Critical

DIVD says Zammad zero-days enabled AI-driven network breach

BleepingComputer
Actively Exploited

Overview

The Dutch Institute for Vulnerability Disclosure (DIVD) reported that its network was breached due to the exploitation of two zero-day vulnerabilities in the Zammad ticketing system, which is open-source software used by various organizations. This breach raises concerns about the security of open-source applications, as attackers were able to leverage these vulnerabilities to gain unauthorized access. The incident emphasizes the need for users of Zammad and similar systems to ensure they are up to date with security patches and to monitor their networks for any suspicious activity. As the details of the breach unfold, it serves as a reminder for organizations to prioritize vulnerability management and implement robust security measures to protect their data and infrastructure.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Zammad ticketing system
  • Action Required: Users should update to the latest version of Zammad and review their security configurations.
  • Timeline: Newly disclosed

Original Article Summary

The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]

Impact

Zammad ticketing system

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Users should update to the latest version of Zammad and review their security configurations. Regular monitoring for unusual activity is also recommended.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Zero-day, Vulnerability.

Related Coverage

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

The Hacker News

Researchers have identified a significant security breach involving WordPress sites, where attackers have implemented a backdoor known as SC. This malware is designed to maintain persistent access to infected sites by using various methods for recovery, even after attempts to remove it. The backdoor can reinfect the site through files, database entries, or shared memory, making it particularly challenging for site administrators to eliminate. This incident raises serious concerns for website owners who rely on WordPress, as the backdoor can compromise sensitive information and lead to further attacks. Users and companies need to be vigilant and take proactive measures to secure their sites against such persistent threats.

Oct 1, 2026

Police dismantle KillSec ransomware gang allegedly led by 16-year-old

BleepingComputer

Law enforcement agencies from multiple countries have successfully executed 'Operation KillSwitch', targeting the KillSec ransomware gang. During the operation, authorities seized the gang's data leak site and servers, leading to the arrest of three individuals, including a 16-year-old who is believed to be the group's main administrator. This operation is significant as it disrupts a notable ransomware group that has been involved in various cyberattacks, affecting numerous victims. The dismantling of this gang could help reduce the prevalence of ransomware attacks, which have been a growing concern for businesses and individuals alike. The involvement of a minor in this criminal activity raises questions about the recruitment and involvement of young individuals in cybercrime.

Oct 1, 2026

Kiteworks patches max severity code injection vulnerability

BleepingComputer

Kiteworks, a company specializing in secure file-sharing software, has issued updates to fix 126 vulnerabilities in its products. Among these is a high-severity code injection flaw in their Email Protection Gateway (EPG) security solution, which could allow attackers to execute arbitrary code on affected systems. This vulnerability poses a significant risk as it could lead to unauthorized access and data breaches if exploited. Users of Kiteworks' EPG are particularly urged to apply these patches promptly to safeguard their systems. The rapid response to these vulnerabilities emphasizes the importance of regular software updates in maintaining cybersecurity.

Oct 1, 2026

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

The Hacker News

OpenAI recently revealed that it has disrupted a campaign aimed at extracting sensitive reasoning from its AI models. This operation, linked to a group connected with Moonshot AI, a Beijing-based company, has been ongoing since early July. The campaign involved coordinated efforts to illicitly access proprietary information from OpenAI's systems. This incident raises concerns about the security of AI technologies and the lengths to which some entities may go to exploit them. As AI becomes more integrated into various sectors, safeguarding these systems from unauthorized access is crucial for maintaining trust and innovation in the field.

Oct 1, 2026

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

SecurityWeek

Cisco has released a patch for a serious zero-day vulnerability found in its Catalyst SD-WAN appliances. This flaw could allow remote attackers to gain administrative access to affected devices without needing any authentication. The vulnerability poses a significant risk, as it can be exploited to take control of network infrastructure. Users of Cisco's SD-WAN products should prioritize applying the patch to safeguard their systems. The disclosure of this vulnerability emphasizes the need for organizations to remain vigilant about software updates and security practices.

Oct 1, 2026

Metamask discloses security incident affecting its infrastructure

BleepingComputer

MetaMask, a popular cryptocurrency wallet, has reported an ongoing security incident that affects parts of its infrastructure. While details are still emerging, the company has acknowledged that some users may be impacted by this incident. It's crucial for users to remain vigilant and monitor their accounts for any unusual activity. The exact nature of the security issue has not been fully disclosed, but MetaMask is actively working to address the situation. This incident serves as a reminder of the vulnerabilities that can exist in digital wallet services, highlighting the need for strong security practices among users.

Oct 1, 2026