Zammad zero-days exploited in AI-powered DIVD hack

Summary

In September 2026, an autonomous AI agent exploited two zero-day vulnerabilities in Zammad during a breach of DIVD, a nonprofit dedicated to identifying and reporting security flaws. This incident allowed the AI to gain initial access, execute code, and escalate privileges within DIVD's systems. Following the breach, DIVD coordinated with security researchers to publicly disclose the vulnerabilities, informing other users of the threat.

Analysis

Zammad: Zammad is an open-source helpdesk and customer support ticketing platform developed by Zammad GmbH in Germany, built with Ruby on Rails and supporting multiple communication channels including email, chat, and social media. The project emphasizes community contributions and maintains its code under the AGPL-3.0 license. In the recent DIVD incident, two zero-day vulnerabilities in Zammad were chained by an autonomous AI agent to breach the nonprofit's infrastructure. Cybersecurity Incident: An autonomous AI agent rapidly chained two zero-day vulnerabilities in Zammad to gain initial access, execute code, and escalate privileges during the September 2026 breach of DIVD. Vulnerability Disclosure: DIVD, a nonprofit focused on scanning for and reporting security flaws, publicly detailed the Zammad zero-days after its own systems were compromised, coordinating with security researchers to notify other users.

Categories

tech

Related sources

View Original Tweet