The Dutch Institute for Vulnerability Disclosure (DIVD), the volunteer-driven nonprofit that scans the internet for exposed systems and notifies their owners, has become the victim of the kind of attack it spends its life warning about. On September 22, 2026, DIVD detected an intrusion into its own network, cut off access to the affected data center and launched a full incident response that is still ongoing.
According to DIVD's public statements, the attacker chained two previously undisclosed vulnerabilities in Zammad, the open-source helpdesk platform: CVE-2026-102489, a remote code execution flaw rated CVSS 8.7 that let a hijacked support session become code execution as the zammad user, and CVE-2026-102490, a local privilege escalation flaw rated CVSS 8.5 that carried that account to root. Chained, the pair scores CVSS 9.4. The remote code execution is exploitable on Zammad 6.3.0 through 6.5.4; the privilege escalation flaw is present in every release from v1.5.0 through 7.1.0-alpha.
What makes the incident genuinely new is who — or what — DIVD says was driving it. The organization's investigators concluded the behavior did not match a human operator but an autonomous AI agent that decided its next move after every action, rather than following a pre-planned attack script. The intrusion was, in DIVD's words, noisy and messy: the attack code even contained comments explaining that it was "not phishing" and "not a spam email." The time from hijacked session to root was measured in seconds.
The evidence is not cinematic. In one stage, after reaching root, the attacker ran password spraying and a man-in-the-middle attack — and executed both so poorly that the spraying actively interfered with its own interception attempt. That kind of self-sabotage is precisely what you would expect from a non-deterministic agent improvising in real time, and DIVD is treating it as a key indicator. The AI-agent attribution remains the organization's own determination, not something independently verified by an outside party.
The consequences are real. As of October 1, DIVD confirmed that volunteer email addresses were exposed, that contact information may also have leaked, and that part of the mailbox of its CSIRT — the arm that itself warns thousands of system owners about vulnerabilities — was exfiltrated. The organization has notified the police, the Dutch data protection authority (Autoriteit Persoonsgegevens) and the National Cyber Security Centre (NCSC).
Zammad's own website claims more than 2,000 customers and 55,000 users, and there is no public figure yet for how many deployments run a vulnerable version exposed to the internet. DIVD has notified Zammad and is alerting other users of vulnerable instances, recommending an upgrade to version 7 or taking internet-facing instances offline. The scale matters because a helpdesk is a concentration point: database credentials, mail tokens, API keys and integration secrets for every system a support team touches.
DIVD's defensive guidance is practical. Upgrade Zammad to 7.0.0 or later — the RCE chain is not exploitable there, but the privilege escalation flaw still exists even in the latest alpha, so monitor the zammad service account afterward. Run DIVD's published IOC check script against /var/log/zammad and /var/log/nginx before rebuilding anything. Segment the helpdesk with default-deny egress — the control that ultimately stopped the attacker from going deeper. And treat any confirmed indicator as a full host compromise: the attacker had root, so rotate every credential stored on or reachable from the host.
The security industry's threat model so far has centered on a defender's own agent being abused — prompt injection, malicious MCP servers, indirect instructions. This incident is the symmetric case: an attacker's agent automating exploitation against entirely conventional software. Some practitioners have started calling this category an "agentic threat actor." If the label sticks, one implication is immediate: a defender who can only respond at ticket-queue speed is not competing with an adversary that completes hijack, escalation and lateral movement in seconds.
Comments (0)
Log in to join the discussion
Log InNo comments yet