TECH
AI agents breach Dutch vulnerability disclosure group using chained Zammad zero-days
The Dutch Institute for Vulnerability Disclosure suffered a breach on September 21 when AI-driven attackers exploited two zero-day flaws in its Zammad ticketing system, stealing email addresses of volunteer researchers and escalating to root access within seconds.
The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed on Thursday that automated AI agents compromised its infrastructure via two zero-day vulnerabilities in Zammad, the open-source helpdesk platform the non-profit uses for support ticket management.
The attack took place on September 21. The attackers chained CVE-2026-102489 and CVE-2026-102490—both carrying a combined CVSS 4.0 score of 9.4—to hijack sessions, execute code as the local 'zammad' user, and escalate privileges to root in seconds. DIVD discovered the intrusion the following day, cut off access to its data center systems, and engaged the incident response firm Merlon Security.
The breach exposed email addresses belonging to DIVD's volunteer security researchers. The organization warned that this creates an elevated risk of social engineering, as attackers can now more convincingly impersonate DIVD personnel. Anyone receiving suspicious contact from someone claiming an affiliation with DIVD should verify the claim via communications@divd.nl.
DIVD acts as a CVE Numbering Authority and assigned the identifiers itself. CVE-2026-102489 affects Zammad versions 6.3.0 through 6.5.4 and 7.0.0 through 7.1.3, although the vendor states that the 7.x branch is not exploitable due to environmental conditions. CVE-2026-102490 affects all versions of Zammad. DIVD urges all users to upgrade to Zammad 7 or take the software offline.
The offensive against DIVD highlights the evolution in the use of automated agents that operate using language models and task-execution modules. Unlike conventional scans—which follow static scripts to test for known vulnerabilities—AI agents attempt to interpret server responses, generate commands in real time, and dynamically iterate through potential weaknesses. This approach produces exploit traffic with unusual signatures, combining various probing techniques within a short timeframe.
For companies and security teams in Brazil, the significance of this case lies in the large-scale proliferation of this attack methodology. Corporate environments with internet-facing services, legacy portals, or inadequately protected APIs become targets of continuous, unstructured testing; this overwhelms Security Operations Centers (SOCs) with false-positive alerts and increases the risk of compromise due to basic configuration flaws.
The incident did not stem from a single zero-day vulnerability with a registered CVE identifier, but rather from a sequence of brute-force attempts, command injections, and tests for known flaws orchestrated by the agent. Common vectors for this type of agent include directory enumeration, the submission of varied payloads via HTTP parameters, and attempts to exploit exposed credentials or API keys.
The primary factor determining whether such an attack succeeds—or simply generates noise—is the direct exposure of services to the public network without edge-based behavioral mitigation. Environments that maintain accessible administrative interfaces and outdated systems, or lack request-rate limiting rules, end up absorbing the full testing cycle generated by the offensive agent.
An intruder that narrated Its own moves...In an update on Monday, DIVD described the attack as “loud and very very messy”. The agent chose each next step itself, at speed and with sloppy logic. At one point its password spraying disrupted its own adversary-in-the-middle attack.
It also over-explained its decisions in its comments. DIVD believes the agent was poorly trained and badly configured for the job and the trail it left is enough for investigators to reconstruct the intrusion.
The way in was an ordinary vulnerability in a system DIVD has not named. It has ruled out Citrix NetScaler whose two zero-days CISA added to its Known Exploited Vulnerabilities catalogue on 27 September.
What DIVD has not said yet...The purpose of the attack is unknown and so is what, if anything, the attacker took. DIVD is withholding technical detail so that it does not disturb the investigation or expose other organisations running the same vulnerable system and says it will notify them as soon as it can. A fuller update is due on 1 October.
Treat the agentic AI attack label as DIVD’s working assessment until then. It rests on how the intruder behaved, not on a recovered tool or a named model and nothing has been published that outsiders can check. The people making the call analyse intrusions for a living which counts for a lot. It does not replace the evidence.
Spain, ENISA and Microsoft flagged agent-driven attacks in September...DIVD’s case is not isolated. In mid-September Spain’s data protection agency, AEPD, said it had received its first breach notification describing an attack carried out by an AI agent built on a known large language model. The agency has not yet verified the organisation’s account.
On 22 September ENISA published its Threat Landscape 2026 which assesses that AI will highly likely support malicious operations to a growing degree and that 2026 may see experiments with attacks that run without a human in the loop. Three days later Microsoft described agent-driven attacks by a group it tracks as Storm-3168. The group used compromised Azure service principals and targeted more than 100 storage accounts in a destructive stage that lasted seven minutes.
DIVD spotted the activity itself...The most useful line in DIVD’s first statement is the least dramatic one, it noticed the suspicious activity itself. An intruder that picks its own next move at machine speed shortens the gap between foothold and damage, and a weekly log review will not close it.
Patch internet-facing systems against actively exploited flaws first. DIVD’s attacker still needed an ordinary vulnerability to get in and the agent only took over after that.
Hunt for automation inside the network, not only at the edge. Password spraying from internal hosts and bursts of commands issued faster than any person types are the patterns DIVD’s account points to.
If DIVD contacts your organisation once its investigation ends, treat the message as an incident report, not a courtesy notice.
How to check...Defense and AppSec teams should analyze logs from WAFs, load balancers, and web servers for anomalous request patterns. The behavior of an autonomous agent often manifests as bursts of sequential calls to various endpoints using synthetically generated parameter values, alongside variations in HTTP header composition—such as User-Agent strings and custom headers.
At the internal detection layer, SOC analysts should monitor for clusters of HTTP 400, 404, and 500 errors originating from a single source address or from residential and cloud service network ranges. It is also crucial to correlate these network events with endpoint telemetry (EDR) from edge servers, looking for the execution of atypical child processes—such as command-line interpreters or operating system utilities—launched by web services.
Agentic AI fingerprints...DIVD researchers stated that the attack exhibited characteristics typical of an agentic AI operation—behavior they had never encountered before. The intrusion was "noisy and very, very messy," featuring automated decision-making at machine speed and "sloppy logic or patterns."
Log screenshots shared by DIVD show comments embedded in the attack scripts where the agent justified its own actions, explaining why its steps were "ok and really not phishing." Human attackers rarely annotate their own exploit code with moral reasoning.
"What human attacker leaves notes for themselves in their scripts?" DIVD wrote. "The AI was simply given a task and keeps justifying its own actions in the code via comments. Who has time for that, anyway?"
Praised for transparent response...Security researchers praised DIVD's openness. Patrick Garrity of VulnCheck called it "brutal honesty" and noted that the organization is "eating its own dog food" by disclosing the issue quickly, allowing other Zammad users to apply fixes before being targeted. The DIVD reported the vulnerabilities to the vendor on September 24, notified the Dutch Data Protection Authority and the National Cyber Security Centre, and discussed the incident with the police. The investigation is ongoing.
mundophone


