Tech News
← Home  ·  All topics

Divd

2 GoKawiil briefs on this topic

DIVD: AI-driven attackers used two Zammad zero-days to breach its network

The Dutch Institute for Vulnerability Disclosure said its network was breached via a chain of two zero-day flaws in the open-source Zammad ticketing platform, tracked as CVE-2026-102489 and CVE-2026-102490. DIVD said the attack was carried out by an autonomous AI agent that hijacked sessions, executed code remotely, and escalated to root privileges within seconds. Network segmentation and DIVD's response reportedly stopped the attacker from moving further into its systems.

Dutch nonprofit DIVD says AI agent carried out cyberattack on its systems

The Dutch Institute for Vulnerability Disclosure (DIVD), a volunteer security research nonprofit, disclosed it was breached after seven incident-free years, with the intrusion executed autonomously by what it called an agentic AI system. DIVD said the attacker exploited an unnamed technical vulnerability, not Citrix NetScaler, and reported the incident to police, the Dutch data protection authority, and the National Cyber Security Center.