← Back to briefings

Dutch Cybersecurity Nonprofit DIVD Breached Through AI-Automated Exploitation of Zammad Zero-Days

Cybersecurity2026-10-01·4 min read

The Dutch Institute for Vulnerability Disclosure (DIVD), a well-known cybersecurity nonprofit that coordinates vulnerability disclosures across the internet, revealed on September 30 that its own network was breached through a chain of two zero-day vulnerabilities in Zammad, an open-source helpdesk and ticketing platform used by organisations including Amnesty International and Nextcloud.

The two flaws, now tracked as CVE-2026-102489 and CVE-2026-102490, allowed an attacker to hijack an active session, execute arbitrary code remotely, and escalate privileges to root. What makes the incident particularly notable is DIVD's assessment that the entire exploitation chain — from initial access to data exfiltration — was performed in a matter of seconds using AI-driven automation, suggesting that the attacker used an autonomous agent rather than manual exploitation.

DIVD discovered and reproduced the vulnerabilities on September 22 to 23, reported them to Zammad on September 24, and began notifying other organisations running vulnerable instances on September 26. The nonprofit recommends that all Zammad users upgrade to version 7, which addresses both flaws, or take affected instances offline immediately.

The identity of the attacker, the full extent of data exposure, and the precise objectives behind the intrusion remain unknown. The incident is a striking example of the double-edged nature of AI in cybersecurity: the same organisation that exists to protect others from vulnerabilities was itself compromised by an AI-accelerated attack. DIVD has promised additional technical details in a follow-up disclosure.

Source: BleepingComputer. This article summarizes the linked reporting and distinguishes announced plans from demonstrated results.