DIVD Reports Network Breach via Zammad Zero-Day Chain
Two unpatched vulnerabilities in the Zammad ticketing system enabled an AI-driven intrusion into Dutch Institute for Vulnerability Disclosure systems

Key Takeaways
- DIVD confirmed a network breach facilitated by a chain of two zero-day vulnerabilities in Zammad.
- The attack included an AI-driven component, though technical details remain sparse.
- No CVE IDs or specific vulnerability details have been published as of the report.
- DIVD and Zammad are reportedly developing mitigations and patches.
- Users of Zammad should apply updates as soon as they are released and monitor official advisories.
Quick answers
- What happened?
- The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed that its network was compromised through the exploitation of a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. The attack leveraged the vulnerabilities to facilitate unauthorized access, with reports indicating an AI-driven component to the breach. Both organizations are working on mitigations, and users are advised to apply updates as they become available.
- Which products are affected?
- Zammad
- What should defenders do?
- Users should monitor official advisories from DIVD and Zammad and apply available patches immediately. General best practices include keeping systems updated, network segmentation, and reviewing access controls.
The Dutch Institute for Vulnerability Disclosure (DIVD) announced that its internal network was breached via the exploitation of two zero-day vulnerabilities in the Zammad ticketing system. According to reports, the attack chain exploited flaws in Zammad to gain unauthorized access, after which an AI-driven element was used to further the intrusion. DIVD and Zammad have not disclosed the specific technical details of the vulnerabilities or the nature of the AI component, stating that official advisories and patches are pending. The incident highlights the risks associated with zero-day exploits in widely used open-source software and the potential for compound attacks involving automated tools. Affected users are urged to monitor official channels from both DIVD and Zammad for security updates and to apply any available patches immediately.
Security Details
Exploitation of a chain of two zero-day vulnerabilities in the Zammad ticketing system to enable unauthorized access to DIVD's network. An AI-driven component was reportedly used to facilitate the breach. Specific vulnerability details, CVEs, and exploitation mechanics are not yet publicly disclosed.
Affected products
Zammad
Mitigation
Users should monitor official advisories from DIVD and Zammad and apply available patches immediately. General best practices include keeping systems updated, network segmentation, and reviewing access controls.
Sources
BleepingComputer
DIVD says Zammad zero-days enabled AI-driven network breach
Sep 30, 2026 · 19:49
Original link
Related Security News

MetaMask Discloses Ongoing Infrastructure Security Incident
MetaMask, the popular cryptocurrency wallet developed by ConsenSys, has disclosed an ongoing security incident impacting its infrastructure. Details regarding the attack vector, specific systems compromised, and potential user impact remain limited in the initial report.

Google Announces Gemini 4 Argon AI Model for Trusted Cyber Defenders
Google has announced Gemini 4 Argon, a new frontier artificial intelligence model being distributed to a set of trusted cyber defenders through the Fairwind Program. The company states the model delivers frontier performance across complex workflows including software engineering, enterprise knowledge work, and cybersecurity defense. Google also indicated plans to release a guardrail-free version of the model in the future. The announcement was made on October 1, 2026, via The Hacker News. No known exploitation or security vulnerabilities have been reported, as the model is currently limited to a trusted defender program and is not publicly released.



