Skip to main content

Share story

Security AI

DIVD identifies Zammad zero-day chain behind network breach

DIVD identifies Zammad zero-day chain behind network breach Image: Primary
The Dutch Institute for Vulnerability Disclosure says two previously unknown Zammad vulnerabilities enabled the breach of its network. The flaws, CVE-2026-102489 and CVE-2026-102490, allowed session hijacking, remote code execution and escalation to root privileges. DIVD says an autonomous AI agent exploited the chain and accessed and exfiltrated data within seconds. It reconstructed the incident using explanations the agent left behind. Network segmentation and incident response prevented deeper movement, but the investigation continues. DIVD notified Zammad and recommends that users upgrade to version 7, which it considers safe, or take vulnerable instances offline.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Products Infrastructure
Products Infrastructure

HPE announces $1.2 billion Vultr order and raises networking outlook

Hewlett Packard Enterprise announced a $1.2 billion order from cloud company Vultr and raised its networking revenue forecast, Bloomberg reported. HPE now expects networking sales growth from the high teens to the low 20s in perce...

Infrastructure Products
Infrastructure Products

Accelevation raises $540 million in IPO priced below marketed range

Accelevation Holdings and its private equity backer raised $540 million in an initial public offering priced below its marketed range, Bloomberg reported. Shares of the data center infrastructure company fell 2.5% after the offeri...

Capital AI
Capital AI

Flow Engineering raises $50 million at $750 million valuation

Flow Engineering raised $50 million at a $750 million valuation to help companies use AI agents to design and build hardware, Bloomberg reported. Founder and CEO Pari Singh discussed the financing on Bloomberg Tech alongside inves...

Security
Security

Cisco patches actively exploited SD-WAN authentication bypass

Cisco released fixes for CVE-2026-76504, a critical flaw in Catalyst SD-WAN Manager that the company says attackers are actively exploiting. The vulnerability lets unauthenticated attackers gain remote administrator access and aff...