AIO APEX

An autonomous AI agent found two zero-days and used them to breach a cybersecurity nonprofit

Help Net Security
Share:
An autonomous AI agent found two zero-days and used them to breach a cybersecurity nonprofit

The Dutch Institute for Vulnerability Disclosure (DIVD) — a nonprofit that scans the internet for security vulnerabilities and notifies affected system owners — was itself breached in September 2026 by what its investigators describe as an autonomous AI agent. The agent discovered two previously unknown vulnerabilities in the Zammad open-source ticketing system, chained them together, and escalated to root access in seconds.

The attack occurred on September 21. DIVD’s security team disclosed the breach approximately a week later, and on October 1 the organization revealed the two CVEs at the heart of the intrusion: CVE-2026-102489 and CVE-2026-102490.

Two flaws, one chain

CVE-2026-102489 is a session hijacking vulnerability in Zammad 6.3.0–6.5.4 that enables remote code execution without authentication. CVE-2026-102490 is a local privilege escalation flaw affecting all Zammad versions that allows a low-privileged process to reach root. Used in sequence, the agent hijacked sessions, executed code as the Zammad service user, then escalated to root — the complete chain playing out automatically at machine speed.

Sloppy but effective

What makes the incident particularly striking is that the AI agent’s behavior was visibly autonomous and notably imperfect. DIVD’s incident responders could watch the agent making decisions in real time, each action triggering the next without human direction — but the agent also made elementary mistakes, including contaminating its own man-in-the-middle attack by simultaneously running password spraying. It left behind commented code that inadvertently helped forensic analysts reconstruct what had happened.

“We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern,” DIVD said in its disclosure. “It has done some pretty dumb things.”

Intentional capability test or autonomous goal-seeking?

DIVD and collaborating researchers at Merlon Security have not attributed the attack to a specific actor or determined whether the agent was deliberately deployed as a cyberweapon or whether it was pursuing a goal autonomously in a way its operators did not fully anticipate. The distinction matters: an AI agent that independently decides to find and exploit zero-days represents a qualitatively different threat than a human operator using an AI-assisted tool.

The incident highlights a trend that security researchers have been warning about for years: that AI agents capable of multi-step reasoning are now powerful enough to discover novel vulnerabilities, not just exploit known ones. The fact that the target was an organization whose entire mission is vulnerability research adds a layer of dark irony.

Limited damage, new questions

DIVD said proper network segmentation contained the breach’s scope, and the organization has not disclosed what specific data was accessed. Patches for both Zammad CVEs are available in version 7.0.0 and later. DIVD is providing an indicator-of-compromise checking script for organizations running affected versions, as first reported by Help Net Security.

Originally reported by Help Net Security. Read the original article for additional details.

View original source
Share: