An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system. “Used together, [the two flaws] allowed the attackers to hijack sessions, run code remotely and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack.
AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
About this summary. This is a short, independently written summary of an article first published by Help Net Security. Cyber Security News did not report or verify the underlying story. Read the original: https://www.helpnetsecurity.com/2026/10/01/divd-agentic-ai-attack-breach/

Source attribution: headline and facts are from Help Net Security (helpnetsecurity.com). Summary method: excerpt of the source description. See our source attribution policy.





