The breach at a glance
In late September 2026, the Dutch Institute for Vulnerability Disclosure (DIVD) disclosed that the breach of its own network had been made possible by chaining two zero-day vulnerabilities in the open-source Zammad ticketing system. The case quickly became one of the most closely watched examples of emerging AI cybersecurity threats, because the intrusion was not driven by a human operator working through a checklist. According to the nonprofit, which is made up of volunteer security researchers, the attack was "loud and very, very messy," propelled by an AI agent that moved autonomously and decided its next steps without external intervention or direction.
What makes the incident unusually instructive for defenders is that the very autonomy that made the intrusion dangerous also produced the trail that exposed it. DIVD was able to retrieve extensive details about the attack because the AI agent left behind clear explanations of its decisions, allowing the organization to reconstruct the incident almost step by step. The episode now sits at the intersection of two fast-moving areas of cybersecurity news: web-application vulnerabilities in widely deployed open-source software, and the first wave of agentic attacks where artificial intelligence compresses a chain of exploits into a matter of seconds.
How AI is used in cybersecurity: a dual-use moment
To understand what happened to DIVD, it helps to start with the question many readers ask when they first hear the term: what is AI in cyber security, and how is it actually used day to day? In plain terms, it refers to machine-learning and large-language-model systems applied to security work — triaging alerts, spotting anomalies in network traffic, summarizing threat intelligence, writing and reviewing code, and, on the offensive side, planning and executing sequences of actions against a target. The same underlying capability of reasoning and acting on a goal can be pointed in opposite directions, which is why defenders and attackers are both racing to adopt it. The offensive side of that race is covered in our look at vulnerability discovery run through AI code tooling.
DIVD's incident is a rare real-world illustration of that dual-use dynamic. The organization is itself a cybersecurity nonprofit whose entire mission is finding and responsibly disclosing vulnerabilities, and it was on the receiving end of an AI agent that performed reconnaissance, chained exploits, and exfiltrated data with little to no human hand-holding. On one side, AI is used defensively to accelerate investigation and decision-making; on the other, those same agentic capabilities let an attacker operate at machine speed. Reading the two together answers the broader question of how AI is used in cybersecurity: it is less a single tool and more a new class of autonomous actor that changes the pace at which both attacks and responses happen.
The attack mechanics: a zero-day chain run at machine speed
The technical core of the breach was a chain of two previously unknown flaws, now identified as CVE-2026-102489 and CVE-2026-102490. Individually, each is a serious web-application vulnerability in the Zammad platform; used together, they formed a path from an unauthenticated foothold all the way to full control of the host. DIVD described the combined impact directly: "Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack."
That phrase — in seconds — is the detail that elevates this from a routine web-application compromise into a case study for AI cybersecurity threats more broadly. In a conventional intrusion, an attacker identifies a vulnerability, develops or selects an exploit, manually escalates privileges, and then slowly probes the environment, each stage gated by human reaction time. Here, the agentic AI automated that entire decision loop. After exploiting the vulnerabilities, the attacker was able to access other services, and read and exfiltrate data from DIVD's systems, all actions performed in a matter of seconds thanks to the AI automation. The chain from session hijacking to remote code execution to root privileges happened faster than a human operator could have narrated it.
What the zero-days enabled
Breaking the impact into its components helps defenders assess their own exposure to comparable flaws. Session hijacking let the agent assume the identity of a legitimate Zammad user without needing that user's credentials. Remote code execution turned that foothold into the ability to run arbitrary commands on the underlying server. Privilege escalation then lifted those commands from the limited Zammad service account to root, the highest level of access on the host. Once at root, the agent could reach adjacent services and pull data out of the environment.
The escalation chain is the most important takeaway for any organization running Zammad or similar ticketing platforms. Ticketing systems are frequently internet-facing, often trusted as "internal" tools, and frequently overlooked in patch cycles precisely because they are not seen as crown-jewel assets. A two-flaw chain that ends in root undermines that assumption entirely, converting a helpdesk into a beachhead for the rest of the network in a matter of seconds.
Containment, segmentation, and the ongoing investigation
A bright spot in an otherwise alarming story is that the damage was bounded. Thanks to network segmentation and prompt incident-response actions, the threat actor did not move deeper into DIVD's network. The segmentation plan worked exactly as intended: it limited the blast radius of a compromise that began at the edge, buying the response team the time to contain an attack that was otherwise unfolding at machine speed.
That said, the organization stressed that the investigation was still underway at the time of disclosure, and DIVD said it would share additional updates the following day. For readers following the latest cybersecurity news, that caveat matters: the published CVE identifiers, the root-escalation path, and the autonomous-agent narrative are confirmed, but the full data-exfiltration scope and attribution were still being established. It is also not an isolated data point in 2026 — see our breakdown of the UK police database breach for another recent case where exposed records and automated tooling collided. The decision to leave a clear decision trail is also double-edged — it helped DIVD reconstruct events, yet it is a byproduct of how these agents are built, not a feature an attacker would deliberately choose.
Zammad's blast radius and the recommended fix
The downstream risk depends on how widely the vulnerable software is deployed. Zammad is an open-source, AI-powered helpdesk and support ticketing platform used to manage customer inquiries, IT support requests, and internal ticketing. It is available both as a self-hosted and as a hosted service, and the vendor claims on its website that it has over 2,000 customers and 55,000 users, including De'Longhi, Amnesty International, and NextCloud. That footprint means the two zero-days are not a DIVD-only problem; they are a supply-chain concern for every organization exposing a vulnerable instance.
DIVD discovered the zero-day vulnerabilities in collaboration with Merlon Security. The nonprofit notified Zammad about the issue and is alerting other users of vulnerable instances. The recommended remediation is straightforward and urgent: Zammad users should upgrade to version 7, which is considered safe, or take the instance offline as soon as possible. When the window between public disclosure and active exploitation is measured in seconds rather than weeks, "patch this weekend" is not a viable answer — isolation or upgrade needs to happen immediately.
What this signals for AI cybersecurity threats in 2026
This breach is one of the first cases where a defensive security organization was itself breached by an autonomous agent and then documented the agent's reasoning in detail. For the broader security community, the message is that agentic AI collapses the timescale that defenders have historically relied on. Detection and response plans built around human reaction times — alert triage queues, escalation pagers, "respond within the hour" playbooks — are poorly matched to an adversary that finishes the exploit chain before the first alert is read.
The pattern is consistent with what we have seen elsewhere in the AI threat landscape, including EncForge, an attacker toolkit aimed squarely at the AI stack. The practical guidance that follows mirrors the defensive uses of AI itself: validate, decide, fix, and re-validate at machine speed. Network segmentation proved decisive here, which is a reminder that old-school containment architecture still pays off against very new attack methods. At the same time, the case makes clear that patch velocity for internet-facing web applications now carries a different kind of urgency, because the cost of a missed patch is no longer a slow human intrusion but an autonomous run from zero-day to root in seconds. As 2026 progresses, DIVD's incident will likely be cited as a turning point in how organizations think about AI cybersecurity threats — not as a hypothetical future risk, but as a current operational reality.
Sources
- BleepingComputer — "DIVD says Zammad zero-days enabled AI-driven network breach," Bill Toulas, September 30, 2026. https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/
- Zammad official website (deployment scale and product description). https://zammad.com/
- DIVD official website. https://divd.nl/