On the night of September 21, 2026, an intruder slipped into the network of the Dutch Institute for Vulnerability Disclosure, the volunteer nonprofit that scans the public internet for exposed systems and warns their owners before criminals find them. In seven years of operation, DIVD had never suffered a significant breach. This one needed no stolen passwords, no phishing campaign, and no human operator. The attacker was an autonomous AI agent that chained two previously unknown vulnerabilities in the open-source Zammad helpdesk platform into full root access on a DIVD server, in seconds.

The incident, documented in DIVD's public case files and confirmed by a forensic investigation it commissioned with Merlon Security, is the clearest case yet of what researchers call an agentic threat actor: software that perceives, plans, and acts on its own, choosing its next move after every action without waiting for a human.

The breach, step by step

DIVD's timeline shows how fast the response had to move. The attacker gained access on September 21. The institute noticed suspicious activity the next day, cut access to every system in its data center, and began a forensic investigation. On September 24 it notified the Dutch data protection authority, the National Cyber Security Centre, and law enforcement, announced the breach publicly, and warned Zammad's vendor. On September 26 it began scanning the internet for other exposed Zammad instances to notify their owners, and on September 29 it published the case files and the two CVE records.

On October 2, the US Cybersecurity and Infrastructure Security Agency added both vulnerabilities to its Known Exploited Vulnerabilities catalog, ordering federal agencies to remediate within days and flagging the case for forensic triage. The listing signaled that this was not a one-off curiosity. Zammad reports more than 2,000 enterprise customers, including De'Longhi, Amnesty International, and Nextcloud, plus 55,000 individual users.

The data at risk is the most sensitive part. DIVD confirmed that volunteers' email addresses were exfiltrated and that contact details may have been taken. The CSIRT ticketing system, holding every email to the incident-response mailbox and every reply, showed signs of compromise and was believed partially extracted, potentially including follow-up requests with IP addresses of vulnerable systems and extracts of credential dumps. DIVD's Jira and Confluence systems also showed signs of compromise. Accounting and banking information was unaffected.

Two zero-days, one chain

Enjoying this story?

Get the five most important stories in tech, every morning. Free.

The attack worked because two flaws combined into something worse than either alone. CVE-2026-102489 let an unauthenticated attacker hijack a session and execute code as the Zammad service user on versions 6.3.0 through 6.5.4. DIVD scored it CVSS 8.7; the US National Vulnerability Database rated it 9.8, critical. The same code exists in versions 7.0.0 through 7.1.3, but DIVD said environmental conditions prevented exploitation there, a protection the vendor echoed while adding hardening in version 7.2.0.

CVE-2026-102490 was the second link: a local privilege escalation that turned the low-privilege Zammad user into root. It affects every Zammad version from 1.5.0 through 7.1.0-alpha and remained unpatched as of early October 2026. Chained together, the two flaws carried a reported CVSS score of 9.4, turning an internet-facing helpdesk into a fully compromised server.

There is an unsettling symmetry here. Zammad's AI assistant features had already produced a high-severity remote code flaw in April 2026, when CVE-2026-34724, a template injection rated CVSS 8.7, was published. The new chain is different, but the pattern of input-handling weaknesses around AI-integrated components keeps repeating.

The agent did not wait for a human to review its results. It chose its next step after every action, at machine speed, and reached root in seconds.

A loud, messy, successful attacker

Machine Speed: The Numbers Behind the DIVD Breach

An autonomous agent chained two zero-days before a human analyst could react.

Unauthenticated access to root
seconds
Fastest recorded eCrime breakout time (CrowdStrike 2026)
27 seconds
Year-over-year rise in AI-enabled attacks (CrowdStrike 2026)
89%
Security pros ranking agentic AI the top 2026 attack vector (Dark Reading)
48%
Combined CVSS score of the two-CVE exploit chain (DIVD)
9.4

Note: figures from DIVD's public case files, CISA's Known Exploited Vulnerabilities catalog, and CrowdStrike's 2026 Global Threat Report.

What made this intrusion a reference case was not that an AI was involved but how it behaved. DIVD called the attack "loud and very, very messy." The agent wrote detailed natural-language comments into its own attack scripts, narrating its reasoning, including notes claiming "no phishing" and "no spam." It was so poorly tuned that its own password spraying disrupted its man-in-the-middle attack. A human attacker is typically the opposite: quiet, deliberate, evasive.

The messiness was forensically useful. Sysdig's threat research team noted that verbose self-explanatory comments are a signature of LLM-driven attack tooling, rarely seen in hand-written intrusion code. The same trait appeared in JADEPUFFER, the first fully agentic ransomware campaign, which Sysdig documented in July 2026 after an AI agent entered through an unpatched Langflow instance and independently carried out reconnaissance, theft, lateral movement, and database destruction.

That a clumsy agent still succeeded is the point that should worry defenders most. DIVD assessed the agent as poorly trained and badly configured. It reached root anyway and exfiltrated data anyway. A better-built agent would likely have been quieter, leaving less of the noisy evidence that helped investigators.

Why the seconds matter

Fingerprint scan representing identity and intrusion forensics
The DIVD breach went from unauthenticated access to root in seconds, a pace no human analyst can match. (Illustration: Calder Brief)

The breach landed in a community already confronting the gap between attack speed and response speed. CrowdStrike's 2026 Global Threat Report logged a fastest recorded eCrime breakout time of 27 seconds and an 89 percent year-over-year increase in AI-enabled attacks. A Booz Allen Hamilton report from March 2026 put it bluntly: "The time gap between AI-speed attacks and human-speed defense is not narrowing." A Dark Reading poll found 48 percent of security professionals now rank agentic AI the top attack vector of the year.

DIVD had competent defenses: segmentation limited how far the agent could move, and a team cut off the entire data center within a day. None of it stopped the initial compromise or the exfiltration. The whole attack lived inside the window human response cannot close, the seconds between first exploitation and the first alert.

The practical consequence is a shift in where defense happens. Detecting a zero-day by signature is impossible by definition, so teams must detect behaviors instead: a service account spawning a shell, processes running as root where they should not, outbound traffic to unfamiliar destinations. Containment decisions that used to wait for human approval increasingly need to be pre-authorized and automatic.

What Zammad administrators should do

The guidance from DIVD and Sysdig is unusually blunt. Upgrade to Zammad 7.2.0 or later, or take the instance offline. Versions 6.5 and earlier no longer receive security updates, so upgrading is the only path. Version 7.0 and later are not practically affected by the remote code flaw, and 7.2.0 adds hardening, but the privilege escalation flaw has no patch in any release. Until one ships, restrict server access to trusted administrators, run DIVD's published IoC log-check script against your logs, preserve those logs before patching, and treat any sign of exploitation as full host compromise, rotating every reachable credential.

Segmentation deserves special attention because it worked at DIVD. A helpdesk host concentrates secrets: database credentials, mail and API tokens, keys for every system the support team touches. Its own network segment with default-deny outbound access turns exfiltration from a quiet event into a blocked one, even after compromise.

One quieter risk outlasts the patching. The theft of volunteers' email addresses opens the door to impersonating DIVD personnel, a credential of trust aimed at organizations the institute normally protects. The barrier between finding a zero-day and weaponizing it at scale has collapsed to a single software agent, operating alone, in seconds.