Published Wednesday, September 30, 2026 at 05:45 PM PT

<strong>DEVELOPING — Zammad Zero-Days Exploited in AI-Driven Breach; DIVD Investigating</strong>

BLUF: DIVD (Dutch Institute for Vulnerability Disclosure) has disclosed unpatched zero-days in Zammad helpdesk software that were actively exploited to conduct AI-driven network attacks. Organizations running Zammad should inventory instances immediately and monitor for unauthorized access. Details remain sparse; coordinated disclosure underway.

DETAILS

  • DIVD identified zero-day vulnerabilities in Zammad (helpdesk/ticketing platform) actively exploited in network breaches.
  • Attack vector involved automated AI agent(s) coordinating initial access and reconnaissance—same methodology used in parallel breach of DIVD’s own infrastructure.
  • Exploitation enabled network-level compromise; AI automation suggests broad targeting potential.
  • Patch/advisory status unknown; vendors/disclosure timeline not yet public in available material.
  • Related threat activity: concurrent AI-augmented attack frameworks observed across financial and security sectors (credential theft, lateral movement).

IMPACT

  • Directly affected: Organizations operating Zammad for helpdesk/ticketing—potentially hundreds to thousands globally.
  • Indirect risk: Supply chain; DIVD’s own compromise may have exposed vulnerability details or victim data, widening exposure window.
  • Threat model: Zero-day + AI agent = low detection friction; remediation complexity depends on dwell time pre-discovery.

RECOMMENDED ACTIONS

  • Immediate: Audit firewall/proxy logs for Zammad instances; isolate from untrusted networks if zero-day severity warrants.
  • Within 24h: Subscribe to DIVD’s disclosure timeline and Zammad’s official security channels; prepare patch procedure.
  • Ongoing: Enable enhanced logging on Zammad authentication and API; search historical logs for anomalous bot/API activity (agent footprint).
  • If exposed: Assume credential compromise; rotate API keys, service account passwords, and Zammad admin tokens.

SOURCES

  • BleepingComputer: “DIVD says Zammad zero-days enabled AI-driven network breach” (headline; full advisory pending).
  • BleepingComputer: “Automated AI agent used to breach cybersecurity nonprofit DIVD” (parallel attack pattern).
  • Status: Unconfirmed—details sparse. Awaiting DIVD/Zammad official CVE and remediation guidance.

Recent high-severity events at publish time:

Recent high-severity events