The Dutch Institute for Vulnerability Disclosure (DIVD), a non-profit that helps get security flaws reported and fixed, was itself breached on September 21. According to Help Net Security, the attack was driven by an agentic AI system and exploited two zero-day vulnerabilities in Zammad. The AI agent Zammad zero-day DIVD breach is a useful case study for anyone who relies on organizations that handle sensitive security information.

The public details are still limited, so this post sticks to what has been confirmed and avoids guessing at the rest.

What Happened at DIVD on September 21

DIVD is known for finding exposed systems and notifying their owners so problems can be fixed. On September 21, its own network became the target. The reported attack was agentic, meaning an AI system carried out steps with a degree of autonomy rather than a human operator typing each command.

The entry point was Zammad, an open-source ticketing and helpdesk platform. Organizations use tools like it to manage support requests and internal communication. Two previously unknown flaws, known as zero-days because no patch existed when they were used, were exploited in the attack.

The irony is hard to miss. An organization whose job is coordinating vulnerability disclosure was breached through vulnerabilities nobody had disclosed yet. That does not point to carelessness. It shows that any organization running internet-facing software can be hit by a flaw its vendor does not yet know about.

How the AI Agent Zammad Zero-Day Chain Worked

The key word in the reporting is "chain." Instead of relying on one flaw, the attacker combined two Zammad zero-days. Chaining is a common technique: one weakness gives a foothold or partial access, and a second turns that into something more serious. Neither flaw needs to be catastrophic alone for the combination to cause real damage.

What stands out here is who did the chaining. Security researchers have long expected AI systems to help find and combine bugs, and this incident is described as an agentic AI attack using two zero-days against a real target. For the technical specifics of the vulnerabilities themselves, our earlier report on the DIVD Zammad zero-day chain behind the AI-driven breach goes deeper.

Because the flaws sit in server software, the attack targeted the application itself. It did not rely on stealing a password from a user or tricking an employee into clicking a link. That distinction matters when we get to what individuals can and cannot do about it.

What AI-Driven Attacks Change for Defenders

Automation changes the pace more than the nature of the threat. A few practical shifts are worth noting:

  • Speed. An automated agent can test, adapt and combine steps faster than a human working alone, which shrinks the time defenders have to notice and respond.
  • Scale. Software that can probe one target can be pointed at many. Popular open-source tools with public-facing interfaces are natural candidates.
  • Patch windows. With a zero-day there is no patch to apply in advance. What matters is how quickly a vendor can ship a fix and how quickly operators can install it once it exists.

None of this means defenders are helpless. Network segmentation, limiting what a helpdesk server can reach, monitoring for unusual behavior and keeping systems on supported versions all reduce the damage when something unexpected gets through. Prompt disclosure by the affected organization, as DIVD has done, also helps other Zammad operators check their own setups.

What This Means For You

Most readers do not run a helpdesk server, but many use services that do. Support portals, ticketing systems and internal request tools often hold names, email addresses and the text of conversations people assumed were private. If a service you use runs self-hosted helpdesk software, a flaw like this could expose that information regardless of how careful you are.

This is also where a VPN has limits. A VPN encrypts traffic between your device and the VPN server and hides your IP address from the sites you visit. That is valuable on public Wi-Fi or for reducing tracking. It does nothing to patch a vulnerable server run by someone else, and it cannot stop an attacker from exploiting a flaw in an application that is reachable from the internet. Server-side flaws like these have to be fixed by the people operating the server.

That does not make privacy tools pointless. It means they address a different problem. Treat them as one layer, not a shield against every kind of breach.

Practical Takeaways

  • If you run Zammad or similar helpdesk software, check your version, watch the vendor's security advisories and apply updates as soon as fixes are available. Review what the server can reach on your internal network.
  • If you use services that collect support tickets, avoid putting sensitive details such as passwords, ID numbers or financial data into a ticket or support email.
  • Use unique passwords and two-factor authentication so that exposure of one account does not cascade to others.
  • Watch for notices from companies you deal with, and be cautious of unexpected messages that reference a past support request.
  • Keep realistic expectations of your VPN. It protects your connection, not the servers you connect to.

The AI agent Zammad zero-day DIVD breach is a reminder that even the groups coordinating vulnerability disclosure can be caught by flaws no one has reported yet. For the technical breakdown, read our report on the Zammad zero-day chain that enabled the DIVD breach, then take a few minutes to find out whether the services you depend on, or your own organization, run self-hosted helpdesk software that needs patching.