The Dutch Institute for Vulnerability Disclosure (DIVD), a coordinated vulnerability disclosure organisation, announced an intrusion into its own systems on September 24, 2026. It blocked access to its infrastructure and began an investigation with an external response team. Its DIVD-2026-00014 case remains open.
DIVD dates the first malicious access to September 21 and detection to the following day. It later identified two zero-day flaws in its Zammad support software as the entry point. These dates and conclusions reflect the organisation’s published investigation and may be supplemented by later updates.
Two Zammad flaws combined
DIVD links the intrusion to CVE-2026-102489 and CVE-2026-102490. Its case file says the flaws were combined to hijack a session, execute code remotely and move from a Zammad user account to root privileges. DIVD describes this progression as taking place within seconds.
The vulnerabilities also prompted a separate DIVD case, DIVD-2026-00015, to notify potentially exposed organisations. Administrators should check Zammad’s advisory for affected versions and applicable fixes, then determine whether their instance is exposed to the internet.
What data left DIVD
On October 1, DIVD confirmed that volunteer data had left its systems, including email addresses and possibly other contact details. It has not yet established exactly whose data or which details were affected. The organisation warns that this information could make it easier to impersonate a volunteer.
DIVD also says the intrusion enabled access to other services and data exfiltration, but it has not published a final, complete inventory. It reports other signs of compromise that remain under review. Network segmentation and its teams’ response are said to have prevented deeper movement through the network.
What DIVD says about the AI agent
DIVD assesses that the modus operandi indicates an attack carried out with an artificial intelligence agent. It published redacted log screenshots that, in its view, show automated scripts justifying their own actions. This is DIVD’s assessment; it is not independent attribution of the operator or the tool.
The organisation says its forensic investigation is ongoing and it cannot yet fully describe the incident’s scope. The case file therefore does not establish that all accessible data was retrieved or publicly identify the person behind the attack.
Steps for affected teams
Zammad operators should check the vendor advisories, apply official fixes or mitigations, and review authentication logs, privileged accounts and activity launched by the application. If the instance could reach mailboxes, databases or integration tokens, assess those paths and rotate secrets after containment.
DIVD volunteers and people communicating with the organisation should verify unexpected messages through a known address, especially if they request a code, document or urgent action. DIVD has provided an official contact address for checking suspicious messages.
The Soclyde connection
A support instance may hold or reach credentials used by a team. Soclyde does not protect Zammad and cannot remediate this intrusion. Its encrypted local-first vault helps users organise passwords and access details on their devices; application permissions, network segmentation and incident response must be handled in the affected environment.
Takeaway
DIVD links the intrusion to two Zammad flaws and confirms volunteer email addresses left its systems, while the full scope remains under investigation. The AI-agent hypothesis is DIVD’s assessment, which it says is supported by redacted log material it published.
If you use Zammad, follow the vendor advisory and look for unusual activity. To reduce password sprawl across a team, see our guide to local-first password managers.



