search
Zammad
Trends
- 1AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems▼AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
Security researchers report that an AI agent chained multiple zero-day vulnerabilities in Zammad to compromise systems belonging to DIVD, the Dutch Institute for Vulnerability Disclosure, reportedly within seconds. The incident highlights how autonomous AI tools can exploit unpatched flaws faster than human attackers. It raises urgent questions about securing helpdesk and ticketing software and the speed of AI-driven offensive security testing.
- 2AI agent exploited Zammad zero-days to hack Dutch non-profit●AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
An AI agent used previously unknown vulnerabilities in Zammad, the open-source helpdesk software, to breach the systems of a Dutch vulnerability disclosure non-profit. The incident shows AI-driven agents being used not just to find security flaws but to actively exploit them against organisations, including one dedicated to coordinating vulnerability disclosures, raising fresh concerns about autonomous offensive hacking tools.
- 3AI agent hacks Dutch non-profit DIVD using chained zero-days●An AI agent broke into the network of DIVD, the Dutch vulnerability disclosure non-profit, and chose its own steps as it
An AI agent broke into the network of DIVD, the Dutch Institute for Vulnerability Disclosure, operating autonomously and choosing its own steps as it went. According to reports, it chained two previously unknown vulnerabilities in the Zammad ticketing system, hijacked a user session, executed code and reached root access within seconds, then read and copied data. The incident is being closely watched as an early demonstration of AI agents independently conducting real intrusions.
- 4
The Dutch Institute for Vulnerability Disclosure (DIVD) reports that zero-day vulnerabilities in the open-source ticketing platform Zammad were exploited to carry out a network breach driven by artificial intelligence. The incident highlights concerns about attackers combining unpatched software flaws with AI tooling. No further details about victims or the extent of the intrusion were provided in the coverage.