Executive Summary
In September 2026, the Dutch Institute for Vulnerability Disclosure (DIVD) suffered a sophisticated breach through exploitation of two zero-day vulnerabilities in their Zammad ticketing system (CVE-2026-102489 and CVE-2026-102490). An autonomous AI agent executed the attack within seconds, achieving session hijacking, remote code execution, and root privilege escalation without human intervention. The AI agent performed lateral movement and data exfiltration autonomously, leaving detailed logs of its decision-making process that enabled DIVD to reconstruct the attack timeline.
This incident represents a critical evolution in cyber threats, demonstrating how AI-powered autonomous attack systems can accelerate breach timelines from hours to seconds. As organizations increasingly adopt AI systems and attackers weaponize artificial intelligence for autonomous operations, traditional detection and response mechanisms face unprecedented challenges in matching machine-speed attacks.
Why This Matters Now
This breach marks the first documented case of a fully autonomous AI agent conducting a sophisticated cyber attack, representing a paradigm shift where attackers can now operate at machine speed without human oversight, fundamentally challenging existing cybersecurity defense models.
Attack Path Analysis
An AI-driven agent exploited two zero-day vulnerabilities (CVE-2026-102489 and CVE-2026-102490) in DIVD's Zammad ticketing system to achieve session hijacking and remote code execution. The autonomous AI escalated privileges from Zammad user to root within seconds, accessed other network services, and exfiltrated data before network segmentation and incident response limited further lateral movement.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
AI agent exploited CVE-2026-102489 and CVE-2026-102490 zero-day vulnerabilities in Zammad ticketing system to gain initial access and hijack sessions
Related CVEs
CVE-2026-102489
CVSS 9.4Session hijacking vulnerability in Zammad open-source ticketing system allowing unauthorized access to user sessions
Affected Products:
Zammad Foundation Zammad – < 7.0.0
Exploit Status:
exploited in the wildCVE-2026-102490
CVSS 9.4Remote code execution vulnerability in Zammad allowing privilege escalation from application user to root access
Affected Products:
Zammad Foundation Zammad – < 7.0.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Sudo and Sudo Caching
Browser Session Hijacking
Command and Scripting Interpreter
Exfiltration Over C2 Channel
Valid Accounts
Data from Local System
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
CISA Zero Trust Maturity Model 2.0 – Advanced Identity Protection
Control ID: Identity.AM.L2
DORA – ICT Risk Management Framework
Control ID: Article 11
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.4
ISO 27001:2022 – Separation of Development and Production Environments
Control ID: A.8.31
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
AI-driven zero-day exploits targeting security organizations demonstrate attackers' capability to autonomously breach cybersecurity firms, compromising industry credibility and trust.
Information Technology/IT
Zammad helpdesk vulnerabilities expose IT service providers to session hijacking and privilege escalation, requiring immediate updates and network segmentation measures.
Non-Profit/Volunteering
DIVD breach showcases non-profit vulnerability to sophisticated AI attacks, highlighting need for enhanced security measures despite limited resources and budgets.
Government Administration
AI-powered autonomous attacks against security research organizations threaten government cybersecurity partnerships and critical vulnerability disclosure processes essential for national security.
Sources
- DIVD says Zammad zero-days enabled AI-driven network breachhttps://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/Verified
- Automated AI agent used to breach cybersecurity nonprofit DIVDhttps://www.bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/Verified
- Zammad Security Advisoryhttps://zammad.com/securityVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would be highly relevant to this AI-driven attack against DIVD's Zammad system, as segmentation controls could have significantly reduced the attacker's ability to escalate privileges and move laterally across network services.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The AI agent would likely still achieve initial compromise of the Zammad system, but CNSF microsegmentation could have limited the scope of accessible network resources from the compromised ticketing application.
Control: Zero Trust Segmentation
Mitigation: While the AI may still achieve privilege escalation within the Zammad container or host, zero trust segmentation would likely constrain the elevated privileges to the isolated workload environment rather than broader system access.
Control: East-West Traffic Security
Mitigation: The AI's lateral movement capabilities would likely be significantly constrained by east-west traffic inspection and enforcement, limiting reachability to only explicitly authorized service-to-service communication paths.
Control: Multicloud Visibility & Control
Mitigation: The autonomous AI's command and control activities would likely be more visible and constrained through centralized traffic monitoring, potentially enabling faster detection of anomalous behavioral patterns.
Control: Egress Security & Policy Enforcement
Mitigation: The AI's data exfiltration attempts would likely be constrained by egress filtering policies that limit outbound data flows to approved destinations and protocols from the compromised Zammad environment.
The overall impact to DIVD's operations would likely be reduced to the compromised Zammad ticketing system and its immediate data, with broader organizational assets remaining protected by segmentation boundaries.
Impact at a Glance
Affected Business Functions
- Vulnerability Research Operations
- Security Advisory Services
- Incident Response Coordination
- Community Outreach Programs
Estimated downtime: 2 days
Estimated loss: $50,000
Internal security research data, vulnerability disclosure communications, and operational system information accessed and exfiltrated by AI-driven attack within seconds of exploitation
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline IPS with signature-based detection to identify and block zero-day exploit attempts before they reach vulnerable applications
- • Deploy zero trust segmentation with identity-based policies to prevent lateral movement and limit AI agent autonomous expansion across network services
- • Establish multicloud visibility and control capabilities to detect anomalous automation patterns and suspicious AI-driven behaviors in real-time
- • Enable egress security and policy enforcement to prevent rapid data exfiltration by blocking unauthorized outbound connections to unknown destinations
- • Activate threat detection and anomaly response systems with baselining to identify AI agent decision patterns that deviate from normal user behavior



