The Dutch Institute for Vulnerability Disclosure (DIVD) faced a potential nightmare for any CISO: an AI agent autonomously exploiting two zero-day vulnerabilities in their Zammad ticketing system. This attack escalated from session hijack to root access in seconds, exfiltrating data before human defenders could react.
This wasn't a theoretical exercise. It was a real breach against an organization of security researchers, and the speed of execution should concern you.
What Happened
DIVD uses Zammad, an open-source ticketing platform with over 2,000 customers and 55,000 users. An attacker exploited two previously unknown vulnerabilities, now tracked as CVE-2026-102489 and CVE-2026-102490, to compromise DIVD's system.
The attack chain enabled session hijacking, remote code execution, and privilege escalation from the Zammad application user to root. The AI agent then accessed other services and exfiltrated data from DIVD's systems. All of this occurred autonomously, with the agent making tactical decisions without human direction.
DIVD contained the breach through network segmentation and incident response, preventing lateral movement. The investigation continues.
Timeline
The specific timeline hasn't been disclosed, but DIVD described the attack as happening "in seconds" due to AI automation. Traditional attacks involve reconnaissance, tool deployment, and manual pivoting, creating detection windows measured in hours or days. This attack compressed those phases into moments.
The AI agent left detailed logs explaining its decision-making process, which allowed DIVD to reconstruct the incident. That transparency is unusual and likely unintentional, but it provided forensic visibility most organizations won't have in similar attacks.
Which Controls Failed or Were Missing
Vulnerability management for zero-days: Zero-day vulnerabilities have no patch at the time of exploitation. DIVD couldn't have patched what wasn't disclosed. However, the platform choice matters. Zammad is open-source, making the attack surface fully visible to anyone, including adversaries with AI-assisted code analysis tools.
Application isolation: The Zammad user account had sufficient privileges to enable escalation to root. This suggests the application wasn't running in a hardened, least-privilege configuration. If your ticketing system can reach root, you've given it more trust than it deserves.
Lateral movement prevention: Network segmentation worked. This control stopped the breach from becoming a full compromise. The attacker gained access to systems adjacent to Zammad but couldn't move deeper into the network.
Detection at machine speed: There's no indication DIVD detected the initial exploitation in real time. The attack moved faster than human-driven monitoring could respond. Traditional SIEM correlation rules and analyst review cycles aren't built for second-scale attack sequences.
What the Relevant Standards Require
NIST SP 800-53 Control SI-2 (Flaw Remediation) requires organizations to identify, report, and correct system flaws, and to install security-relevant software updates within organization-defined time periods. For zero-days, this means having a process to respond when a vendor releases an emergency patch, which Zammad did by recommending an immediate upgrade to version 7.
ISO/IEC 27001 Annex A.12.6.1 (Management of Technical Vulnerabilities) requires timely information about technical vulnerabilities, evaluation of exposure, and appropriate measures to address the risk. For open-source platforms, this includes monitoring security advisories from both the project maintainers and the broader community.
CIS Controls v8.1 Control 7.1 (Establish and Maintain a Vulnerability Management Process) calls for scanning systems for vulnerabilities and remediating them based on risk rating and criticality. Control 7.2 requires automated vulnerability scanning. Neither helps with zero-days until they're disclosed, but they establish the infrastructure you'll need to respond quickly when patches become available.
NIST SP 800-53 Control AC-6 (Least Privilege) requires each system component to operate with the most restrictive set of rights needed to perform authorized tasks. If your ticketing system runs with privileges that allow root escalation, you're not meeting this requirement.
NIST SP 800-61 (Computer Security Incident Handling Guide) describes the incident response lifecycle: preparation, detection and analysis, containment/eradication/recovery, and post-incident activity. DIVD's network segmentation demonstrates preparation that enabled effective containment. Their forensic reconstruction shows strong post-incident analysis capability.
Lessons and Action Items for Your Team
Audit your open-source platform footprint: List every open-source application in your environment that handles sensitive data or has network access. Zammad isn't unique. Open-source platforms are transparent by design, which benefits both defenders and attackers. If you're running self-hosted instances, you own the security posture.
Implement application-level least privilege: Review the system privileges assigned to your business applications. Your ticketing system, CRM, and collaboration tools shouldn't run with credentials that allow privilege escalation. Use dedicated service accounts with minimal permissions, and enforce that boundary with mandatory access controls where possible.
Test your segmentation under time pressure: DIVD's network segmentation prevented lateral movement, but only because it was already in place. Run tabletop exercises that assume an attacker has already compromised a business application and has seconds, not hours, to pivot. Can your segmentation hold?
Build a zero-day response playbook: You can't patch what doesn't have a CVE yet, but you can prepare to respond when one drops. Define who makes the decision to take a critical system offline, what the communication plan looks like, and what your rollback procedure is. DIVD recommended users either upgrade to version 7 or take instances offline immediately. Do you have the authority and process to make that call for your own platforms?
Rethink detection for autonomous attacks: If an AI agent can chain vulnerabilities and exfiltrate data in seconds, your weekly SIEM review isn't going to catch it. This doesn't mean you need an AI-powered defense system tomorrow, but it does mean you should prioritize detection mechanisms that operate at sub-minute intervals. Behavioral anomaly detection, automated session termination on privilege changes, and real-time egress monitoring become more valuable when attacks compress.
Evaluate hosted vs. self-hosted risk: Zammad offers both self-hosted and hosted options. Self-hosted gives you control but also full responsibility for patching, hardening, and monitoring. Hosted services shift some of that burden to the vendor, though you're still responsible for configuration and access controls. Reassess that trade-off in light of how quickly vulnerabilities can be weaponized.
The DIVD breach won't be the last AI-driven attack, and it probably won't be the fastest. Your incident response strategy was built for attacks that unfold over hours or days. Start adapting it for attacks that unfold in seconds.





