ESPNFollow live: Braves taking control after Ozzie Albies' two-run homer extends Game 3 leadESPN DeportesSteelers y Browns en divertido partido por la división en ClevelandPunch‘I didn’t declare myself winner of Gombe PDP gov primary’The Jerusalem PostIsraeli EuroCup, EuroLeague teams open their continental campaigns with mixed results across EuropeCNN TürkABD, Suriye'yi savunma ticareti kısıtlamaları listesinden çıkardı한겨레참여연대 “검찰청 폐지 자업자득…중수청, 제2의 검찰청되면 안 돼”UOLFlávio Bolsonaro diz que Lula 'vai ser expulso da Presidência no domingo'Globo EsporteNovorizontino x Goiás - Campeonato Brasileiro Série B 2026 - Ao vivo - globoesporte.com매일경제쓰레기봉투 속 현금 2500만원…주인 못 찾아 최초 발견자 손으로3DNewsСуд в США признал иски издателей к Google из-за потери трафика по вине ИИ несостоятельными경향신문대구, ‘의료급여사업’ 예산 62억원 추가···특화사업으로 효율도↑自由時報南韓廢除78年檢察廳!偵查、起訴分家 「恐龍警察」接手引憂
The Daily Newsstand · Free, Always
Friday, October 2, 2026

AI agents hacked the hackers, stealing email addresses from security research org

Translate

Chained Zammad flaws enabled session hijacking, code execution, and root escalation in seconds

AI agents hacked the hackers - the Dutch Institute for Vulnerability Disclosure (DIVD) - via two zero-day bugs in its Zammad support platform, abusing the flaws to hijack sessions, run code remotely as the local zammad user, and escalate privileges to root.

The chained exploits took just seconds to move from session hijacking to root access, and on Thursday, the nonprofit bug hunting organization said the miscreants stole data belonging to its volunteer security researchers, including DIVD email addresses and potentially other contact details.

“We’re still investigating exactly which data of which volunteers is affected,” DIVD said in its incident report. “For DIVD volunteers (and others) this means a higher risk of social engineering, because this makes it easier for someone to pose as a DIVD’er.”

REG AD

A subsequent LinkedIn post advised anyone receiving an email or contact request from someone at DIVD “that feels slightly off” to verify that it’s legit by emailing communications@divd.nl.

REG AD

DIVD is also a CVE Numbering Authority (CNA), and it assigned CVE IDs to the now-public security holes in Zammad, an open-source helpdesk and customer support ticketing system. They are CVE-2026-102489 and CVE-2026-102490, and both bugs received CVSS 4.0 scores of 9.4, when assessed in the chained attack scenario.

CVE-2026-102489 enables unauthenticated attackers to achieve remote code execution and leak user sessions, while CVE-2026-102490 allows a local user to elevate their privileges to root. 

Zammad versions 6.3.0 to 6.5.4 are vulnerable to CVE-2026-102489, and it also exists in versions 7.0.0 through 7.1.3 - but it’s not exploitable “due to environment conditions,” according to DIVD’s advisory.

All Zammad versions are vulnerable to CVE-2026-102490. DIVD advises “all users of Zammad to upgrade to version 7 of Zammad or to take it offline.”

What happened

According to the nonprofit’s timeline, the attack happened on September 21, when "malicious actors” broke into its IT system via the two zero-days in its ticketing support software.

The bug hunters discovered the attackers the following day, blocked access to all of its data center systems, and formed an incident response team with Merlon Security.

On September 24, DIVD reported the Zammad vulnerability to the vendor, notified the Dutch Data Protection Authority and the National Cyber Security Centre about the incident, and discussed its options with police. It also posted its first disclosure on LinkedIn.

REG AD

“It took us (almost) seven years but we can now say that we're the hackers that got hacked,” the post said, adding that DIVD remained committed to handling the incident in “the way we think it should be handled. That is open, transparent and honest, even if it sucks.”

'Modus operandi' indicates agentic AI

DIVD also noted that its team had never seen an attack like this before. 

“This is an attack we have not seen before,” according to the post. “Not because it’s our first, but because the modus operandi indicates that this is an agentic AI powered attack.”

The attack was "loud and very very messy," DIVD said. "We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern."

Subsequent posts with screenshots of logs found during the investigation reveal embedded notes found in the attack script - another indication that this was an agentic operation or at least AI-enabled.

“What human attacker leaves notes to themself in their scripts, explaining why what they're doing is okay and really not phishing? The AI just got a task and keeps justifying its own actions in the code as comments, a human wouldn’t care less," the post said. "Who has time for that anyway?”

REG AD

If only all orgs responded to hacks like this

While the investigation remains ongoing, security researchers applauded DIVD for its transparency in disclosing and responding to the hack.

“Kudos to DIVD for their level of honesty and transparency working through their active incident and investigation,” VulnCheck security researcher Patrick Garrity posted on LinkedIn. “It would be nice if all organizations were this transparent about their security incidents!”

In a subsequent interview with The Register, Garrity said he applauded DIVD’s “brutal honesty” about the breach. “They're eating their own dog food, which is great, and getting information out quickly to other organizations that potentially use this product so they can take action before they get hit.”®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.