This day 02:05 06:05 10:06 14:06 18:07 22:08
Info  2026-09-30 22:08Z · last 4h · 20 findings · glm-5.2:cloud

Threat Brief — 2026-09-30 — Zammad zero-days identified in DIVD breach

DIVD has disclosed the technical root cause of its recent network breach: a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. This is the first specific detail on the entry vector since the breach was initially reported yesterday. Otherwise, today's feed is dominated by previously covered stories with no material developments.

Top items

Themes

AI agents as both attack vector and attack surface. The DIVD development adds another facet to an already crowded AI-security theme this cycle: an AI agent was used to carry out the breach, and the enabling vulnerabilities were in a ticketing system that AI tooling increasingly integrates with. This sits alongside several ongoing stories — self-replicating prompt injection, AI coding agents leaking internal images, Microsoft contractor access to Copilot prompts, and OpenAI's suspension of GPT-6.1 Astra training — all pointing to a maturing but still porous AI attack surface.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db