bleeping-computer · Crawled Oct 1, 2026

DIVD says Zammad zero-days enabled AI-driven network breach

Read original article ↗

AI Summary

The Dutch Institute for Vulnerability Disclosure (DIVD) suffered a network breach enabled by a chain of two zero-day vulnerabilities in the Zammad ticketing system. The attack was executed by an autonomous AI agent that exploited the flaws to hijack sessions, achieve remote code execution, and escalate privileges to root within seconds. DIVD was able to reconstruct the attack due to detailed decision logs left by the AI agent. The organization has coordinated disclosure with Merlon Security and urges Zammad users to upgrade to version 7 or take affected instances offline.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.