A devastating AI-driven network breach was recently uncovered by the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organization that specializes in identifying and mitigating cybersecurity threats. The attack, which has left experts reeling, was made possible by exploiting two zero-day vulnerabilities in the open-source Zammad ticketing system.
Zammad is an AI-powered helpdesk and support ticketing platform used by over 2,000 customers and 55,000 users worldwide, including prominent organizations such as De’Longhi, Amnesty International, and NextCloud. The platform’s automated nature made it a prime target for attackers looking to exploit its vulnerabilities. According to DIVD, the attack was “loud and very, very messy,” with an AI agent moving autonomously and deciding its next steps without external intervention or direction.
The two zero-day flaws, identified as CVE-2026-102489 and CVE-2026-102490, enabled session hijacking, remote code execution, and escalation to root privileges. This meant that the attacker could access other services, read and exfiltrate data from DIVD’s systems with ease, all within a matter of seconds due to AI automation. The attackers’ actions were so swift and seamless that they would have gone undetected if not for the AI agent leaving behind clear explanations of its decisions.
DIVD collaborated with Merlon Security to discover the zero-day vulnerabilities, which they promptly notified Zammad about. As a result, Zammad users are being alerted to upgrade to version 7 or take their instance offline as soon as possible to prevent similar attacks. It’s worth noting that network segmentation and incident response actions prevented the threat actor from moving deeper into the DIVD network.
The investigation is still ongoing, but one thing is clear: this attack highlights the growing threat of AI-powered attacks on networks. As more organizations adopt AI-driven solutions, they must also be aware of the potential vulnerabilities these systems can introduce. DIVD’s discovery serves as a stark reminder that even with the most advanced security measures in place, zero-day exploits can still have devastating consequences.
For those using Zammad or similar platforms, this incident is a wake-up call to prioritize patching and upgrading their systems regularly. The swift action of DIVD and Merlon Security in identifying and mitigating this attack serves as a model for other organizations to follow. As we move forward in the age of AI-powered attacks, it’s essential that security professionals stay vigilant and proactive in identifying vulnerabilities before they can be exploited by attackers.
Source: Bleeping Computer — 2026-09-30