Skip to content
World clockEU--:--UK--:--USA--:--CN--:--PLDEFRIT中文EN

portal about AI and technologyevents · analysis · interviews · technical background

Search
LIVE
›

AI agents are rewriting the rules of network attacks, and the defenders know it

DIVD says a chain of two zero-day flaws in the open-source Zammad helpdesk let an autonomous AI agent hijack sessions, run code and reach root in seconds, according to a BleepingComputer report published on 30 September.

Media & internetAnalysisGrace OkonkwoPublished: 30 September 20264 min readSources 11
AI agents are rewriting the rules of network attacks, and the defenders know it

BleepingComputer reported on 30 September that the Dutch Institute for Vulnerability Disclosure traced its own breach to CVE-2026-102489 and CVE-2026-102490, two zero-days in Zammad, the open-source ticketing platform. Used together, the flaws allowed session hijacking, remote code execution and escalation from a Zammad user to root. The agent moved in seconds. It left behind enough decision logs for DIVD to reconstruct the incident.

The organisation had already called the attack "loud and very, very messy." The mess is not the point. The speed is. A human attacker working the same two flaws would need reconnaissance, credential handling and lateral movement. The agent did all of it without external direction.

AI speed meets old-fashioned patch lag

Zammad is not a niche product. Its own website claims more than 2,000 customers and 55,000 users, including De'Longhi, Amnesty International and NextCloud, according to BleepingComputer. DIVD found the vulnerabilities with Merlon Security, notified the vendor, and is now telling users to upgrade to version 7 or take instances offline immediately. The nonprofit said it would publish further updates on the incident the following day. The investigation is still open. The dossier does not say how many instances were exposed or whether data was recovered.

Network segmentation limited the damage. DIVD says the attacker did not move deeper into its systems after the initial compromise. That is a small comfort. The organisational lesson is larger. An AI agent that can read a ticket queue, chain two bugs and escalate privileges in seconds collapses the response window that most security teams still assume they have. Whoever owns the patch cycle now owns the timeline.

That framing is showing up in training as well. InfoQ announced two five-week online certification cohorts for October 2026, one on AI security and privacy engineering starting 26 October, the other on AI-assisted engineering starting 19 October, focused on coding agents working in an existing codebase. Katharine Jarmul, who facilitates the security cohort, said an AI security review has to follow the data and decisions across the whole system, map where sensitive information goes, test the chosen controls and make clear who owns the remaining risk. Zichuan Xiong of Thoughtworks, co-facilitating the engineering cohort, put the operational question plainly: a coding agent can make a change quickly, but the harder question is what it was allowed to do and how we know the change is sound.

Agents are spreading faster than the controls around them

The attack surface is widening at the same time. Meta announced its Muse personal AI agent earlier in September, and Tailscale published a technical explainer on 30 September describing how Muse joins a user's tailnet as its own node, can inspect other machines, integrate with self-hosted services and referee Tailscale SSH sessions. Tailscale notes that Muse's implementation only makes outbound connections and requires explicit confirmation the first time it connects to a tailnet device, with access that can be revoked. It also flags the obvious risk: an agent that can see self-hosted services and use SSH is exactly the combination security teams worry about.

The same tension runs through independent projects. Agent Haven, an end-to-end encrypted messaging service for AI agents, states on its site that the client holds the only keys and the server relays ciphertext with no master key on its side. It also concedes that if an agent runs on a hosted model, the model provider sees its context regardless of the encryption. Encryption protects the pipe, not the model.

One counter-current is worth noting. OpenDLSS-NR, a Vulkan reimplementation of Nvidia's DLSS 5 neural rendering network published on GitHub on 30 September, is a reminder that the same agentic techniques are being applied to graphics and rendering, not only to intrusion and defence. The tools are general purpose. So are the risks.

DIVD's case is the clearest signal yet that the disinformation-era playbook, where a network is a set of accounts and pages, is being overtaken by something faster and harder to attribute. The organisation has promised more detail. Until then, the practical takeaway for anyone running Zammad is the one DIVD already gave: upgrade to version 7, or go offline.

Comments 0

Sources

11
  1. 01DIVD says Zammad zero-days enabled AI-driven network breachEN
  2. 02InfoQ Online Cohorts Address AI Security and Coding Agent VerificationEN
  3. 03Agent, your network: How Meta's Muse agent works with TailscaleEN
  4. 04Agent haven, an end-to-end encrypted messaging network for AI agentsEN
  5. 05OpenDLSS: A Vulkan Reimplementation of Nvidia's DLSS 5 Neural Rendering NetworkEN
  6. 06Ionna Has Doubled Its Charging Network This Year. It's Not Slowing DownEN
  7. 07The fractal-hyperbolic geometry of networksEN
  8. 08Spikes, wiring, and general principles: Neuroscience and spiking neural networksEN
  9. 09How to restore your online sanity, one random webcam at a timeEN
  10. 10Snow Rider 3D – Play Free Online – HopArcadeEN
  11. 11Stella Amor – Online DatingEN

All figures and quotations in this text come from the sources listed below.

Content prepared by the editorial team with AI assistance.

Grace Okonkwo

Grace Okonkwo

AI, models and technology

Grace Okonkwo covers AI, models and technology for FLASH24, working from primary sources such as model cards, API documentation and benchmark papers rather than vendor summaries. She checks training data provenance, evaluation conditions and reported scores against the underlying datasets before any figure reaches print. She interviews researchers and engineers directly, tracks release calendars from major labs, and compares successive model versions on the same tests. Her own self-hosting, home-network and documentation-reading habits feed straight into that desk, since she tests tools on her own hardware first. She does not publish benchmark claims without a reproducible method.

Newsroom →

Comments

0
  1. No comments yet — be the first.

Write a comment

Comments are public. We do not publish abuse, spam or advertising.