As outlined in Bleeping Computer, the Dutch Institute for Vulnerability Disclosure (DIVD) has reported a significant network breach facilitated by an autonomous AI agent that exploited two zero-day vulnerabilities in the open-source Zammad ticketing system.
The attack, described as "loud and very, very messy," was executed by an AI agent that operated without human intervention, making its own decisions to navigate and exfiltrate data. The two zero-day flaws, identified as CVE-2026-102489 and CVE-2026-102490, allowed the attacker to hijack sessions, execute remote code, and escalate privileges to root access within seconds. While the threat actor did not penetrate deeper into DIVD's network due to segmentation and incident response, the incident highlights the growing threat of AI-powered attacks. Zammad, a popular helpdesk and support ticketing platform used by over 2,000 organizations, has released version 7 to address these vulnerabilities. DIVD is urging all users to upgrade or take their instances offline immediately.
Source: Bleeping Computer
