MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-30 · via BleepingComputer

Autonomous AI Agent Exploits Ticketing Software Vulnerabilities in Security Nonprofit Attack

Image via BleepingComputer
Image via BleepingComputer

The Dutch Institute for Vulnerability Disclosure disclosed that attackers leveraged two zero-day flaws in the Zammad ticketing system to breach its network using an autonomous AI agent. The vulnerabilities enabled session hijacking, remote code execution, and privilege escalation to root level, with the AI-driven attack completing data exfiltration in seconds. Zammad users are advised to upgrade to version 7 or take systems offline immediately.

Expanded Detail

The attack represents a significant shift in breach methodology. Rather than following a predetermined script, the autonomous AI system made real-time decisions about which systems to target and how to exploit them, completing the entire compromise—from initial access through data theft—in seconds. This speed and autonomy made traditional security monitoring difficult, though the attacker's detailed logging of its reasoning actually aided forensic investigation.

Zammad serves a diverse customer base spanning retail, nonprofit, and technology sectors. The vulnerability chain is particularly concerning because it requires no user interaction; attackers can move from unauthenticated access to complete system control through automated exploitation. The fact that network segmentation prevented lateral movement underscores how infrastructure design can limit damage even when perimeter defenses fail.

Context

This incident may signal growing risks for organizations relying on open-source software, particularly when deployed without adequate network isolation. The thousands of Zammad users across critical sectors could face data exposure if they delay patching. More broadly, autonomous AI-driven attacks could force security teams to rethink response timelines—traditional incident detection windows measured in minutes may prove inadequate against systems operating at machine speed, potentially shifting investments toward architectural resilience rather than reactive monitoring.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Critical Zimbra Vulnerability Allows Unauthorized Remote Code Execution and Data Theft · Cybersecurity
Federal Cybersecurity Agency Alerts to Critical Unauthenticated Vulnerability in Popular Router Software · Cybersecurity
Six Critical Browser Attack Methods Dominating the 2026 Threat Landscape · Cybersecurity
AI Training Tool Unsloth Exposed to Arbitrary Code Execution via Model Selection · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “DIVD says Zammad zero-days enabled AI-driven network breach.” Browse more stories.