Zero-day flaws chained in the attack: 2 (Source: DIVD, case DIVD-2026-00015 (statement reported September 30, 2026))
One incident, and a claim about speed
Human intruders read output, think and try again. Each pause gives a defender a chance to notice. In one recent case, a Dutch security nonprofit attributes the speed of its own breach to an AI agent. That is the nonprofit's account, and it is still being tested.
The nonprofit is DIVD, the Dutch Institute for Vulnerability Disclosure, a group of volunteer researchers. It was itself breached. While working out how the attackers got in, and together with Merlon Security, it found two zero-day flaws in Zammad. Zammad is an open-source helpdesk and ticketing system. A zero-day is a flaw the vendor did not know about, so no fix existed.
DIVD says the two flaws, used together, let the attackers hijack sessions, run code remotely and climb from the Zammad user to root. It says this took seconds "due to the agentic part of this hack." The attackers then reached other services and read and exfiltrated data.
The agent label is DIVD's own claim. BleepingComputer reports that DIVD earlier described an agent acting on its own and choosing its next moves. The outlet also reports that the agent left written explanations of its choices, which let DIVD rebuild the sequence of events.
What the public record says about the flaws
DIVD calls each flaw significant on its own and more serious in combination. The public material does not explain how the chain works beyond a short description of one flaw. Treat any deeper account as unconfirmed.
Three terms help. Session hijacking means taking over a logged-in user's identity, so the system treats the attacker as that user. Remote code execution means running the attacker's commands on a server they do not own. Privilege escalation means moving from a limited account to root, the all-powerful administrator account.
The case file lists CVE-2026-102489 as remote code execution as the Zammad user, which can be used to leak sessions. It names Zammad 6.3.0 to 6.5.4 as vulnerable. Versions 7.0.0 to 7.1.3 also contain the flaw, but DIVD says environment conditions keep it from being exploitable there.
The public sources do not say what CVE-2026-102490 does by itself. DIVD's advice for users of any Zammad version is to update to version 7 or take the system offline.
Two credits, and what this case suggests
DIVD gives two reasons the attackers did not get deeper: network segmentation, and the actions of its IT and incident response team after detection. Segmentation splits a network into zones, so a break-in to one zone does not open the others.
The sources do not let anyone rank those two factors. Our interpretation is narrower. The case suggests segmentation limited how far the intrusion spread, while the response team acted once the attack was detected. Both were needed, and the investigation is not finished.
The protection was partial. DIVD says some damage was already done. It has found signs of compromise that it is still examining. Until it can show otherwise, it treats its systems as breached.
What is still contested
Some security professionals who replied to DIVD's post questioned how much weight the word "agentic" can carry. They asked what controls failed, why a compromised application could reach other services, and what should have limited lateral movement. Lateral movement means an attacker hopping from one system to another.
One commenter asked whether this was hackers with some AI help or something else. DIVD has not answered these points in the material available. How much of the attack was agent-driven, and how much was human, is not stated.
That leaves a practical point regardless of the agent question. How far a compromised helpdesk server can reach is a design decision your own team can examine today.
What to ask your team this week
First, do we run Zammad, and which version? If it is below version 7, ask for an update date or a plan to take it offline.
Second, if an attacker took over a helpdesk server today, what else could it reach? Ask for a map, not an assurance.
Third, can our logs show signs of abuse? DIVD has published a script for checking logs, linked from its case file.
Fourth, which of our defenses rely on a person noticing and acting within minutes, and what stands behind them if that does not happen?
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: DIVD (Dutch Institute for Vulnerability Disclosure).





