AI-Powered Attack Hits Dutch Cybersecurity Organization Using Zammad Zero-Days
Want more insights like this?
The Dutch Institute for Vulnerability Disclosure was hacked on September 21 in what it calls an agentic AI-powered attack, a first for the organization. Attackers chained two Zammad zero-days — CVE-2026-102489, a session hijack giving remote code execution as the zammad user, and CVE-2026-102490, a local escalation to root — moving from one to the other in seconds.
The two flaws cover different ground. CVE-2026-102489 affects Zammad 6.3.0 through 6.5.4, and sits in 7.0.0 to 7.1.3 without being exploitable there. CVE-2026-102490 reaches every release from v1.5.0 to v7.1.0-alpha, so moving to version 7 closes the first flaw and not the second. DIVD still advises upgrading or taking instances offline.
Network segmentation stopped the attackers going deeper, though they pivoted to other services and exfiltrated data — The Register reports email addresses were taken. DIVD notes the agent left visible traces of its work, and warns that a more careful attacker using the same approach would be far harder to spot.
Source: SecurityWeek