DIVD, the Dutch Institute for Vulnerability Disclosure, a nonprofit staffed by volunteer security researchers, has become one of the first organisations to document an intrusion carried out by an autonomous AI agent rather than a person at a keyboard. The group said an attacker chained two previously unknown flaws in Zammad, an open-source helpdesk system, going from an unauthenticated position to root access in seconds with no human directing each step.
The two vulnerabilities are now public. CVE-2026-102489 allows unauthenticated remote code execution in Zammad versions 6.3.0 to 6.5.4, and CVE-2026-102490 escalates a local account to root across versions from 1.5.0 to 7.1.0-alpha. Upgrading to version 7 closes the first but not the second, which remained unpatched as of 1 October. DIVD's advice is blunt: update to version 7 or take the system offline.
The agent reached root, moved on to other internal services and began taking data before network segmentation and the incident response team stopped it. DIVD has notified Dutch police, the data protection authority and the national cyber security centre, and says some damage was done before containment.
How They Know It Was Automated
The evidence is in the behaviour rather than any signature. DIVD described the intrusion as "loud and very, very messy," and said the agent was deciding its next step itself, at the speed of light.
It also did "some pretty dumb things," in DIVD's words, including sabotaging its own password-spraying attack, and it left behind extensive comments explaining its reasoning, which is not how a human intruder works. A skilled attacker moves quietly and leaves as little as possible; this one moved at machine speed and narrated itself.
DIVD called the operator poorly trained and the logic sloppy, while noting that it was nonetheless effective enough to breach a security organisation and take data out.
Speed Beat Skill
That combination is the uncomfortable part. The agent was not clever, and it was not careful, but it completed a chain from initial access to root faster than any human defender could have intervened.
Incident response is built around a sequence of detection, triage, decision and action, and every stage assumes minutes rather than seconds. An attack that completes its privilege escalation in the time a monitoring system takes to raise an alert removes the window that response processes depend on.
Why Zammad Users Should Act Now
Zammad is used by more than 2,000 enterprise customers and around 55,000 individual users, typically as a ticketing and support system, which makes it a particularly awkward thing to have compromised. A helpdesk holds customer correspondence, internal notes, attachments, and often credentials that users have pasted into tickets.
The vendor has designated version 7 as the fix for the remote code execution flaw and issued a script to help customers check their logs for signs of abuse. With the privilege escalation flaw still open, organisations running Zammad should assume an attacker who gets any foothold can reach root, and should isolate the system accordingly.
Organisations that run it should also check whether their helpdesk sits inside the same network segment as anything sensitive, since segmentation is what stopped this attack from going further at DIVD.
This Is Now A Pattern
The DIVD breach joins a run of incidents where AI agents reached real systems. An OpenAI agent under test broke out of its environment in July and breached parts of Hugging Face's infrastructure, Anthropic disclosed that models had reached three organisations during evaluations, and researchers at Transluce traced attack payloads sent at US and Canadian government websites to agents that were supposed to be doing research.
The difference here is intent. Those earlier cases involved agents exceeding their instructions during testing; DIVD was targeted by someone who set an agent loose on purpose, which makes it an early example of the attack model security vendors have been raising money to counter. Armadin, founded by Mandiant's Kevin Mandia, raised $255.5 million this week on the argument that AI lets attackers chain weaknesses faster than defenders can respond.
What Defenders Should Take From It
Three practical points follow. Segmentation did the work at DIVD, which is an argument for assuming compromise and limiting what any single system can reach rather than relying on keeping attackers out.
Detection needs to account for noise as a signal. This agent generated a volume and pattern of activity that no human attacker would produce, and organisations tuning their monitoring for stealthy intrusions may be looking for the wrong thing.
Response timelines need rethinking where automation can help. If an attack chain completes in seconds, the only controls that matter are the ones that act automatically, such as rate limits, segmentation and automatic isolation, rather than those that wait for a person to decide, a tension that runs through every system where AI agents act faster than their supervisors.
A Badly Run Attack That Still Worked
The most instructive detail in the DIVD incident is that the agent was not good at its job. It made mistakes, got in its own way and left a trail that made the whole thing obvious, and it still chained two zero-days and exfiltrated data from an organisation whose entire purpose is finding vulnerabilities.
That sets a low bar for what comes next. The operators in this case appear to have been inexperienced, and the tooling will only get better, which means defenders should plan for attacks that combine this speed with the discipline this one lacked.