A Dutch cybersecurity nonprofit was compromised by an agentic AI attack that weaponized two previously unknown vulnerabilities in its helpdesk software, according to a disclosure published September 30 by the Dutch Institute for Vulnerability Disclosure (DIVD). The organization, which is staffed by volunteers and works to ethically report security flaws it discovers in systems, detected unusual activity on September 24 and subsequently determined that attackers had chained together two zero-day bugs in Zammad to gain root access. The incident marks one of the first documented cases where an AI agent autonomously exploited multiple vulnerabilities in rapid succession to breach a security-focused organization.

The attackers exploited remote code execution vulnerability CVE-2026-102489 and privilege escalation flaw CVE-2026-102490, both in the Zammad helpdesk platform. When used in combination, the two bugs carry a CVSS severity score of 9.4. The exploits allowed the intruders to hijack active sessions, execute code remotely, and escalate their access from a standard Zammad user to root-level privileges within seconds due to the autonomous nature of the attack. From that elevated position, they accessed additional services and extracted data from DIVD's systems. Volunteer information including DIVD email addresses and potentially contact details was compromised, raising the risk that malicious actors could impersonate staff members.

Investigation logs revealed telltale signs that an AI agent, rather than a human operator, conducted the intrusion. The organization said the attacker's scripts contained notes where the agent justified its own actions, explaining why what it was doing was acceptable and not phishing—something a human attacker wouldn't bother with. DIVD urged all users running any version of Zammad to upgrade to version 7 immediately or take their systems offline as soon as possible. Thanks to proper network segmentation and swift action by its IT and incident response team after detection, DIVD was able to prevent the attackers from penetrating deeper into its systems and network, though some damage had already occurred by the time containment measures took effect.

Tim Burke, CEO of managed IT service provider Quest Technology Management, warned that AI-driven attacks are compressing detection and response timelines, making continuous monitoring and visibility more critical for companies without a dedicated security operations center. He emphasized that AI doesn't replace the fundamentals—it makes patching, monitoring, access controls, air-gapped and immutable data storage, segmentation, and incident response even more important. Network segmentation proved key to limiting damage in this case, preventing access from spreading across the broader environment. Burke said the first hour should focus on containment: isolating affected systems, restricting compromised accounts or credentials, blocking suspicious connections, and stopping further movement while the team determines what happened. Organizations should know in advance who has the authority to take those containment actions, he added, because delays matter more when attack activity happens at machine speed. The DIVD incident underscores a shift in the threat landscape where autonomous agents can discover, chain, and exploit vulnerabilities faster than traditional human-led operations, forcing defenders to rethink response protocols built for slower adversaries. Security teams may soon need to assume that the window between initial compromise and lateral movement has collapsed from hours to seconds, fundamentally altering the calculus of detection versus prevention.