DIVD traces suspected AI-assisted breach to two Zammad zero-days
The Dutch nonprofit says attackers chained two flaws, reached other services and exposed some volunteer data; its forensic investigation continues.
What DIVD has established
The Dutch Institute for Vulnerability Disclosure says intruders entered its network by chaining two previously unknown vulnerabilities in the Zammad ticketing system. Its October 1 incident update identifies the flaws as CVE-2026-102489 and CVE-2026-102490 and says the chain enabled session hijacking, remote code execution and privilege escalation to root. DIVD says the attackers then reached other services and exfiltrated data. It has confirmed exposure of some volunteer email addresses and says contact details may also be involved, while it continues to determine exactly whose records were affected. BleepingComputer separately reported the vulnerability chain and DIVD’s response.
DIVD attributes the speed and decision-making it observed to an agentic AI-powered attack. It cites automated actions and notes in attacker scripts explaining subsequent steps. That is the organization’s current assessment, not proof of a particular attacker, model or level of autonomy. DIVD says network segmentation and incident response stopped the intruders from going deeper. The forensic investigation is still open, so the full data impact and the attackers’ identity remain unconfirmed. The concrete warning is that an exposed support system and chained flaws gave the intruders a path into a security nonprofit’s infrastructure.