decrypted · 1 october 2026 · vulnerabilities and patching · ai and llm security · surveillance and privacy

A Zammad zero-day chain let an AI agent breach the people who find zero-days

The organisation that finds other people's security holes has been breached through two of them. The Dutch Institute for Vulnerability Disclosure (DIVD) said this week that attackers got into its network through two previously unknown flaws in Zammad, an open-source helpdesk system, and that the way the intruder worked points to an agentic AI at the controls. For UK organisations the lesson is not the AI. It is how much a helpdesk server was trusted.

What happened

According to DIVD's case file, the first malicious access came on 21 September. DIVD spotted it the next day, disconnected its datacentre systems and brought in Merlon Security for forensics. It reported the flaws to Zammad on 24 September and began warning other users from 26 September.

The two bugs chain together. CVE-2026-102489 is a session hijacking flaw that gives remote code execution as the low-privilege zammad user. DIVD lists it as affecting versions 6.3.0 through 6.5.4, with limited exploitability in 7.0.0 to 7.1.3. CVE-2026-102490 then lets that local user become root, and DIVD lists it as affecting every version from 1.5.0 to 7.1.0-alpha. BleepingComputer reports the pair let the attacker climb from nothing to root in seconds.

The hotel analogy

Think of a hotel. The first flaw is a stolen staff lanyard: it gets you into the building as a cleaner. The second is a master key left in the cleaners' cupboard. Together they open every room, and an automated guest can try every door faster than any night porter can react.

Why the AI matters, and why it does not

DIVD's case file describes the breach as a hack through AI agents. That is DIVD's assessment from the behaviour it saw, and the investigation is still open. BleepingComputer reports that the agent recorded its own reasoning, which let DIVD reconstruct what it did.

Whatever drove it, the defender's problem is speed. A human intruder pauses, makes mistakes and keeps office hours. Software that chains a session bug into root and starts reading files does not, so the gap between first access and data leaving can shrink to minutes.

What helped DIVD was ordinary design. Network segmentation, BleepingComputer reports, stopped deeper lateral movement, and DIVD noticed the activity the next day. It has also made its case file public and kept it updated.

The Secure by Design lesson

Three decisions would have limited this:

The cost is modest. List your self-hosted helpdesk, wiki and ticketing systems, ask who can reach them from the internet, and ask what a root user on that box could read next. Opinion, not advice: if the honest answer is everything, the segmentation is the project, not the patch.

Also this week

MikroTik RouterOS. CISA published advisory ICSA-26-272-06 on 29 September for CVE-2026-84411, a pre-authentication integer underflow in the web management service, scored 9.8. One crafted request can give root code execution or a crash. CISA lists RouterOS versions before 7.24 as affected and says it knows of no exploitation. Update to 7.24 or later, and keep management interfaces off the internet. Routers sit at the edge of many small UK offices and branch sites, so an inventory check is better than a shrug.

Star Blizzard. Microsoft said on 29 September that the Russian state actor has run at least 13 large-scale phishing campaigns, affecting over 100 organisations primarily in the United States and United Kingdom. The new RedFlick technique needs only one user interaction: a password-protected ZIP holding a virtual disk, and an installer that creates three scheduled tasks. Lures are often conference invitations aimed at NGOs, think tanks and governments. Opinion: blocking disk-image attachments at the mail gateway is cheap.

Paragon. Spyware maker Paragon's parent, RedLattice, plans to list on Nasdaq through a $1.25bn merger with the SPAC Bold Eagle, announced on 28 September and expected to close around year end. SiliconANGLE describes Graphite, Paragon's flagship product, as mobile spyware that can infiltrate messaging apps. A listed company must file more disclosures, which is useful, but it also makes surveillance a growth market. For UK readers the question is who buys such tools, and under what warrant.

Sources

If you want a second pair of eyes on how your helpdesk and ticketing systems are segmented, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.