decrypted · 1 october 2026 · vulnerabilities and patching · ai and llm security · surveillance and privacy
A Zammad zero-day chain let an AI agent breach the people who find zero-days
The organisation that finds other people's security holes has been breached through two of them. The Dutch Institute for Vulnerability Disclosure (DIVD) said this week that attackers got into its network through two previously unknown flaws in Zammad, an open-source helpdesk system, and that the way the intruder worked points to an agentic AI at the controls. For UK organisations the lesson is not the AI. It is how much a helpdesk server was trusted.
What happened
According to DIVD's case file, the first malicious access came on 21 September. DIVD spotted it the next day, disconnected its datacentre systems and brought in Merlon Security for forensics. It reported the flaws to Zammad on 24 September and began warning other users from 26 September.
The two bugs chain together. CVE-2026-102489 is a session hijacking flaw that gives remote code execution as the low-privilege zammad user. DIVD lists it as affecting versions 6.3.0 through 6.5.4, with limited exploitability in 7.0.0 to 7.1.3. CVE-2026-102490 then lets that local user become root, and DIVD lists it as affecting every version from 1.5.0 to 7.1.0-alpha. BleepingComputer reports the pair let the attacker climb from nothing to root in seconds.
The hotel analogy
Think of a hotel. The first flaw is a stolen staff lanyard: it gets you into the building as a cleaner. The second is a master key left in the cleaners' cupboard. Together they open every room, and an automated guest can try every door faster than any night porter can react.
Why the AI matters, and why it does not
DIVD's case file describes the breach as a hack through AI agents. That is DIVD's assessment from the behaviour it saw, and the investigation is still open. BleepingComputer reports that the agent recorded its own reasoning, which let DIVD reconstruct what it did.
Whatever drove it, the defender's problem is speed. A human intruder pauses, makes mistakes and keeps office hours. Software that chains a session bug into root and starts reading files does not, so the gap between first access and data leaving can shrink to minutes.
What helped DIVD was ordinary design. Network segmentation, BleepingComputer reports, stopped deeper lateral movement, and DIVD noticed the activity the next day. It has also made its case file public and kept it updated.
The Secure by Design lesson
Three decisions would have limited this:
- A service account that cannot become root. CVE-2026-102490 is a local privilege escalation, so running the application in a locked-down container turns a root compromise into a contained one.
- Segmentation that assumes the helpdesk will fall. The agent reached other services and files, and segmentation is the control that decides how far a bad day spreads.
- A patch plan for tools nobody calls critical. BleepingComputer says Zammad has more than 2,000 customers. DIVD's advice is blunt: upgrade to version 7 or take the instance offline, then run its verification script against your logs.
The cost is modest. List your self-hosted helpdesk, wiki and ticketing systems, ask who can reach them from the internet, and ask what a root user on that box could read next. Opinion, not advice: if the honest answer is everything, the segmentation is the project, not the patch.
Also this week
MikroTik RouterOS. CISA published advisory ICSA-26-272-06 on 29 September for CVE-2026-84411, a pre-authentication integer underflow in the web management service, scored 9.8. One crafted request can give root code execution or a crash. CISA lists RouterOS versions before 7.24 as affected and says it knows of no exploitation. Update to 7.24 or later, and keep management interfaces off the internet. Routers sit at the edge of many small UK offices and branch sites, so an inventory check is better than a shrug.
Star Blizzard. Microsoft said on 29 September that the Russian state actor has run at least 13 large-scale phishing campaigns, affecting over 100 organisations primarily in the United States and United Kingdom. The new RedFlick technique needs only one user interaction: a password-protected ZIP holding a virtual disk, and an installer that creates three scheduled tasks. Lures are often conference invitations aimed at NGOs, think tanks and governments. Opinion: blocking disk-image attachments at the mail gateway is cheap.
Paragon. Spyware maker Paragon's parent, RedLattice, plans to list on Nasdaq through a $1.25bn merger with the SPAC Bold Eagle, announced on 28 September and expected to close around year end. SiliconANGLE describes Graphite, Paragon's flagship product, as mobile spyware that can infiltrate messaging apps. A listed company must file more disclosures, which is useful, but it also makes surveillance a growth market. For UK readers the question is who buys such tools, and under what warrant.
Sources
- DIVD case DIVD-2026-00014: DIVD got hacked through AI agents
- DIVD case DIVD-2026-00015: Zammad vulnerabilities
- BleepingComputer: DIVD says Zammad zero-days enabled AI-driven network breach
- CISA ICSA-26-272-06: MikroTik RouterOS
- Microsoft Security blog: Star Blizzard and the RedFlick technique
- SiliconANGLE: RedLattice to go public in $1.25B SPAC deal
If you want a second pair of eyes on how your helpdesk and ticketing systems are segmented, get in touch.
More like this
- A Russian spy operation had Claude rewrite its own malware after getting caught 13 september 2026
- An MCP flaw lets a rogue tool server steal an AI agent's login keys 29 september 2026
- Supabase's secure default skips the way most apps are built now 29 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.