A New Frontier in Automated Exploitation
The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organization dedicated to uncovering security flaws, has officially confirmed that it was compromised by an autonomous, agentic AI. This breach marks a significant milestone in cyber warfare, as the attackers utilized a high-speed, automated "modus operandi" that security experts have rarely encountered in the wild. The incident underscores the escalating sophistication of AI-powered threats, where machines are now capable of chaining vulnerabilities and executing complex attacks without direct human oversight.
The Anatomy of the Zammad Breach
The attack centered on two critical zero-day vulnerabilities within the Zammad open-source helpdesk platform, designated as CVE-2026-102489 and CVE-2026-102490. According to the investigation, the AI agent successfully exploited the first vulnerability to gain unauthenticated remote code execution and perform session hijacking. Within seconds, it pivoted to the second exploit, elevating its privileges to root access. The rapid progression of these events left the organization's defenses reeling.
Both vulnerabilities received a daunting CVSS 4.0 score of 9.4. While the first bug affects specific iterations of Zammad versions 6.3.0 through 7.1.3, the second vulnerability impacts all versions of the software. DIVD has urgently advised all Zammad users to migrate to version 7 or temporarily take their systems offline to prevent further exploitation until patches are fully propagated.
Evidence of AI Agency
What distinguished this attack from traditional human-led operations was the sheer velocity and distinct methodology of the intrusion. DIVD security researchers noted that the "agent" appeared to make real-time decisions, autonomously selecting its next move after every action. This behavior was described as "loud and messy," moving at a pace far beyond typical human capacity.
Perhaps most startling was the discovery of internal "notes" embedded within the malicious scripts. The AI agent appeared to be documenting its own logic, leaving comments in the code to justify its actions—a behavior fundamentally antithetical to standard human hacking practices. Experts suggest this confirms that the attacker was operating under a broad, high-level task, with the AI autonomously determining how to navigate the system to achieve its objectives.
Why It Matters
- Automated Escalation: The speed at which the AI transitioned from initial access to root control highlights the extreme danger of agentic systems when used for malicious purposes.
- Transparency as Defense: By openly disclosing the breach, the DIVD has provided the security community with a rare, candid look at the capabilities of AI-driven threats.
- New Threat Vectors: The use of embedded "justification" logs suggests that AI agents may be optimizing for goals rather than just following rigid attack strings, making them harder to detect through traditional pattern-matching filters.
Outlook and Mitigation
The breach has resulted in the theft of volunteer contact information, including email addresses, heightening the risk of targeted social engineering attacks. DIVD is currently working with police and data protection authorities while urging its community to exercise extreme caution regarding any communications that appear suspicious. This event serves as a stark wake-up call for organizations relying on automated ticketing and support infrastructure: the tools of the trade are evolving, and the next wave of adversaries may not be human at all.











