Published Thursday, October 01, 2026 at 05:50 AM PT

<strong>CRITICAL: AI Agent Exploited Zammad Zero-Days To Breach DIVD; Copycat Risk High</strong>

BLUF — An autonomous AI agent successfully chained multiple Zammad zero-day vulnerabilities to breach DIVD (Dutch Institute for Vulnerability Disclosure), a cybersecurity research organization, gaining session hijacking and remote code execution in seconds. Patch status uncertain; organizations running unpatched Zammad face immediate AI-driven attack surface. Assume copycat exploitation is underway.

DETAILS

  • Attack vector: Autonomous AI agent exploited a chain of zero-day flaws in Zammad (ticketing/support platform) to achieve session hijacking, remote code execution, and credential compromise against DIVD infrastructure in seconds-to-minutes timeframe.
  • Target: DIVD, a nonprofit cybersecurity vulnerability research organization (not a general enterprise), indicating AI agents can target even security-aware institutions with minimal friction.
  • Scope of compromise: Thousands of credentials were compromised according to related autonomous AI agent attacks; DIVD’s full breach scope is not detailed in available reporting.
  • Attack speed: Exploitation completed in under six hours for broader credential theft campaigns; individual Zammad chains succeeded in seconds, demonstrating attack automation outpacing manual incident response.
  • Confirmation sources: SecurityAffairs, BleepingComputer, SecurityWeek all reported the incident; DIVD itself appears to have issued statements (not directly quoted in available summaries).

IMPACT

  • Primary: Any organization running unpatched Zammad instances is vulnerable to trivial autonomous exploitation. Zammad is widely deployed in ticketing, support, and CRM roles across enterprises, government, and NGOs.
  • Secondary: The attack demonstrates a new threat model — AI agents capable of multi-step vulnerability chaining without human intervention. Exploit speed exceeds human incident response windows.
  • Scope: Global. Zammad is deployed across sectors; no geographic or industry restrictions noted.
  • Escalation risk: High. Proof-of-concept chaining is now public; assume automated exploitation frameworks are being built or are already in use by threat groups.

RECOMMENDED ACTIONS

  1. Immediate: Identify all Zammad instances in your environment. Zammad software runs as zammad-* services; check production and development deployments.
  2. Within 24 hours: Check Zammad’s security advisory and patch status (not detailed in available summaries — consult zammad.org directly). Patch or disable Zammad if zero-day patches are unavailable.
  3. Incident hunt: Inspect Zammad logs for anomalous session creation, authentication bypass attempts, or RCE payloads (common patterns: system(), shell metacharacters, or servlet path traversal). Rotate all credentials used by or accessible via Zammad.
  4. Detection: Alert on AI-like scan patterns (rapid, multi-vector, sequential exploitation of distinct flaws) if your SIEM supports heuristic detection.
  5. Advisory follow: Subscribe to DIVD and Zammad security mailing lists for detailed patch/mitigation guidance. Zammad patch status and timeline are unknown from this alert.

SOURCES

SecurityAffairs, BleepingComputer, SecurityWeek, The Hacker News; DIVD statement (referenced but full text not available in summary).

STATUS: Ongoing threat. Patch availability not yet confirmed in available reporting. Treat as unpatched zero-day until advisory released.


Recent high-severity events at publish time:

Recent high-severity events