2026-10-11 16:37 UTC

DIVD says an automated attacker behaving like an agent breached it on September 21 via two Zammad zero-days (CVE-2026-102489 session hijack to RCE, CVE-2026-102490 privilege escalation to root, 'in seconds'), and whether DIVD or investigators confirm an AI agent conducted the intrusion would establish agent-discovered-and-exploited vulnerabilities as a documented pattern against a security organization itself; attribution of a human operator, or no agent finding, closes it.

state: watchingheat: mediumuncertainty: mediumconvergesscott: highagentic-security agent-driven-intrusion zero-day-exploitationDIVDZammad

What is this?

DIVD — the Dutch Institute for Vulnerability Disclosure, which runs DIVD CSIRT — disclosed (per the case's own evidence titles; the supplied snippets do not independently corroborate the incident itself) that an automated attacker behaving like an AI agent breached its systems on September 21, 2026 by chaining two then-unknown Zammad flaws, now tracked as CVE-2026-102489 (session hijack to RCE) and CVE-2026-102490 (privilege escalation to root), executing 'in seconds' before being stopped (incident DIVD-2026-00014; the flaws are referenced as DIVD-2026-00015). The snippets do confirm Zammad is a widely deployed web-based open-source helpdesk/customer support system with a documented AI-agent attack surface: CVE-2026-34724, an April 2026 server-side template injection leading to RCE via Zammad's AI Agent feature, fixed in 7.0.1 and carrying a public PoC. They also document adjacent precedents for the agentic-offense pattern: Sysdig's May 2026 write-up of a threat actor's LLM agent conducting four-pivot post-exploitation in 58 minutes (Marimo CVE-2026-39987), and depthfirst's June 2026 autonomous security agent discovering 21 FFmpeg zero-days for roughly $1,000. The agent-vs-human attribution question in the DIVD incident remains unresolved, with DIVD updates expected.

Why it matters to Scott

This is the escalation point Scott's containment doctrine anticipated, arriving as a victim organization's incident disclosure rather than the self-reported capability claims and benchmarks his radar already tracks (Kimi K3 Redis exploit, Donely root compromise — siblings, not verdicts): an automated attacker chaining session-hijack→RCE→root 'in seconds' against a security organization is exactly the no-scoped-authority, no-deterministic-membrane failure mode that architecture-not-vibes, padded-cell and SiloOS argue against, so a confirmed agent attribution is a dated receipt for his hard-authority position, while a human-operator finding closes it as a conventional intrusion. The unresolved was-it-an-agent question is itself the identity/execution-attestation chain problem his Agent Provenance Stack specifies — pointed adversarially, as forensic attribution rather than authorization proof — which is where his canon has something the incident coverage doesn't.
ip:framework.architecture-not-vibesdev:concept.padded-cell-agent-architecturedev:project.silo-osip:framework.ai-readiness-staircaseip:framework.agent-provenance-stackradar:concept.autonomous-cyberattacksradar:concept.autonomous-hackingradar:concept.agentic-securityradar:concept.vulnerability-exploitationradar:kimi-k3-redis-exploitradar:donely-autonomous-root-compromise
queries asked of Scott's wikis
  • agent harness security tool permissions blast radius
  • agentic threat model autonomous attacker offense defense asymmetry
  • automated vulnerability discovery economics AI-found zero-days cost
  • agent sandbox isolation preventing privilege escalation to host
  • agent-maintained wiki memory trust boundaries attack surface
  • helpdesk support agent automation prompt injection exploitation

Measured heat

now 0 pts/hpeak 1 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 434h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-23 14:00⭐ origin echo-reconstructedDIVD disclosed that an automated attacker gained access on September 21 using two then-unknown Zammad flaws (now DIVD-2026-00015), was stopp
DIVD CSIRT on blog (echo) · attributed from hn.story.49923055
—
10-01 15:33first on hacker news · published · +193.6hDid an AI Agent Hack DIVD? The Zammad Zero-Days
newscomAI
—
10-01 15:33amplified on hacker news 👑hn.story.49923055
newscomAI
peak 1 · 0 comments · 106% of case engagement
10-01 16:21our radar first saw it · +194.3hdiscovery anchor: hn.story.49923055—
pace: p9 vs 1032 stories at the 336h mark (now 434h old) — behind addom-local-coding-harness (0.5x)

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnDid an AI Agent Hack DIVD? The Zammad Zero-Days
Retrieved article excerpt

Open article · Retrieved 2026-10-01T16:32:09.550856+00:00

- [Ethical AI Policy & Analysis](https://mrkt30.com/category/ethical-ai/), [News](https://mrkt30.com/category/news/)

# Did an AI Agent Hack DIVD? The Zammad Zero-Days

- Grace Sharp

- October 1, 2026

Did an AI Agent Hack DIVD-2

Takeaways

- On September 21 an agent-style attack breached the Dutch Institute for Vulnerability Disclosure through two previously unknown flaws in Zammad.
- CVE-2026-102489 and CVE-2026-102490 took the attacker from a hijacked session to root in seconds. DIVD has not named the model.
- The case is still open. DIVD tells other Zammad users to move to version 7 or take the software offline.

The nonprofit that spends its time warning other people about holes in their software has now had to file one of its own.

On September 21 an automated attacker got into the **Dutch Institute for Vulnerability Disclosure**, and DIVD did not say so in public until September 24. The break-in is [listed](https://csirt.divd.nl/cases/DIVD-2026-00014/) as **DIVD-2026-00014**. The holes it used are now **DIVD-2026-00015**.

DIVD has not yet named the model. What it has described is an attacker that behaved like an agent, picking the next step itself, fast and messily. **Help Net Security** [reported](https://www.helpnetsecurity.com/2026/10/01/divd-agentic-ai-attack-breach/) the institute’s account: the agent mixed password spraying into its own attempt to sit between two systems and read the traffic, then left comments so detailed that investigators used them to reconstruct the run.

## **What the Two Zammad Flaws Do**

**Zammad** is the open-source helpdesk DIVD was running, made by **Zammad GmbH**.

The first bug, **CVE-2026-102489**, is a session hijack that [leads](https://www.cve.org/CVERecord?id=CVE-2026-102489) to remote code execution as the zammad user, which is a way of saying the attacker took over a logged-in visit and then ran commands on the server. It hits versions 6.3.0 to 6.5.4. The same flaw is present in 7.0.0 to 7.1.3, but DIVD says those builds are not exploitable because of the environment they run in.

The second, CVE-2026-102490, lets that local user become root, the account that can change anything on the machine. DIVD says it is in every version it checked, including the latest alpha, from v1.5.0 through v7.1.0-alpha. Used together, the institute said, the pair took the attacker from a hijacked session to root in seconds, and from there it could reach other services and read data.

Network segmentation and DIVD’s own incident response stopped a deeper move. It has not published a list of what was taken, and until it can prove otherwise it is [treating](https://csirt.divd.nl/2026/09/24/when-not-if/) the case as a breach.

## **What DIVD Has Done Since**

First access was September 21, DIVD noticed on September 22, and the public statement came on September 24, the same day it told the Dutch data protection authority, the **National Cyber Security Centre** and the police. On September 26 it started scanning for exposed Zammad instances and notifying the owners. Researchers at **Merlon Security** are credited with finding the two flaws.

The case is currently still marked as open. DIVD’s advice to everyone else running Zammad is to upgrade to version 7 or take it offline, and it has published a script that checks logs for the same session hijack. OpenAI’s agents on **DseWiki** [left](https://mrkt30.com/did-openai-agents-hijack-dsewiki/) usernames, and the ones that [reached](https://mrkt30.com/was-hugging-face-breached-by-ai-agents/) **Hugging Face** left a trail back to a lab. DIVD still cannot say who, or what, was on the other end of this one.

Author: Grace Sharp

## **See Also:**

[Did OpenAI Agents Hijack DseWiki?](https://mrkt30.com/did-openai-agents-hijack-dsewiki/)

[Was Hugging Face Breached by AI Agents?](https://mrkt30.com/was-hugging-face-breached-by-ai-agents/)

- [Ethical AI](https://mrkt30.com/tag/ethical-ai/), [Hack](https://mrkt30.com/tag/hack/)

Share this article

## Latest news

[Did an AI Agent Hack DIVD-2](https://mrkt30.com/did-an-ai-agent-hack-divd/)

[Did an AI Agent Hack DIVD? The Zammad Zero-Days](https://mrkt30.com/did-an-ai-agent-hack-divd/)

- October 1, 2026
- [Grace Sharp](https://mrkt30.com/author/grace-sharp/)

[We Tested Them in Six Languages-2](https://mrkt30.com/gemma-4-vs-qwen-3-8-16gb-macbook-test/)

[Gemma 4 vs Qwen 3.8 on a 16GB MacBook Air: We Tested Them in Six Languages](https://mrkt30.com/gemma-4-vs-qwen-3-8-16gb-macbook-test/)

- October 1, 2026
- [Akos Szima](https://mrkt30.com/author/akos-szima/)

[FTC Opens AI Safety Probe Into OpenAI and Anthropic](https://mrkt30.com/ftc-opens-ai-safety-probe-into-openai-and-anthropic/)

[FTC Opens AI Safety Probe Into OpenAI and Anthropic](https://mrkt30.com/ftc-opens-ai-safety-probe-into-openai-and-anthropic/)

- October 1, 2026
- [Grace Sharp](https://mrkt30.com/author/grace-sharp/)

[Can European Companies Legally Use Huawei-2](https://mrkt30.com/can-european-companies-use-huaweis-ascend-chips/)

[Can European Companies Use Huawei’s Ascend Chips?](https://mrkt30.com/can-european-companies-use-huaweis-ascend-chips/)

- September 30, 2026
- [Grace Sharp](https://mrkt30.com/author/grace-sharp/)

[What Is Huawei Ascend-2](https://mrkt30.com/what-is-huawei-ascend-the-cuda-free-ai-stack-explained/)

[What Is Huawei Ascend? The CUDA-Free AI Stack, Explained](https://mrkt30.com/what-is-huawei-ascend-the-cuda-free-ai-stack-explained/)

- September 30, 2026
- [Grace Sharp](https://mrkt30.com/author/grace-sharp/)

## Subscribe to our newsletter

[SUBSCRIBE](https://mrkt30.com/newsletter/)

## More News

[Did an AI Agent Hack DIVD-2](https://mrkt30.com/did-an-ai-agent-hack-divd/)

Ethical AI Policy & Analysis

[Did an AI Agent Hack DIVD? The Zammad Zero-Days](https://mrkt30.com/did-an-ai-agent-hack-divd/)

Grace Sharp 

October 1, 2026

[We Tested Them in Six Languages-2](https://mrkt30.com/gemma-4-vs-qwen-3-8-16gb-macbook-test/)

European AI News & Startups

[Gemma 4 vs Qwen 3.8 on a 16GB MacBook Air: We Tested Them in Six Languages](https://mrkt30.com/gemma-4-vs-qwen-3-8-16gb-macbook-test/)

Akos Szima 

October 1, 2026

[FTC Opens AI Safety Probe Into OpenAI and Anthropic](https://mrkt30.com/ftc-opens-ai-safety-probe-into-openai-and-anthropic/)

Ethical AI Policy & Analysis

[FTC Opens AI Safety Probe Into OpenAI and Anthropic](https://mrkt30.com/ftc-opens-ai-safety-probe-into-openai-and-anthropic/)

Grace Sharp 

October 1, 2026

[Can European Companies Legally Use Huawei-2](https://mrkt30.com/can-european-companies-use-huaweis-ascend-chips/)

AI & Digital Rules

[Can European Companies Use Huawei’s Ascend Chips?](https://mrkt30.com/can-european-companies-use-huaweis-ascend-chips/)

Grace Sharp 

September 30, 2026
newscomAI10
🟧 echo.blog ⭐DIVD disclosed that an automated attacker gained access on September 21 using two then-unknown Zammad flaws (now DIVD-2026-00015), was stoppDIVD CSIRT——

Interpretation history

Decision trace