Threat Brief — 2026-09-30 — Zammad zero-days identified in DIVD breach
DIVD has disclosed the technical root cause of its recent network breach: a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. This is the first specific detail on the entry vector since the breach was initially reported yesterday. Otherwise, today's feed is dominated by previously covered stories with no material developments.
Top items
- DIVD breach attributed to chained Zammad zero-days. The Dutch Institute for Vulnerability Disclosure has confirmed that the compromise of its network — initially reported on 2026-09-29 as an AI-agent-driven breach — was enabled by exploiting a chain of two unpatched zero-day vulnerabilities in the open-source Zammad ticketing platform. The identification of the specific entry vector is a genuine development; organisations running Zammad should treat this as a prompt to verify patch status. (src: BleepingComputer) — Developing; first reported 2026-09-29 by BleepingComputer.
Themes
AI agents as both attack vector and attack surface. The DIVD development adds another facet to an already crowded AI-security theme this cycle: an AI agent was used to carry out the breach, and the enabling vulnerabilities were in a ticketing system that AI tooling increasingly integrates with. This sits alongside several ongoing stories — self-replicating prompt injection, AI coding agents leaking internal images, Microsoft contractor access to Copilot prompts, and OpenAI's suspension of GPT-6.1 Astra training — all pointing to a maturing but still porous AI attack surface.
