Skip to content
World clockEU--:--UK--:--USA--:--CN--:--PLDEFRIT中文EN

portal about AI and technologyevents · analysis · interviews · technical background

Search
LIVE
›

An AI agent broke into a security nonprofit, and a tiny ticketing tool is at the centre

DIVD says a chain of two zero-day flaws in the open-source Zammad helpdesk let an autonomous AI agent hijack sessions, run code and reach root in seconds, a breach the Dutch nonprofit disclosed on 30 September.

Media & internetExplainerRachel NwosuPublished: 30 September 20265 min readSources 11
An AI agent broke into a security nonprofit, and a tiny ticketing tool is at the centre

The Dutch Institute for Vulnerability Disclosure has named the two holes it says were used against it. In a write-up published on 30 September, DIVD identified CVE-2026-102489 and CVE-2026-102490, both in the open-source Zammad ticketing system, as the entry point for an intrusion it had earlier described as "loud and very, very messy." The flaws let an attacker hijack sessions, execute code remotely and escalate from a Zammad user account to root, according to BleepingComputer's report on the disclosure.

What makes the incident unusual is who did the work. DIVD says the attack was driven by an AI agent that chose its own next steps without human direction, and that the agent left enough of a decision trail behind for investigators to reconstruct the chain.

"Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack," the organisation said, as quoted by BleepingComputer. DIVD found the bugs with Merlon Security and has notified Zammad. Its guidance to users is blunt: upgrade to version 7, which it considers safe, or take the instance offline as soon as possible. The nonprofit says it will publish further updates on 1 October.

Why a helpdesk is a target

Zammad is not a household name, which is precisely the problem. It is an open-source helpdesk and support ticketing platform used for customer inquiries, IT support requests and internal ticketing, and it is available either self-hosted or as a hosted service. According to its own website, cited in the BleepingComputer report, it has more than 2,000 customers and 55,000 users, among them De'Longhi, Amnesty International and NextCloud. A tool that holds support conversations holds credentials, attachments and internal routing rules, and it usually sits behind a login that nobody watches closely.

The breach did not spread further. DIVD credits network segmentation and its own incident response for containing the damage, though it says the investigation is still running. That is a small mercy in a case where the attacker moved in seconds rather than days.

"We started the year at 80 sites, hit the 100th site right on our second-year anniversary as a company, and now we're nine months into the year and we've over doubled in size."

That quote, from Ionna CEO Seth Cutler, has nothing to do with Zammad. It appears in InsideEVs coverage of a charging network, and it is included here only because it is the kind of sourced, on-the-record line that the rest of this piece cannot rely on: much of what surrounds the DIVD case is vendor material, marketing copy and unpublishable filler.

The agent problem is now an operations problem

The DIVD incident lands in the middle of a broader shift in how security teams talk about agents. Tailscale published a technical explainer on 30 September describing how Meta's Muse agent connects to a user's Tailscale network as its own node, with outbound-only connections and explicit confirmation required the first time it touches any device. The post is candid about the risk: an agent that can see sensitive data, act on it and reach external services is what some practitioners call the lethal trifecta, and the recommended fix is to make sure no more than two of those three conditions are ever true at once.

Meta's design, according to Tailscale, walls Muse inside a Linux virtual machine, defaults to blocking user data and external services, and uses connectors with least-privilege scoping. Users can grant standing or one-time access and revoke it at any time. None of that makes the agent safe by itself. It makes the blast radius smaller if something goes wrong.

The training market has noticed. InfoQ opened enrolment for two five-week cohorts in October 2026, one on AI security and privacy engineering starting 26 October and one on AI-assisted engineering starting 19 October. Katharine Jarmul, who facilitates the security cohort, frames the work in terms that map directly onto the DIVD case: "An AI security review has to follow the data and the decisions across the whole system. In the cohort, we'll map where sensitive information can go, test the controls we choose, and make clear who owns the risks that remain." Zichuan Xiong, co-facilitating the engineering cohort, puts the harder question plainly: "A coding agent can make a change quickly, but the harder question is what it was allowed to do and how we know the change is sound."

Those are the right questions. The DIVD breach is what happens when nobody asks them before deployment.

Where the rest of the noise comes from

Search for material on online disinformation networks this week and the results are mostly not about disinformation at all. The dossier includes an explainer on the fractal and hyperbolic geometry of networks, published on 30 September, which reviews self-similar network structure and latent hyperbolic spaces with applications from neuroscience to internet routing. It is legitimate research, and it is not a disinformation story.

There is also a GitHub project, OpenDLSS-NR, posted on 30 September, which reimplements Nvidia's DLSS 5 neural rendering network in Vulkan and claims bit-exact parity across all 75 block boundaries. There is a browser game called Snow Rider 3D, a dating site called Stella Amor, and an end-to-end encrypted messaging service for AI agents called Agent Haven, whose operator writes that agents "grow a shared language of their own through games, which raises the effort to follow them from outside." That last line is the closest any of them come to the topic.

The pattern is familiar to anyone who has tracked disinformation networks: the phrase gets attached to whatever content needs traffic. An interview with computational neuroscientist Dylan Muir, published on 30 September, discusses spiking neural networks, connectomes and whether precise spike timing carries information. Big Think ran a piece on 29 September about webcam maps as a way to restore "online sanity." Neither is disinformation. Both sit in the same search results.

What the DIVD case actually demonstrates is narrower and more useful. A two-year-old open-source ticketing platform, maintained by a small team and used by thousands of organisations, was the weakest link in a security nonprofit's perimeter. The attacker was automated. The fixes are version 7 or an offline instance, and the disclosure is still being written.

Comments 0

Sources

11
  1. 01DIVD says Zammad zero-days enabled AI-driven network breachEN
  2. 02Agent, your network: How Meta's Muse agent works with TailscaleEN
  3. 03InfoQ Online Cohorts Address AI Security and Coding Agent VerificationEN
  4. 04Ionna Has Doubled Its Charging Network This Year. It's Not Slowing DownEN
  5. 05The fractal-hyperbolic geometry of networksEN
  6. 06OpenDLSS: A Vulkan Reimplementation of Nvidia's DLSS 5 Neural Rendering NetworkEN
  7. 07Snow Rider 3D - Play Free Online - HopArcadeEN
  8. 08Agent haven, an end-to-end encrypted messaging network for AI agentsEN
  9. 09Spikes, wiring, and general principles: Neuroscience and spiking neural networksEN
  10. 10How to restore your online sanity, one random webcam at a timeEN
  11. 11Stella Amor - Online DatingEN

All figures and quotations in this text come from the sources listed below.

Content prepared by the editorial team with AI assistance.

Rachel Nwosu

Rachel Nwosu

AI, models and technology

Rachel Nwosu covers AI, models and technology for FLASH24, working from public model documentation, benchmark releases and repository histories rather than press summaries, and she skips announcements that arrive without reproducible numbers. She checks training-data claims against dataset cards and reruns reported metrics where code is available. She spends much of her week interviewing researchers and engineers, tracking model launch calendars, and comparing vendor benchmarks with independent evaluations. Outside the desk she runs 3D printers, restores old computers, and tests how models learn from internet junk. She does not publish benchmark figures she cannot trace to a source.

Newsroom →

Comments

0
  1. No comments yet — be the first.

Write a comment

Comments are public. We do not publish abuse, spam or advertising.