The Dutch Institute for Vulnerability Disclosure (DIVD), a non-profit organization focused on ethically reporting security flaws, recently experienced a sophisticated cyberattack involving zero-day vulnerabilities. The attack, identified on September 24, exploited two critical zero-day flaws in the institute's helpdesk platform, Zammad. These vulnerabilities, a remote code execution bug (CVE-2026-102489) and an elevation of privileges flaw (CVE-2026-102490), both carry a CVSS score of 9.4 when combined. The attackers used these flaws to hijack sessions, execute code remotely, and escalate privileges rapidly, allowing them to access other services and extract data. In response, DIVD has strongly advised all Zammad users to upgrade to version 7 or disconnect the system immediately.

Thanks to DIVD's robust security measures and prompt action by their IT and incident response teams, the threat was contained, preventing further infiltration into their systems. However, the attack did compromise volunteer data, including email addresses and possibly contact details, posing a risk of identity impersonation by malicious actors. Logs from the incident revealed the use of agentic AI elements, with scripts that included self-justifying notes, a characteristic uncommon in human-driven attacks.

This incident underscores the critical importance of network segmentation and a proactive security posture. Tim Burke, CEO of Quest Technology Management, highlighted that AI-driven attacks can significantly shorten detection and response times, emphasizing that fundamental security practices like patching, monitoring, and incident response remain essential. Burke noted that the initial focus during such incidents should be on containment, including isolating affected systems and blocking suspicious activities, with clear authority established for taking these urgent actions.