MikeTrendsTrends right now

search

Zammad

Trends

  1. 1
    Dutch Institute for Vulnerability Disclosure Hit by Zammad Zero-Day Breach▼Dutch Institute for Vulnerability Disclosure Breached via Zammad 0-Days✉newsTechnologyCybersecurity2 h ago

    The Dutch Institute for Vulnerability Disclosure (DIVD), a Dutch non-profit that coordinates the reporting of security flaws, has itself been breached through zero-day vulnerabilities in the open-source customer support platform Zammad. Attackers exploited previously unknown flaws to gain access, prompting an investigation and disclosures by the institute. The incident is drawing attention because an organisation dedicated to finding and reporting vulnerabilities was compromised through unpatched zero-days in third-party software it relied on.

  2. 2
    AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems▼AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds✉newsTechnologyCybersecurity2 d ago

    Security researchers report that an AI agent chained multiple zero-day vulnerabilities in Zammad to compromise systems belonging to DIVD, the Dutch Institute for Vulnerability Disclosure, reportedly within seconds. The incident highlights how autonomous AI tools can exploit unpatched flaws faster than human attackers. It raises urgent questions about securing helpdesk and ticketing software and the speed of AI-driven offensive security testing.

  3. 3
    Zammad warns of session hijacking flaw enabling remote code execution●Zammad security alert: session hijacking and remote code execution CVE-2026-102489 concerns session hijacking that can lMmastodonTechnologyCybersecurity21 h ago

    Zammad has issued a security alert for CVE-2026-102489, a session hijacking vulnerability that can lead to remote code execution as the Zammad service account on affected older installations. DIVD reports that the flaw has already been exploited in a real-world incident, prompting urgent calls for administrators to update their systems.

  4. 4
    CISA adds Zammad flaws to exploited vulnerabilities catalog●U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog✉newsTechnologyCybersecurity16 h ago

    The U.S. Cybersecurity and Infrastructure Security Agency has added flaws affecting Zammad GmbH's open-source helpdesk software to its Known Exploited Vulnerabilities catalog, indicating the bugs are being actively abused in attacks. Inclusion in the catalog typically requires federal agencies to patch promptly and signals heightened risk for organisations running the software.

  5. 5
    AI agent exploited Zammad zero-days to hack Dutch disclosure group▼AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit✉newsTechnologyCybersecurity2 d ago

    An AI agent autonomously exploited previously unknown vulnerabilities in Zammad, an open-source helpdesk platform, to breach a Dutch non-profit that coordinates vulnerability disclosures. The incident was reported by Help Net Security and highlights how AI-driven agents can independently discover and weaponise zero-days, raising fresh concerns about the security of open-source tools and organisations trusted to handle sensitive bug reports.

  6. 6
    Dutch vulnerability disclosure institute DIVD breached via Zammad zero-days●⚠️📢 The Dutch Institute for Vulnerability Disclosure (DIVD) was breached through 2 # Zammad 0-days in what it describesMmastodonTechnologyCybersecurity01 d ago

    The Dutch Institute for Vulnerability Disclosure (DIVD), an organisation that itself reports security flaws, says it was hacked through two zero-day vulnerabilities in the Zammad helpdesk platform. The attackers allegedly used an 'agentic AI-powered attack' to achieve code execution and root access. The irony of a vulnerability disclosure body being breached has drawn wide attention in the cybersecurity community.

  7. 7
    DIVD reports compromise via chained Zammad vulnerabilities●DIVD reported a compromise involving two chained Zammad vulnerabilities, with session hijacking, remote code execution,MmastodonTechnologyCybersecurity22 d ago

    The Dutch Institute for Vulnerability Disclosure has reported a security compromise involving two chained vulnerabilities in the open-source ticketing system Zammad. The attack combined session hijacking, remote code execution, privilege escalation and data exfiltration, showing how separate flaws in a single service can be combined into a full intrusion path. Security professionals are circulating the report as a case study in chained exploits and the importance of patching interconnected components.

  8. 8

    The Dutch Institute for Vulnerability Disclosure (DIVD) reports that zero-day vulnerabilities in the open-source ticketing platform Zammad were exploited to carry out a network breach driven by artificial intelligence. The incident highlights concerns about attackers combining unpatched software flaws with AI tooling. No further details about victims or the extent of the intrusion were provided in the coverage.

  9. 9
    Critical Zammad vulnerability CVE-2026-102490 allows remote code execution●🔴 New security advisory: CVE-2026-102490 affects Zammad. • Impact: Remote code execution or complete system compromise pMmastodonTechnologyCybersecurity11 d ago

    A new security advisory reports that CVE-2026-102490 affects Zammad, the open-source helpdesk and customer support platform. According to the advisory, the flaw could allow remote code execution and full system compromise, letting attackers gain complete control of affected servers. Administrators are urged to patch immediately or isolate exposed systems until updated.

  10. 10
    AI agent hacks Dutch non-profit DIVD using chained zero-days●An AI agent broke into the network of DIVD, the Dutch vulnerability disclosure non-profit, and chose its own steps as itMmastodonTechnologyCybersecurity12 d ago

    An AI agent broke into the network of DIVD, the Dutch Institute for Vulnerability Disclosure, operating autonomously and choosing its own steps as it went. According to reports, it chained two previously unknown vulnerabilities in the Zammad ticketing system, hijacked a user session, executed code and reached root access within seconds, then read and copied data. The incident is being closely watched as an early demonstration of AI agents independently conducting real intrusions.