DIVD says Zammad zero-days enabled AI-driven network breach

Executive Summary

The Dutch Institute for Vulnerability Disclosure (DIVD) reported that attackers breached its network by exploiting a chain of two zero‑day vulnerabilities in the open‑source Zammad ticketing system. The exploitation was reportedly AI‑driven, allowing the attackers to gain unauthorized access and potentially exfiltrate data. The incident highlights the risk of unpatched zero‑days in widely used open‑source software.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-30T19:49:15+00:00 - Category: threat-intel

Original Description: The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]

"Using the power of decision gives you the capacity to get past any excuse to change any and every part of your life in an instant."

— Tony Robbins
Source: Bleeping Computer