Security News

Security Researchers Hacked via Zero-Day Flaws in Support Software, Volunteer Data Stolen

The Register · 2 Oct 2026
Key Takeaway If your business uses Zammad or similar support ticketing software, patch to the latest version immediately and watch for suspicious contact attempts impersonating trusted partners.

The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit that hunts and reports security flaws, has itself been hacked. Attackers exploited two previously unknown vulnerabilities in Zammad, an open-source helpdesk and ticketing platform DIVD used, to hijack active sessions, run malicious code, and escalate access to full root control, all within seconds of the initial breach.

The attack took place on 21 September and was discovered the following day, prompting DIVD to cut off access to its data center systems and bring in an incident response team. The organisation confirmed that data belonging to its volunteer researchers was stolen, including DIVD email addresses and possibly other contact details. DIVD warned that this raises the risk of social engineering, since attackers could now impersonate its volunteers more convincingly, and it urged anyone receiving a suspicious contact request claiming to be from DIVD to verify it directly through its communications address.

The two flaws, tracked as CVE-2026-102489 and CVE-2026-102490, both scored 9.4 out of 10 in severity when chained together. The first allows unauthenticated attackers to remotely execute code and steal user sessions, affecting Zammad versions 6.3.0 through 6.5.4. The second allows a local user to gain root privileges and affects all Zammad versions. DIVD has advised all Zammad users to upgrade to version 7 or take affected systems offline immediately.

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.