DIVD says an autonomous AI agent chained two Zammad zero-days to break into its network in seconds
The Dutch vulnerability-disclosure nonprofit says the agent left explanations of its own decisions behind, which let investigators reconstruct the September 21 attack.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.
The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit of volunteer security researchers, says the September 21 breach of its network relied on two zero-day vulnerabilities in Zammad, an open-source support-ticketing system. DIVD had already described the intrusion as "loud and very, very messy" and said it was driven by an AI agent that moved autonomously and chose its next steps without outside direction. According to SecurityWeek, the first flaw, CVE-2026-102489 (CVSS 9.4), lets unauthenticated attackers run code remotely and leak user sessions. The second, CVE-2026-102490 (CVSS 9.4), lets a local user escalate privileges to root. DIVD says that used together, the flaws let attackers hijack sessions, execute code and go from the Zammad user to root "in seconds, due to the agentic part of this hack." The attacker then reached other services and read and exfiltrated data. BleepingComputer reports that the agent left clear explanations of its decisions, which allowed DIVD to reconstruct the incident. DIVD says network segmentation and its incident response kept the intruder from moving deeper into the network. The organization notified Dutch authorities, and the investigation is still under way. Organizations that run Zammad should watch for fixes for both flaws.