Select a theme from the list.
Insights

From our experts

Latest
OpenSSL DTLS Bug Can Spill Heap Data Outside the Encrypted ChannelAI-Speed Intruder Chains Zammad Zero-Days Into Root AccessCrafted Emails Turn Zimbra Servers Into Command-Execution GatewaysRansomware Disrupts Business Systems at Major Japanese Railway GroupStolen Passwords Left French Tax Data Exposed for Seven WeeksCheap AI Decisions Could Create an Expensive Security ProblemApple Closes CoreGraphics Flaw Linked to Sophisticated Targeted AttacksThousands of Supabase Databases Leak the Secrets Behind Rapid App DevelopmentNeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows NetworksSharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer WorkloadsOpenSSL DTLS Bug Can Spill Heap Data Outside the Encrypted ChannelAI-Speed Intruder Chains Zammad Zero-Days Into Root AccessCrafted Emails Turn Zimbra Servers Into Command-Execution GatewaysRansomware Disrupts Business Systems at Major Japanese Railway GroupStolen Passwords Left French Tax Data Exposed for Seven WeeksCheap AI Decisions Could Create an Expensive Security ProblemApple Closes CoreGraphics Flaw Linked to Sophisticated Targeted AttacksThousands of Supabase Databases Leak the Secrets Behind Rapid App DevelopmentNeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows NetworksSharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer Workloads
Security Insight

AI-Speed Intruder Chains Zammad Zero-Days Into Root Access

AI-Speed Intruder Chains Zammad Zero-Days Into Root Access
Photo by Ann H on Pexels

The Dutch Institute for Vulnerability Disclosure says two previously unknown Zammad vulnerabilities enabled an AI-driven attacker to hijack sessions, execute code and obtain root access. The automated intrusion reportedly reached connected services and exfiltrated data within seconds, although network segmentation limited further movement.

News Date: 2026-09-30

An attack against the Dutch Institute for Vulnerability Disclosure has provided a striking example of what happens when software vulnerabilities are combined with machine-speed decision making. According to the organization, an autonomous AI agent chained two zero-day flaws in the Zammad helpdesk platform to compromise systems and rapidly explore the surrounding environment.

From Session Hijacking to Root

The vulnerabilities are identified as CVE-2026-102489 and CVE-2026-102490. Used together, they reportedly enabled session hijacking, remote code execution and privilege escalation from the Zammad service account to root. Once inside, the attacker accessed additional services and extracted data in a matter of seconds.

Zammad is an open-source ticketing and support platform available in hosted and self-managed forms. Helpdesk systems are attractive targets because support tickets frequently contain internal hostnames, screenshots, credentials, recovery instructions and detailed descriptions of operational problems. They can also be connected to email systems, identity providers and administrative tools.

DIVD previously described the attack as noisy and disorganized, but the automation behind it still made the intrusion dangerous. The agent reportedly selected its next actions without continuous human direction. Ironically, it also left explanations of its decisions behind, helping investigators reconstruct what happened.

Segmentation Limited the Damage

The incident did not progress deeper into DIVD's network because segmentation and incident-response measures restricted the attacker's available paths. That detail is important. Preventive security did not stop the initial compromise, but architectural controls reduced the blast radius after exploitation succeeded.

What Zammad Operators Should Do

  • Upgrade affected deployments to Zammad version 7, which DIVD considers safe.
  • Take vulnerable systems offline if they cannot be updated immediately.
  • Invalidate existing sessions and rotate credentials accessible to the application.
  • Review connections from the helpdesk server to internal services.
  • Search for unexpected commands, new accounts, altered services and unusual data transfers.

I believe the larger lesson is not that AI has created an entirely new category of vulnerability. The weaknesses were still conventional software flaws. The difference was tempo. An autonomous attacker can test possibilities, change tactics and exploit connected services faster than a human analyst can process a conventional alert.

Defenders therefore need containment controls that work even when nobody has reviewed the incident yet. Strong segmentation, limited service permissions and automated isolation can turn an AI-speed compromise from an enterprise-wide emergency into a contained investigation.

Talk to our team →

Latest

OpenSSL DTLS Bug Can Spill Heap Data Outside the Encrypted ChannelOct 1, 2026AI-Speed Intruder Chains Zammad Zero-Days Into Root AccessOct 1, 2026Crafted Emails Turn Zimbra Servers Into Command-Execution GatewaysOct 1, 2026Ransomware Disrupts Business Systems at Major Japanese Railway GroupSep 30, 2026Stolen Passwords Left French Tax Data Exposed for Seven WeeksSep 30, 2026Cheap AI Decisions Could Create an Expensive Security ProblemSep 30, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards