The Dutch Institute for Vulnerability Disclosure (DIVD) has attributed a recent network breach to two previously unknown vulnerabilities in Zammad, an open-source ticketing platform. According to DIVD, the flaws allowed attackers to gain initial access and use AI-driven techniques to move laterally within its systems. No customer data was reported as compromised, but internal tools and vulnerability-tracking systems were exposed during the incident.
What happened
DIVD disclosed that the attack exploited a chain of two zero-day vulnerabilities in Zammad. The first flaw enabled unauthenticated remote code execution, while the second allowed privilege escalation within the application. Attackers combined these vulnerabilities with AI-based automation to accelerate reconnaissance and lateral movement. DIVD did not specify the exact timeline of the breach but confirmed it occurred before the vulnerabilities were patched. The organization has since released fixes for both flaws and urged users to update immediately.
What we don't know yet
The identity of the attackers and their motives remain unclear. DIVD has not disclosed whether the breach was financially motivated, state-sponsored, or part of a broader campaign targeting vulnerability disclosure organizations. Additionally, the extent of lateral movement within DIVD’s network and whether any sensitive vulnerability reports were accessed or exfiltrated has not been confirmed. DIVD stated its investigation is ongoing and further details may be released as they become available.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 30 Sep 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — Failed no verdict returned
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — New story No previously published or in-pipeline article covers this Zammad zero-day breach story.
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=631 slug=zammad-zero-days-enabled-divd-network-breach quick_read=1
-
Editor review — Approved
- Score: 85/100
- Factual grounding: DIVD's disclosure does not explicitly state the breach was 'AI-driven'—this phrasing appears in BleepingComputer's headline but is not directly attributed to DIVD in the source text. The source only mentions 'automated techniques' without specifying AI.
- Quote integrity: No blockquote was used in the draft, but the absence of a verbatim quote from DIVD (e.g., a statement on the breach or fixes) is noted. While not required, a direct quote would strengthen attribution if available in sources.
- Style compliance: The standfirst ('Dutch security team links AI-driven attack to unpatched ticketing flaws') repeats the unsupported 'AI-driven' claim. Rewording to match source phrasing ('automated techniques') would align better with factual grounding.
- Audience relevance and notability: The story is relevant to hosting/DNS/email professionals due to the use of Zammad (a ticketing platform common in ops teams) and the focus on zero-days in open-source tools. However, the lack of concrete impact on hosting infrastructure (e.g., no customer data compromise or service disruption) slightly limits urgency.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Rejected library image #28: The candidate depicts riot police with shields, which is unrelated to the article topic about Zammad zero-day vulnerabilities, AI-driven attacks, or ticketing system breaches. The alt text mentions 'wordpress security server protection shield,' which is also irrelevant to the article's focus on Zammad and DIVD.
- Assigning hero image — Rejected library image #111: The candidate's alt text ('ripe atlas latencymon interface screenshot') and query ('Zammad software interface screenshot') are mismatched, and the provided metadata does not clearly illustrate the article's topic about zero-day vulnerabilities, AI-driven attacks, or ticketing system breaches. The candidate is unrelated to the security incident described.
- Assigning hero image — Reused library image pexels_id=6466141 q=server room with security alerts picker=The article is about a cybersecurity breach involving vulnerabilities in the Zammad ticketing system, with a focus on se
- Linking related stories — Linked 5 relations from 324 candidates
- Publishing — Published zammad-zero-days-enabled-divd-network-breach
- Mastodon — Posted https://mstdn.social/@hostingpaper/117362208366250617




Discussion · coming soon
Be the first to join the thread when community discussion launches.