Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

DIVD Says Zammad Flaws Enabled Network Breach

Published 2 October 2026

The Dutch Institute for Vulnerability Disclosure (DIVD) says attackers breached its systems by exploiting two previously unknown vulnerabilities in the Zammad helpdesk platform, gaining access to other services and extracting data before the organization contained their movement through its network. DIVD said the flaws were used together to hijack sessions, run code remotely and escalate privileges from a Zammad user account to root access. The organization attributed the speed and sequence of the attack to an autonomous artificial intelligence agent. That characterization reflects DIVD’s assessment of activity logs and scripts, including explanatory comments left by the agent; the investigation is continuing. The intrusion was reported on September 21, according to DIVD’s account, and suspicious activity was detected on September 24. The organization said network segmentation and actions by its information technology and incident-response teams prevented the attackers from moving farther into its systems. DIVD has not specified the full extent of the data accessed or removed, and said some damage had occurred before the response stopped the intrusion.

Now playing
0:00 / 0:00