AI agents hacked the hackers, stealing email addresses from security research org
Attackers chained two Zammad zero-days to breach DIVD and steal volunteer researchers' email addresses.
On September 21, attackers breached the Dutch Institute for Vulnerability Disclosure through two zero-days in its Zammad helpdesk, CVE-2026-102489 and CVE-2026-102490. The chain leaked sessions, ran code as the zammad user, and escalated to root within seconds. Stolen data includes volunteer email addresses and possibly other contact details. DIVD said the messy, self-commenting scripts suggest an agentic AI operator and advised all Zammad users to upgrade to version 7 or take systems offline.
81