AI-Driven Hack Exploits Zammad Zero-Day Vulnerabilities in DIVD Breach
PremiumDIVD says chained Zammad zero-days enabled session hijack, RCE, and privilege escalation to root in its AI-driven breach.
§Topic · Identity, Access & Credentials
Credential theft, infostealers, session hijacking, MFA bypass, SSO and Active Directory attacks.
All dispatchesTeamFiltration campaign (UNK_CondorFiltration) compromised Microsoft 365 accounts across 28 tenants, impacting Chilean retail and finance.
Active exploitation of a critical F5 BIG-IP OAuth/APM zero-day enables unauthenticated remote code execution; immediate patching required.
Infostealer logs reveal replayable AI tokens and API keys that attackers reuse to access model providers, bypassing MFA protections.
Attackers use passkey-themed social engineering to hijack Microsoft 365 accounts, bypassing MFA and exfiltrating cloud data.
Three suspected Russian espionage clusters abuse OAuth and WhatsApp linking to hijack accounts at academia, aerospace and governments.
Critical Entra ID RCE patched; exploited reports prompted emergency guidance and wide Microsoft updates.
Get these articles delivered to your inbox.
Subscribe free