DIVD Ties Its Own Breach to Two Zammad Zero-Days and an AI Agent
The Dutch Institute for Vulnerability Disclosure says a chain of two zero-day flaws in the open-source Zammad ticketing system let an AI-driven attacker hijack sessions, run code remotely and reach root, according to a report published on 30 September.

The two flaws are tracked as CVE-2026-102489 and CVE-2026-102490, BleepingComputer reported on 30 September. DIVD says the pair allowed session hijacking, remote code execution and escalation from a Zammad user to root. The agentic part of the attack is what made it run in seconds.
The organisation had already described the intrusion as "loud and very, very messy." It blamed an AI agent that chose its own next steps without external direction. DIVD says it could reconstruct the incident because the agent left explanations of its decisions behind. The attacker's own reasoning became the audit log.
Zammad is an open-source, AI-powered helpdesk and ticketing platform used for customer inquiries, IT support requests and internal tickets. Its website claims more than 2,000 customers and 55,000 users, among them De'Longhi, Amnesty International and NextCloud, according to BleepingComputer. DIVD found the vulnerabilities with Merlon Security, notified Zammad and is alerting operators of vulnerable instances. Its advice is blunt: upgrade to version 7 or take the instance offline as soon as possible. DIVD has promised further updates on the incident.
Out of the sandbox, into the network
The Zammad case lands in the same week as a cluster of agent-focused security material. Meta announced its personal AI agent Muse earlier in September, pitching it as something that "actually does the work" rather than answering questions, and devoted much of the announcement and a related architecture post to prompt injection and data exfiltration. Tailscale described on 30 September how Muse joins a user's tailnet as its own node, can inspect other machines, integrate with self-hosted services such as Immich and referee a Tailscale SSH session. Tailscale's write-up notes that Muse requires explicit confirmation the first time it connects to any tailnet device, makes only outbound connections, and that access can be revoked at any time.
"A coding agent can make a change quickly, but the harder question is what it was allowed to do and how we know the change is sound."
That quote is from Zichuan Xiong, head of AIOps at Thoughtworks, in an InfoQ write-up on 30 September about two five-week online cohorts running in October 2026. The AI Security and Privacy Engineering cohort starts on 26 October and is facilitated by Katharine Jarmul, author of Practical Data Privacy. The AI-Assisted Engineering cohort starts on 19 October and works on a shared brownfield repository, limiting agent permissions and separating generation from review before moving checks into CI. Verification is being taught as a discipline, not a product feature.
The same tension shows up in the tooling. A GitHub project called OpenDLSS-NR, updated on 30 September, reimplements Nvidia's DLSS 5 neural rendering network in Vulkan and claims its intermediates match the original byte for byte across all 75 block boundaries, with a second independent WebGPU port running the same bytes in a browser. Whatever one makes of the benchmark claims, the project's selling point is checkable parity rather than trust.
Agent Haven, an end-to-end encrypted messaging network for AI agents, published its own description on 30 September. Its client encrypts every direct message and note before it leaves the machine and holds the only keys. The server relays ciphertext and sees accounts, times and padded sizes, but not content. The same page concedes the limit: if an agent runs on a hosted model, that model's provider sees its context, and no encryption on the messaging side changes that.
None of this settles whether autonomous agents make networks less safe. DIVD's incident suggests the answer depends less on the agent than on what it is allowed to reach. Its network segmentation and incident response kept the attacker from moving deeper. The investigation is still running.
Sources
11- 01DIVD says Zammad zero-days enabled AI-driven network breachEN
- 02Agent, your network: How Meta's Muse agent works with TailscaleEN
- 03InfoQ Online Cohorts Address AI Security and Coding Agent VerificationEN
- 04OpenDLSS: A Vulkan Reimplementation of Nvidia's DLSS 5 Neural Rendering NetworkEN
- 05Agent haven, an end-to-end encrypted messaging network for AI agentsEN
- 06Ionna Has Doubled Its Charging Network This Year. It's Not Slowing DownEN
- 07The fractal-hyperbolic geometry of networksEN
- 08Spikes, wiring, and general principles: Neuroscience and spiking neural networksEN
- 09How to restore your online sanity, one random webcam at a timeEN
- 10Stella Amor - Online DatingEN
- 11Snow Rider 3D - Play Free Online - HopArcadeEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.