Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI-Aided Hack Exploits Zammad Vulnerabilities

AI-Aided Hack Exploits Zammad Vulnerabilities

Posted on October 1, 2026 By CWS

The Dutch Institute for Vulnerability Disclosure (DIVD) recently encountered a sophisticated cyber attack leveraging artificial intelligence to exploit two undisclosed vulnerabilities in the Zammad support platform. This breach, which took place on September 21, prompted DIVD to initiate a comprehensive incident response, temporarily suspending access to its systems while they investigated the intrusion.

Details of the Cyber Attack

In a LinkedIn update dated September 24, DIVD characterized the attack as unique due to its AI-driven nature. The organization’s investigation revealed that the cybercriminals exploited two specific zero-day vulnerabilities in the Zammad system, which they detailed on September 30. The initial flaw, identified as CVE-2026-102489 with a critical CVSS score of 9.4, allowed unauthorized attackers to execute remote code and access user sessions.

The second vulnerability, CVE-2026-102490, also scored at 9.4 on the CVSS scale, enabling local users to elevate their privileges to root. When combined, these vulnerabilities facilitated the attackers’ ability to manipulate sessions, execute remote code, and escalate privileges rapidly, all due to the AI components of the attack.

Impact and Mitigation Efforts

The attackers managed to move laterally from the compromised Zammad instance, targeting additional services and extracting data. However, DIVD’s network segmentation efforts successfully limited the attackers’ reach within the environment. The organization continues to investigate potential signs of compromise and considers any unauthorized access a serious breach until proven otherwise. DIVD regards halting the attack as a significant victory in their ongoing cybersecurity efforts.

Following the identification of these vulnerabilities, DIVD promptly reported them to Zammad. The company is actively working on remedies for these security issues. Affected versions include Zammad 6.3.0 to 6.5.4, with versions 7.0.0 to 7.1.3 also affected but less susceptible to exploitation due to specific environmental conditions.

Recommendations and Future Outlook

DIVD strongly recommends that Zammad users upgrade to version 7 or temporarily disable the system to mitigate potential risks. To support organizations in identifying potential compromises, DIVD has released a verification script and is actively scanning for vulnerable Zammad instances, notifying their respective administrators.

As cyber threats evolve, this incident underscores the importance of robust security measures and timely updates. Organizations are urged to remain vigilant and proactive in addressing vulnerabilities to protect against similar sophisticated attacks in the future.

Security Week News Tags:AI attack, Cybersecurity, DIVD hack, incident response, network security, privilege escalation, remote code execution, vulnerability disclosure, Zammad vulnerabilities, zero-day exploit

Post navigation

Previous Post: FTC Probes AI Firms Over Customer Safety Concerns
Next Post: Mac Users Targeted by Fake Zoom Installer and CloudSyncD Backdoor

Related Posts

Oneleet Raises  Million for Security Compliance Platform Oneleet Raises $33 Million for Security Compliance Platform Security Week News
Check Point Issues Critical Patch for Zero-Day Vulnerability Check Point Issues Critical Patch for Zero-Day Vulnerability Security Week News
AIVEX: A New Model to Mitigate Supply Chain Risks AIVEX: A New Model to Mitigate Supply Chain Risks Security Week News
Opal Security Secures M to Enhance AI Identity Governance Opal Security Secures $23M to Enhance AI Identity Governance Security Week News
ForceMemo Campaign Exploits GitHub for Malware Injection ForceMemo Campaign Exploits GitHub for Malware Injection Security Week News
ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Activates Windows 11 Backup Setting for Businesses
  • Mac Users Targeted by Fake Zoom Installer and CloudSyncD Backdoor
  • AI-Aided Hack Exploits Zammad Vulnerabilities
  • FTC Probes AI Firms Over Customer Safety Concerns
  • Osavul Secures $10M to Enhance Hybrid Threat Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Activates Windows 11 Backup Setting for Businesses
  • Mac Users Targeted by Fake Zoom Installer and CloudSyncD Backdoor
  • AI-Aided Hack Exploits Zammad Vulnerabilities
  • FTC Probes AI Firms Over Customer Safety Concerns
  • Osavul Secures $10M to Enhance Hybrid Threat Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark