• Tech Support ⤴
  • Projects
  • Services
    • AI Development
    • UI/UX Design
    • Web Development
    • Technology Support
    • Mobile App Development
    • Banking ATM Interfaces
    • Process Automation
    • Security Auditing
    • Local AI Servers
  • odoo ERP
get in touchStart with Eva
logo
Tech Support ⤴
Projects
Services
AI DevelopmentUI/UX DesignWeb DevelopmentTechnology SupportMobile App DevelopmentBanking ATM InterfacesProcess AutomationSecurity AuditingLocal AI Servers
odoo ERP
get in touchStart with Eva
Loading…
logo

Transforming businesses through AI-powered digital innovation and creative excellence.

Quick Links

BlogAinexProjectsContact us

Contact Us

pinDubai Digital Park, A5, DTEC - Silicon Oasisemail[email protected]phone+971 55 7538087
© 2026 aratech. All rights reserved.
Privacy PolicyTerms of ServiceCookie Policy
Home / Blog / An AI Agent Hacked the Hackers: DIVD Breached via Chained Zammad Zero-Days

An AI Agent Hacked the Hackers: DIVD Breached via Chained Zammad Zero-Days

An autonomous AI agent chained two Zammad zero-days to breach the Dutch Institute for Vulnerability Disclosure itself, reaching root in seconds and exfiltrating data. Here's exactly how the chain works and what your team should do this week.

October 3, 2026 - 6 min read

Key Takeaways

ExpandCollapse
  • - An autonomous AI agent chained two Zammad zero-days (CVE-2026-102489 and CVE-2026-102490) to breach DIVD, escalating from unauthenticated access to root in seconds
  • - The chain started on a public helpdesk endpoint: session hijacking led to RCE as the zammad service user, then local privilege escalation to root
  • - The agent made autonomous decisions during the intrusion - chaining exploits, pivoting to other services, and exfiltrating data without human direction
  • - If you run Zammad in any version, update to version 7 or take it offline; the chain is in CISA's Known Exploited Vulnerabilities catalog
  • - Segmentation and fast incident response contained the breach - your helpdesk should never be a trust stepping stone from web form to internal infrastructure
Glowing AI agent silhouette dissolving into code streams pouring into a dark server terminal

The Dutch Institute for Vulnerability Disclosure spends its days scanning the internet, finding holes in other people's software, and politely telling them how to fix it. On September 21, 2026, an autonomous AI agent flipped the script and found the holes in theirs.

Not with a sophisticated supply-chain compromise. Not with a nation-state zero-day arsenal. With two flaws chained in an open-source helpdesk system — and the machine speed of an agent that doesn't wait for a human to press enter.

By the time DIVD's teams caught up, the attacker had root on the box, had reached other internal services, and had read and exfiltrated data. The whole privilege ladder, from unauthenticated stranger to root, took seconds.

When the Vulnerability Hunters Become the Vulnerability

DIVD is a nonprofit of volunteer researchers who notify system owners about flaws before criminals exploit them. Being attacked isn't a shock for them — it comes with the territory. What makes this case different is how the attack ran.

DIVD discovered the intrusion while working an earlier case in which it determined it had been compromised through AI agent activity. Digging into how attackers actually got in, DIVD and its research partner Merlon Security reconstructed the path and identified two previously unknown vulnerabilities in Zammad, the open-source ticketing and helpdesk platform DIVD used internally.

Their write-up on the incident, tracked as DIVD-2026-00015, is blunt about what happened next. As the organization put it: "When hackers get hacked, we deal with it in hacker style."

The Two Zero-Days

The chain is built from two Zammad flaws, both now assigned CVEs:

  1. CVE-2026-102489 — a session hijacking flaw reachable in Zammad 6.3.0 through 6.5.4. An attacker can hijack legitimate sessions and escalate the defect into remote code execution as the zammad service user. (The defect also exists in 7.0.0 through 7.1.3, but environmental conditions block exploitation there.)
  2. CVE-2026-102490 — a local privilege escalation flaw that has existed since version 1.5.0, through 7.1.0-alpha. Once code runs on the host as the service user, this takes the attacker the rest of the way to root.

Each flaw is serious on its own. Chained, they form a straight line: unauthenticated access on a public web endpoint, to RCE, to full root control of the server.

Root in Seconds — the Agentic Speedup

Here's the part that matters for every team running internet-facing software: the speed was the AI agent's signature.

DIVD's disclosure states it plainly. From a Zammad user, to root, in seconds — "due to the agentic part of this hack." The agent analyzed the environment, chained the two vulnerabilities, escalated privileges, and moved to other services without a human directing every step. It made decisions and executed the next move on its own, compressing an attack sequence that historically takes hours of manual work into moments.

After reaching root, the attacker accessed other services, read data, and exfiltrated some of it. Network segmentation and a fast response from DIVD's IT and incident response teams stopped the intrusion before it spread further — but not before some damage was done.

DIVD detected the attack partly because the agent was noisy: it left visible traces that helped investigators reconstruct everything. That's a comfort, but an uncomfortable one. A more disciplined attacker running the same agentic tooling could stay much quieter.

Why a Helpdesk Is a Tier-0 Target

The choice of target vector is worth sitting with. Zammad is popular open-source software — more than 2,000 customers and 55,000 users — and helpdesks are one of the most exposed systems any organization runs.

Think about what lives in a support desk: full name, email, phone numbers, correspondence with external partners, credentials shared in ticket threads, links to internal systems, and a habit of attaching screenshots that were never meant for prying eyes. A helpdesk is a pre-indexed map of your organization, accessible to anyone who can reach the login page.

That's why an RCE chain into a ticketing system is never just a ticketing problem. It's an identity problem, an access problem, and a lateral movement problem, all at once.

What To Do This Week

If your organization runs Zammad in any version, the guidance from DIVD and Zammad is unambiguous:

  1. Update to Zammad version 7, or take the system offline. Version 7 is considered safe; every older version is presumed exploitable. Don't wait for a patch window — this chain is in CISA's Known Exploited Vulnerabilities catalog.
  2. Assume prior compromise. The DIVD chain is silent until an attacker does something loud. Hunt the supplied indicators in your logs and look for unexpected sessions, odd user activity in the helpdesk, and any unrecognized local accounts.
  3. Rotate everything the helpdesk can reach. Tickets routinely carry credentials, tokens, and API keys. Treat anything stored in or sent through the system as potentially exposed.
  4. Cut the helpdesk out of the trust zone. The only reason this breach stayed contained was segmentation. Your ticketing system should never be a stepping stone from a web form to internal infrastructure.
  5. Model the machine-speed threat. Run the scenarios your response plan needs to survive when the attacker moves in seconds, not hours: containment decisions, credential rotation, and management comms all rehearsed at that tempo.

The Bigger Picture: Agentic Attacks Have Arrived

For years, AI in security conversations lived in two boxes: AI helping defenders find and patch faster, and AI-generated phishing getting more convincing. The DIVD breach breaks out of both boxes. This was an AI agent performing the entire intrusion chain — reconnaissance, exploitation, privilege escalation, lateral movement — against a real organization, with real consequences.

It also landed on an ironic target. The institute whose core mission is finding vulnerabilities before they're exploited was itself breached through vulnerabilities nobody knew about. Nobody at DIVD was careless; the flaws existed in code thousands of organizations run.

That's the strategic takeaway for our clients across the GCC and beyond: your security posture is only as strong as the least-watched open-source system you've exposed to the internet, and your adversaries now operate at machine speed. Defense still wins — segmentation, rapid response, and aggressive patching contained this in hours — but the window for manual, ticket-driven remediation is shrinking every month.

An AI agent took over a security nonprofit's infrastructure in seconds. The next one may be quieter. Make sure your stack is ready before, not after.

At aratech, we help organizations harden the systems attackers actually target — helpdesks, identity planes, and the AI infrastructure now entering the kill chain on both sides. If your internet-facing stack hasn't been modeled against agentic-speed attacks, that's the first conversation to have.

Table of Contents

  • ↗When the Vulnerability Hunters Become the Vulnerability
  • ↗The Two Zero-Days
  • ↗Root in Seconds — the Agentic Speedup
  • ↗Why a Helpdesk Is a Tier-0 Target
  • ↗What To Do This Week
  • ↗The Bigger Picture: Agentic Attacks Have Arrived

Related Posts

Glowing AI core surrounded by a shield lattice with guardrail plates floating away, dark cyberpunk circuit background in purple and cyan

Gemini 4 Argon: Google Just Shipped a Frontier AI With the Guardrails Off

Google's new frontier model Gemini 4 Argon is rolling out to trusted cyber defenders through the Fairwind Program — with a guardrail-free version planned. It has already found a previously unknown critical vulnerability in healthcare software used by hospitals worldwide.

Necolas HamwiNecolas Hamwi
October 2, 2026 - 7 min read
Neon wireframe shield of circuit traces and hexagonal panels protecting a stream of glowing purple encrypted payment data, with cyan scanner lines revealing red-amber vulnerability sparks

Visa Just Gave Away Its AI Cyber Defense Playbook - and It's Not Charity

Visa open-sourced its Vulnerability Agentic Harness after AI stress-testing with Anthropic's Claude Mythos surfaced more than 10,000 high and critical vulnerabilities in a single month. The four-phase framework automates discovery, triage, remediation, and validation.

Necolas HamwiNecolas Hamwi
October 1, 2026 - 7 min read
Stylized Citrix NetScaler gateway appliance glowing over a dark circuit-board grid with a root shell prompt exposed

Citrix NetScaler CVE-2026-88771/88772: Exploited in the Wild

Two critical Citrix NetScaler zero-day RCEs were actively exploited before Citrix's September 27 bulletin. Here is what CVE-2026-88771 and CVE-2026-88772 actually do, the fixed builds, and why forensics must come before patching.

Necolas HamwiNecolas Hamwi
September 30, 2026 - 9 min read