DIVD Zammad breach investigation
Dutch vulnerability disclosure group DIVD says attackers chained two Zammad flaws and exposed some volunteer data during a suspected AI-assisted intrusion.
What happened lately
DIVD Zammad breach investigation timeline
A breach under investigation
DIVD says attackers exploited two previously unknown vulnerabilities in its Zammad ticketing system. According to the Dutch nonprofit, the chained flaws allowed session hijacking, remote code execution and escalation to root. It identified the issues as CVE-2026-102489 and CVE-2026-102490. DIVD says the attackers reached other services and removed data, including some volunteer email addresses and possibly contact details.
Evidence and limits
The organization assesses that the attack was driven by an AI agent, citing fast, automated actions and explanatory notes left in scripts. That is DIVD’s assessment during an ongoing forensic investigation, not a confirmed identification of the operator or a general measure of what AI agents can do. DIVD says segmentation and response actions stopped deeper movement, while the full scope of exposed data remains under investigation.