A sophisticated cyberattack on a Dutch cybersecurity nonprofit has shed light on the evolving threat landscape of AI-driven network breaches. The Dutch Institute for Vulnerability Disclosure (DIVD) recently revealed that its own network was compromised by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system.
The attack, which DIVD described as “loud and very, very messy,” was carried out by an AI agent that moved autonomously and decided its next steps without external intervention or direction. This allowed the attacker to rapidly exploit the vulnerabilities and access other services on the network, reading and exfiltrating data from DIVD’s systems in a matter of seconds.
The two flaws, now identified as CVE-2026-102489 and CVE-2026-102490, enabled session hijacking, remote code execution, and escalation to root privileges. In essence, they allowed the attackers to “hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds,” according to DIVD.
Zammad is an open-source AI-powered helpdesk and support ticketing platform used by over 2,000 customers, including major brands like De’Longhi, Amnesty International, and NextCloud. The platform is designed to manage customer inquiries, IT support requests, and internal ticketing, but in this case, its own vulnerabilities left it vulnerable to attack.
DIVD discovered the zero-day vulnerabilities in collaboration with Merlon Security and notified Zammad about the issue. In light of this incident, DIVD recommends that all Zammad users upgrade to version 7, which is considered safe, or take their instance offline as soon as possible.
The incident highlights the growing threat of AI-powered attacks, where sophisticated algorithms can rapidly exploit vulnerabilities and move laterally through a network with devastating speed. As such, it’s essential for organizations to remain vigilant and adapt their security strategies to address these emerging threats.
In practical terms, this means that all Zammad users should prioritize updating their software as soon as possible and consider implementing additional security measures to prevent similar attacks in the future. By staying informed and proactive, we can work together to mitigate the risks associated with AI-driven network breaches.
Source: Bleeping Computer — 2026-09-30