements for robust security architecture. The initial exploitation leverages a high-speed, automated method (agentic hacking) to bypass traditional human-centric detection, immediately shifting the focus from vulnerability patching (the input vector) to systemic defense (the containment strategy). This creates a pattern where novel vulnerabilities are weaponized instantly, demanding that defensive measures evolve beyond static patch management toward dynamic system segmentation and continuous visibility. The mention of agentic justification within the attacker’s logs points to an emerging paradigm where machine autonomy can introduce a layer of obfuscation that evades standard forensic review; this suggests that accountability shifts from identifying human operators to understanding autonomous decision-making chains in security events. The warning emphasizes that foundational principles—segmentation, monitoring, and response protocols—are not obsolete but are amplified by AI speed, suggesting that organizational resilience depends less on stopping the *next* zero-day exploit and more on establishing unbreakable boundaries where even automated processes cannot traverse freely. What is the implicit cost placed on volunteer organizations when they become targets for sophisticated state-level or advanced criminal actors using these emerging tools? How does relying on human incident response teams, even when effective, adapt to an environment where machine-driven speed compresses the window for meaningful intervention?

From the original · InfoSecurity Magazine

A Dutch cybersecurity non-profit has revealed how it was compromised in an agentic AI attack that exploited two zero-day flaws in its helpdesk platform. The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to “make the digital world safer.”
Read the full story at infosecurity-magazine.com

Sentinel — Human

Confidence

The text appears to be a factual report synthesizing an incident, expert commentary, and technical details, exhibiting characteristics of human investigative journalism rather than pure synthetic generation.

Signals Detected
low severity: Sentence length variance shows natural variation; use of direct quotes interspersed with analytical commentary.
low severity: The narrative flows logically from the event disclosure to the technical details, the response, and the philosophical implications without excessive hedging.
low severity: Attribution is specific (e.g., citing logs, quoting CEO Burke) rather than vague generalized claims.
low severity: Specific technical details (CVEs, platform names, dates) are presented in a context that suggests reporting of actual findings rather than pure fabrication.
Human Indicators
The inclusion of direct, specific quotes from the organization and an external expert (Tim Burke) alongside the technical disclosure suggests journalistic sourcing.
The tone shifts appropriately between reporting an incident and offering high-level strategic advice.
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure | Huntaegis