A cybersecurity nonprofit whose entire mission is warning others about vulnerabilities has itself been breached, and it believes an AI agent did the hacking. On September 24, 2026, the Dutch Institute for Vulnerability Disclosure (DIVD) announced that attackers had broken into its systems. Over the following week, DIVD revealed that the attacker exploited two previously unknown vulnerabilities in Zammad, a popular open-source helpdesk and ticketing system, and stole volunteer data. Zammad has not yet released official patches.
If your organization runs Zammad, or any self-hosted helpdesk, this story is directly relevant to you. And even if you do not, it offers one of the clearest real-world looks, yet at what an AI-driven attack can look like and how a well-run organization responds to one.
What Happened at DIVD?DIVD is a Netherlands-based volunteer organization that scans the internet for vulnerable systems and alerts their owners. After detecting suspicious activity, DIVD went into what it called "full incident response mode." It blocked access to its infrastructure, started a forensic investigation with a third-party incident response team, notified the people directly affected, and reported the incident to the Dutch data protection authority (Autoriteit Persoonsgegevens), the National Cyber Security Centre, and law enforcement.
DIVD then did something many organizations avoid: it published regular, detailed public updates. Its stated policy was to be "open, transparent and honest, even if it sucks." Those updates revealed:
- The attacker was likely an agentic AI, meaning an AI system that takes actions on its own rather than simply answering questions.
- The attack exploited two zero-day vulnerabilities in Zammad, identified with help from Merlon Security and now reported to the Zammad developers.
- Volunteer data was accessed and stolen, including DIVD email addresses and possibly contact details.
DIVD has advised anyone who receives suspicious communications claiming to be from DIVD to verify them through an official DIVD email address and has promised its next public update no later than October 9, 2026.
The Two Zammad Vulnerabilities, Explained On their own, each of these flaws is serious. Chained together, they take an attacker from outside the helpdesk portal to complete control of the server it runs on.
| Vulnerability |
Type |
What it allows |
| CVE-2026-102489 |
Session hijack leading to remote code execution |
An attacker can run their own code on the Zammad
server remotely |
| CVE-2026-102490 |
Local privilege escalation |
The local Zammad user account can escalate to
full root (administrator) control |
Two zero-days chained together: from helpdesk portal to root access to stolen data.
Is Your Zammad Version at Risk?
According to DIVD, the vulnerabilities are exploitable in Zammad 6.3.0 through 6.5.4. The flaws are also present in Zammad 7.0.0 through 7.1.3, but DIVD says they are not exploitable in those versions "due to environment conditions." Zammad has not yet released fixes.
Version 7 reduces the immediate risk, but official patches are still needed.
DIVD's guidance is direct: update to Zammad version 7 as soon as possible, or take your instance offline. DIVD is also actively scanning the internet for vulnerable Zammad servers and notifying their owners, so do not be surprised if your organization receives such a notice.
Why Helpdesk Systems Are Such Attractive Targets It is easy to think of a ticketing system as a back-office tool. Attackers see it differently. A helpdesk often contains:
- Names, email addresses, and phone numbers for customers and employees
- Internal conversations about problems, outages, and security issues
- Screenshots, attachments, and configuration details
- Passwords, license keys, or access codes that someone shared "just this once" in a ticket
- A trusted email address that customers expect to hear from
That last point matters. If an attacker controls your support system, they can send phishing messages that come from a real, trusted address and reference real ticket numbers. That makes the follow-on scams far more convincing.
What the AI Angle Really Means
Headlines have focused on the "AI hacker" angle, and SANS NewsBites editors offered a healthy range of views. John Pescatore warned against letting "agentic AI" become the new buzzword excuse, much as "Advanced Persistent Threat" once was. The core problem, he noted, was two exploitable vulnerabilities.
Ed Skoudis highlighted a fascinating detail from DIVD's updates: the attacking agent was "loud," "messy," and prone to "overexplaining in its comments." If that assessment holds up, it suggests that machine-speed attacks are not necessarily stealthy attacks. An AI agent may generate a large amount of observable activity very quickly. That makes good logging, telemetry, and rapid containment more valuable than ever, because there may be plenty of evidence to catch, if someone is watching.
Lee Neely's takeaway was the most practical: assume attackers will use every resource available, including AI, to find weaknesses, and go back to the basics. Defense in depth. A web application firewall. Phishing-resistant MFA. Monitoring and alerting. Keeping systems updated and securely configured. Not exposing management interfaces.
A Model for Breach Communication
Several editors praised DIVD's transparency. As editor Brian Honan put it, organizations are rarely judged simply for being the victim of a cyberattack, but they are judged on how they respond. DIVD's frequent updates showed what good incident communication looks like.
DIVD's response followed the classic incident response playbook, with public communication at every stage.
Every business should ask itself: if our helpdesk or another key system were breached tomorrow, would we know who to call, what to say, and how to reach affected customers if our main website or email were down?
How to Protect Your Organization Now
Whether you run Zammad or a different helpdesk platform, these steps reduce your risk:
1. Upgrade Zammad to version 7 now. If you cannot upgrade immediately, take the instance offline or block access from the internet. Watch for official Zammad patches and apply them as soon as they are released.
2. Check for signs of compromise. Review server and application logs for unusual sessions, unexpected processes, new accounts, or large data transfers, especially if your instance was internet-facing.
3. Keep management interfaces private. Place admin panels and agent portals behind a VPN, zero-trust access, or a web application firewall.
4. Require phishing-resistant MFA for every helpdesk agent and administrator account.
5. Keep secrets out of tickets. Train staff not to share passwords or sensitive data in tickets, and clean up old tickets that contain them.
6. Invest in monitoring and alerting. Fast, noisy attacks are easiest to stop when logs are centralized and someone is watching around the clock.
7. Write your breach communication plan now. Decide who notifies customers, regulators, and partners, and how, before you need to.
Not sure whether your helpdesk is exposed, or who is responsible for patching it? LBT Technology Group, LLC. can assess your self-hosted applications, check for signs of compromise, and put monitoring in place that catches attacks early. Reach out to our team for a quick review.
The Bottom Line
The DIVD breach is a preview of a world where attackers, human or AI, find and chain zero-days faster than ever. The defense is not exotic. It is the fundamentals done consistently: patch quickly, limit exposure, require strong authentication, watch your logs, and plan how you will communicate when something goes wrong. If you run Zammad, upgrade to version 7 today.
Frequently Asked Questions
Is there a patch for these Zammad vulnerabilities?
Not yet, as of DIVD's latest updates. The vulnerabilities have been reported to Zammad's developers. In the meantime, DIVD recommends upgrading to version 7, where the flaws are present but not currently exploitable, or taking vulnerable instances offline.
Was the attack really carried out by AI?
DIVD believes the attacker was likely using agentic AI, based on its behavior. Some experts caution against over-emphasizing the AI angle, since the underlying cause was two exploitable vulnerabilities. Either way, the defensive steps are the same.
I received an email claiming to be from DIVD. Is it real?
DIVD does contact owners of vulnerable systems. Because volunteer email addresses were stolen, DIVD recommends verifying any suspicious message by contacting an official DIVD email address directly rather than replying to the message.
We use a cloud-hosted helpdesk, not Zammad. Should we worry?
This specific flaw affects Zammad. But the lessons apply to any helpdesk: limit who can access it, require MFA, keep sensitive data out of tickets, and confirm your provider monitors for and patches vulnerabilities quickly.
Sources & Further Reading