An automated artificial intelligence agent has been linked to a cyberattack against a Dutch cybersecurity organisation, exposing how attackers can use AI to carry out intrusions with limited human intervention.
The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organisation that identifies software vulnerabilities and warns affected companies, confirmed the breach on September 24.
In its latest findings, published on September 30, DIVD identified two previously unknown vulnerabilities in Zammad, an open-source customer-support platform, that attackers exploited to breach its systems.
The organisation has assigned the vulnerabilities two security identifiers, CVE-2026-102489 and CVE-2026-102490. It has also begun identifying and notifying other organisations potentially exposed to the same weaknesses.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
How an AI Agent Entered a Cybersecurity Organisation
DIVD’s investigation established that attackers first accessed its infrastructure on September 21. The organisation detected suspicious activity the following day and immediately blocked access to systems in its data centre.
A forensic investigation was launched with assistance from cybersecurity firm Merlon Security.
What investigators subsequently discovered was an unusual attack pattern.
According to DIVD’s account, the attacker exploited a technical vulnerability before deploying an automated AI agent to perform further activities inside its network.
Unlike conventional automated hacking tools that follow predefined instructions, the agent reportedly selected its next action after completing each previous step.
The organisation described the attack as noisy and poorly executed. Despite successfully entering the network, the AI agent made repeated operational mistakes that helped investigators reconstruct its activities.
Researchers observed it interfering with its own attempt to intercept communications by simultaneously conducting password-spraying activity.
DIVD also reported that the agent left unusually detailed comments explaining its actions.
These mistakes provided valuable forensic evidence. However, the organisation has not established the attacker’s identity or publicly disclosed the complete impact of the intrusion.
What Are AI Agents and Why Does This Attack Matter?
An AI agent is software capable of performing tasks, making decisions and choosing subsequent actions without requiring a person to approve every individual step.
In cybersecurity, such systems can potentially automate activities that previously required considerable manual effort.
For example, a conventional automated attack might repeatedly test a predefined set of passwords. An AI-enabled system could potentially interpret unsuccessful attempts, examine available information and select alternative actions.
This does not necessarily make every AI-powered attack sophisticated or successful.
The DIVD incident demonstrates that autonomous systems can also make mistakes. However, their ability to perform successive operations without continuous human direction creates additional challenges for cybersecurity teams.
In this case, investigators observed the agent making decisions rapidly after obtaining access to the compromised environment.
The available evidence does not establish which AI model powered the attack or how much human supervision was involved.
Investigators Identify Two Previously Unknown Zammad Vulnerabilities
DIVD’s September 30 findings identified two zero-day vulnerabilities in Zammad, a software platform commonly used to manage customer-support requests and help desks.
A zero-day vulnerability is a software weakness that attackers discover or exploit before affected organisations have had sufficient opportunity to protect themselves.
The first vulnerability, CVE-2026-102489, involves remote code execution. This type of flaw can allow an attacker to execute instructions on an affected system under certain conditions.
DIVD identified Zammad versions 6.3.0 through 6.5.4 as vulnerable. It also reported that the underlying weakness exists in certain version 7 releases but cannot be exploited under the environmental conditions identified by researchers.
The second vulnerability, CVE-2026-102490, involves local privilege escalation.
Put simply, it can allow someone who has already obtained limited access to gain more powerful permissions, potentially taking control of additional parts of the compromised system.
DIVD reported that this weakness affected a broad range of Zammad versions, including versions extending to the latest alpha release examined during its investigation.
The organisation has reported its findings to Zammad and started notifying potentially affected users.
Its published advisory recommends upgrading to Zammad version 7 or taking affected systems offline. However, the advisory also describes a privilege-escalation vulnerability affecting version 7 releases, making it important for administrators to verify the latest remediation guidance rather than assuming an upgrade alone addresses both weaknesses.
DIVD Investigates Breach as Other Organisations Face Potential Exposure
The investigation is continuing as DIVD works to determine the full consequences of the intrusion.
Following the initial discovery, the organisation isolated its infrastructure and brought in external incident-response specialists.
It also reported the incident to the Dutch data protection authority and the country’s National Cyber Security Centre.
DIVD has been cautious about publicly releasing certain technical information while its investigation continues. It previously explained that premature disclosure could complicate the investigation or expose other organisations to additional risks.
The organisation has now established a separate investigation into the Zammad vulnerabilities and is identifying potentially affected systems.
According to its published timeline, DIVD reproduced the vulnerabilities on September 22 and 23, reported them to Zammad on September 24 and began notifying vulnerable organisations on September 26.
The identity of the attacker, the complete extent of any data exposure and the precise objectives behind the intrusion remain unresolved.
The incident illustrates a developing cybersecurity challenge: defenders must address conventional software vulnerabilities while also preparing for attackers who can automate decisions and subsequent attack activities using artificial intelligence.
What this means for you
Organisations using Zammad should immediately review DIVD’s security advisories, identify potentially affected installations and follow the latest confirmed remediation instructions. Businesses should also strengthen access controls and monitor unusual system activity, as AI-assisted attacks can rapidly combine existing hacking techniques.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics