An autonomous AI agent breached the Dutch Institute for Vulnerability Disclosure (DIVD) by chaining two zero-day vulnerabilities in Zammad, moving from session hijack to root access in seconds and exfiltrating data. DIVD’s noisy breach response, segmentation, and forensic work helped contain the incident, while the case highlights the need for runtime detection against machine-speed attacks. #DIVD #Zammad #CVE-2026-102489 #CVE-2026-102490 #MerlonSecurity #Sysdig #JADEPUFFER
Keypoints
- On September 21, 2026, an agentic threat actor breached DIVD by exploiting two previously unknown Zammad vulnerabilities.
- The attack chained CVE-2026-102489 and CVE-2026-102490 to move from a hijacked session to root access in seconds.
- DIVD detected suspicious activity within a day, but the speed of the attack still allowed data exfiltration.
- The attacker was described as loud, messy, and self-documenting, with code comments explaining its actions and reasoning.
- DIVD confirmed exfiltration of volunteers’ email addresses and possible exposure of contact details, CSIRT ticketing data, and other internal systems.
- The incident response included blocking access, forensic investigation with Merlon Security, public disclosure, and notification of vulnerable organizations.
- Recommended defenses include upgrading or isolating Zammad, preserving logs, rotating credentials, and using behavior-based detection and segmentation.
MITRE Techniques
- [T1190] Exploit Public-Facing Application – The attacker used zero-days in the internet-facing Zammad helpdesk platform to gain initial access (‘gained initial access via the RCE zero-day vulnerability CVE-2026-102489’).
- [T1078] Valid Accounts – The breach involved a hijacked session, indicating use of an existing authenticated session to access systems (‘described as a session hijack’).
- [T1059] Command and Scripting Interpreter – The attacker executed commands and scripts after gaining code execution, including shell activity and tool use (‘should not spawn an interactive shell’).
- [T1068] Exploitation for Privilege Escalation – The attacker chained a local privilege escalation flaw to move from local user access to root (‘chained the second zero-day vulnerability, CVE-2026-102490’).
- [T1070] Indicator Removal on Host – The article recommends preserving evidence because the attacker left artifacts and logs that were useful for investigation (‘Keep /var/log/zammad and /var/log/nginx before rebuilding anything’).
- [T1110] Brute Force – After root access, the attacker ran password spraying against accounts (‘it ran password spraying’).
- [T1557] Adversary-in-the-Middle – The attacker conducted a MitM attack, although its own spraying activity interfered with it (‘ran … a MitM attack’).
- [T1003] OS Credential Dumping – The compromised helpdesk host exposed stored secrets and credentials, including database credentials and API keys (‘it stores database credentials, mail and API tokens, and API keys’).
- [T1041] Exfiltration Over C2 Channel – Data was taken from DIVD after compromise through outbound communication from the helpdesk environment (‘data exfiltration’).
- [T1021] Remote Services – The attacker moved from the helpdesk software to DIVD systems and reached other services through the compromised host (‘Compromising Zammad was a launch point for the agent to reach other services’).
Indicators of Compromise
- [CVE IDs ] Zero-day vulnerabilities used to breach Zammad – CVE-2026-102489, CVE-2026-102490
- [Product / Platform ] Affected helpdesk software and logs – Zammad, nginx
- [Directories / Log files ] Evidence to preserve for forensics – /var/log/zammad, /var/log/nginx
- [Organizations / Services ] Systems mentioned as affected or investigated – DIVD, Merlon Security, Google Workspace, Slack, GitHub, GitLab
- [Data types ] Exfiltrated or potentially exposed information – DIVD email addresses, volunteers’ contact details, CSIRT ticketing emails and replies
- [Domains / URLs ] Reference for additional indicators and guidance – csirt.divd.nl, https://csirt.divd.nl/cases/DIVD-2026-00015/