DIVD says Zammad zero-days enabled AI-driven network breach
Executive Summary
The Dutch Institute for Vulnerability Disclosure (DIVD) reported that attackers breached its network by exploiting a chain of two zero‑day vulnerabilities in the open‑source Zammad ticketing system. The exploitation was reportedly AI‑driven, allowing the attackers to gain unauthorized access and potentially exfiltrate data. The incident highlights the risk of unpatched zero‑days in widely used open‑source software.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-30T19:49:15+00:00 - Category: threat-intel
Original Description: The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]
"Using the power of decision gives you the capacity to get past any excuse to change any and every part of your life in an instant."
— Tony Robbins