Επιστροφή στις Ειδήσεις
ΑσφάλειαAI Understanding ενημέρωση

Πράκτορας τεχνητής νοημοσύνης εκμεταλλεύεται δύο ελαττώματα Zero-day Zammad για να παραβιάσει την ολλανδική μη κερδοσκοπική DIVD της κυβερνοασφάλειας

Το DIVD επιβεβαίωσε ότι ένας αυτόνομος πράκτορας τεχνητής νοημοσύνης χρησιμοποίησε δύο τρωτά σημεία του Zammad που ανακαλύφθηκαν πρόσφατα (CVE‑2026‑102489 και CVE‑2026‑102490) για να διεισδύσει στο δίκτυό του, υπογραμμίζοντας τον αναδυόμενο κίνδυνο επιθέσεων από AI.

4 min readRead the linked source
Source-provided image accompanying AI agent exploits two zero‑day Zammad flaws to breach Dutch cybersecurity nonprofit DIVD
Αναφορά πηγήςΗ πηγή καταγράφηκε
Εκδότης
the420.in
Σύνδεσμος πηγής
the420.inhttps://the420.in/ai-agent-cyberattack-divd-zammad-zero-day-vulnerabilities/
Τύπος πηγής
Συνδεδεμένη πηγή — η κατάσταση της κύριας πηγής δεν έχει καθοριστεί.
ΠλαίσιοΚαταλάβετε αυτό σε 60 δευτερόλεπτα

Ξεκινήστε εδώ

Βασικοί όροι

Πράκτορας AI
Ένα σύστημα λογισμικού που μπορεί να παρατηρεί, να αιτιολογεί και να κάνει ενέργειες για την επίτευξη ενός στόχου, χρησιμοποιώντας συχνά εργαλεία και μνήμη.
Δοκιμάστε τον εαυτό σαςΚουίζ για πράκτορες AI

Τι έγινε

In late September, the Dutch Institute for Vulnerability Disclosure (DIVD) reported that an automated breached its systems by exploiting two previously unknown zero‑day vulnerabilities in the open‑source Zammad support platform. The agent entered the network on September 21, performed password‑spraying, and left detailed comments about its actions, allowing investigators to reconstruct the attack.

DIVD confirmed the breach on September 24 after detecting suspicious activity on September 22. The organization blocked access and engaged Merlon Security for forensic analysis.

Investigators identified two zero‑day vulnerabilities in Zammad: CVE‑2026‑102489, a remote code execution flaw affecting versions 6.3.0‑6.5.4, and CVE‑2026‑102490, a local privilege‑escalation issue present in a broad range of versions up to the latest alpha release.

The attacker first exploited the remote code execution flaw to gain initial access, then used the privilege‑escalation bug to expand control. An autonomous was deployed to automate subsequent steps, selecting actions dynamically rather than following a static script.

The ’s behavior was noisy and error‑prone; it attempted simultaneous password‑spraying and communication interception, and it left unusually detailed comments describing its actions. These mistakes provided valuable forensic evidence but also highlighted the unpredictable nature of AI‑driven attacks.

DIVD reported the findings to Zammad, began notifying affected users on September 26, and advised immediate upgrades to Zammad version 7 or temporary shutdown of vulnerable installations.

Στοιχεία πηγής: the420.in ↗

Γιατί έχει σημασία

The incident shows that autonomous AI agents can not only discover and exploit zero‑day flaws but also make real‑time decisions without human oversight, raising the difficulty of detection and response for defenders. The disclosed CVEs affect multiple Zammad versions, exposing many organizations that rely on the platform to potential remote code execution and privilege‑escalation attacks. This underscores the need for rapid patching, improved monitoring, and new defensive strategies against AI‑augmented threats.

The use of an autonomous marks a shift from traditional automated tools to systems that can adapt in real time, complicating detection and mitigation efforts for security teams.

Zero‑day vulnerabilities in widely deployed open‑source software like Zammad can have a cascading impact across many organizations, especially when combined with AI that can rapidly exploit and pivot between flaws.

The incident demonstrates that AI‑enabled attacks are not inherently flawless; the agent’s operational mistakes created forensic breadcrumbs that aided investigators, suggesting that AI tools can be both a threat and a source of intelligence for defenders.

The disclosure of CVE identifiers provides the broader security community with concrete data to prioritize patching and to assess exposure across their own Zammad deployments.

Interactive Mechanism

Διαδραστικός Μηχανισμός: Πώς λειτουργεί στην πραγματικότητα

Εξερευνήστε την υποκείμενη τεχνολογία πίσω από αυτήν την εξέλιξη διαδραστικά.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Διαδραστικός Έλεγχος Έννοιας+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

Τι να παρακολουθήσετε στη συνέχεια

Future developments include monitoring for additional AI‑driven intrusion techniques, the rollout of patches for the Zammad vulnerabilities, and possible attribution efforts to identify the threat actor behind the autonomous agent.

Watch for additional disclosures of AI‑driven attack techniques, particularly those that combine vulnerability exploitation with autonomous decision‑making.

Monitor Zammad’s patch releases and verify that the latest version addresses both CVEs, as the advisory notes a remaining privilege‑escalation issue in version 7 releases.

Observe any attribution efforts or threat‑intel reports that may link the to known threat actors, which could inform broader defensive postures.

Σχετικοί οδηγοί και κουίζ

Πράκτορες AIΗθική του AIΕπεξήγηση μοντέλων AIΤο μέλλον του AIΔοκιμάστε τι γνωρίζετε — δοκιμάστε ένα δωρεάν κουίζ AIΑναζητήστε έναν όρο AI στο γλωσσάρι μαςΑκολουθήστε το πρόγραμμα παρακολούθησης ρυθμίσεων AI
Βρήκατε αυτό χρήσιμο;