The Dutch Institute for Vulnerability Disclosure (DIVD) says its network was breached after attackers exploited two previously unknown (“zero-day”) vulnerabilities in the open-source Zammad ticketing system. DIVD reports the flaws, when chained together, allow attackers to hijack sessions, execute remote code, and escalate privileges from the Zammad user to root.
The outlets describe the incident as involving an “agentic” AI-powered element, framing the attack as automated or orchestrated by AI. Bleeping Computer and Infosecurity Magazine both focus on DIVD’s disclosure that the breach relied on the two Zammad zero-days, while Help Net Security adds more detail about what the attacker is able to do after gaining root access, including reaching other services and reading internal data. Across coverage, the central points are the same: a Zammad weakness is the initial entry path, two zero-days are used together, and DIVD identifies the use of an AI-enabled agent in carrying out the intrusion.