Skip to content
VECTOR WIREAI INTELLIGENCE
UTC

AI agent chains two Zammad zero-days to breach Dutch vulnerability-disclosure nonprofit DIVD

An autonomous AI agent exploited two previously unknown Zammad vulnerabilities to breach the Dutch Institute for Vulnerability Disclosure, which called…

An automated AI agent chained two previously unknown vulnerabilities in the open-source Zammad ticketing platform to breach the Dutch Institute for Vulnerability Disclosure, marking what the nonprofit called the first agentic AI-powered attack it has encountered1,2,3.

DIVD, a volunteer-run organization that scans the internet for vulnerable systems and notifies their owners, confirmed the breach on September 24. Attackers first accessed DIVD's infrastructure on September 21; the organization detected suspicious activity the following day and immediately blocked access to systems in its data center. DIVD described the intrusion as "loud and very very messy," leaving extensive forensic evidence4.

Two zero-days in Zammad

In findings published on September 30, DIVD identified the two zero-day flaws and assigned them CVE-2026-102489, a remote code execution vulnerability, and CVE-2026-102490, a local privilege escalation vulnerability. Zammad versions 6.3.0 through 6.5.4 are vulnerable, and DIVD reported that the second weakness affected a broad range of versions extending to the latest alpha release examined during the investigation. DIVD's published advisory recommends upgrading to Zammad version 7 or taking affected systems offline. The organization has begun notifying other organizations potentially exposed to the same flaws.

According to DIVD's published timeline, researchers reproduced the vulnerabilities on September 22 and 23, reported them to Zammad on September 24, and started notifying vulnerable organizations on September 26.

How the agent operated

DIVD said the attacker first exploited a technical vulnerability in an undisclosed system — which the organization said was not Citrix NetScaler — before deploying the automated AI agent for post-exploitation activities inside its network. The agent reportedly selected its next action after completing each previous step, operating autonomously rather than following a fixed script. Researchers observed the agent interfering with its own adversary-in-the-middle attack by simultaneously conducting password-spraying activity. DIVD also reported that the agent left unusually detailed comments explaining its actions.

DIVD described the attack as noisy and poorly executed. The attack's purpose and full impact remain unclear at this stage.

DIVD launched a forensic investigation with assistance from Merlon Security and reported the incident to the police, the Autoriteit Persoonsgegevens, and the National Cyber Security Centre. The organization promised a more detailed update on October 1.

ANALYSIS That a cybersecurity nonprofit staffed by vulnerability researchers was itself breached by an autonomous agent underscores the operational reality that defenders now face from agentic tooling. The agent's self-interfering behavior and verbose logging suggest current offensive agents remain crude, but the successful exploitation of two zero-days to gain initial access demonstrates that even noisy automation can achieve meaningful network penetration.