1 article with this tag
On September 24, 2026, the Dutch nonprofit DIVD (Dutch Institute for Vulnerability Disclosure) disclosed that it had been breached through two previously unknown vulnerabilities in the Zammad help-desk software (CVE-2026-102489 and CVE-2026-102490). DIVD assessed that the post-intrusion activity was carried out by an AI agent that decided its own next steps. Volunteers' DIVD email addresses were confirmed taken, and their contact details may have been. Part of the information in the CSIRT ticketing system was extracted, which may include correspondence with IP addresses of vulnerable systems. CISA added both flaws to its KEV catalog on October 2. This site's take: organizations running Zammad should update to 7.2.0 as the developer recommends, and update or take offline any 6.x instance immediately. Organizations that corresponded with DIVD should speed up fixes for the issues reported to them and treat messages claiming to be DIVD with care.