<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

AI-Powered Attack Hits Dutch Cybersecurity Organization Using Zammad Zero-Days

DIVD suffers its first AI-powered hack after attackers exploited Zammad zero-days. Urgent update to version 7 advised to prevent further breaches.
Content Team

The Dutch Institute for Vulnerability Disclosure was hacked on September 21 in what it calls an agentic AI-powered attack, a first for the organization. Attackers chained two Zammad zero-days — CVE-2026-102489, a session hijack giving remote code execution as the zammad user, and CVE-2026-102490, a local escalation to root — moving from one to the other in seconds.

The two flaws cover different ground. CVE-2026-102489 affects Zammad 6.3.0 through 6.5.4, and sits in 7.0.0 to 7.1.3 without being exploitable there. CVE-2026-102490 reaches every release from v1.5.0 to v7.1.0-alpha, so moving to version 7 closes the first flaw and not the second. DIVD still advises upgrading or taking instances offline.

Network segmentation stopped the attackers going deeper, though they pivoted to other services and exfiltrated data — The Register reports email addresses were taken. DIVD notes the agent left visible traces of its work, and warns that a more careful attacker using the same approach would be far harder to spot.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo