Security Researchers Hacked via Zero-Day Flaws in Support Software, Volunteer Data Stolen
The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit that hunts and reports security flaws, has itself been hacked. Attackers exploited two previously unknown vulnerabilities in Zammad, an open-source helpdesk and ticketing platform DIVD used, to hijack active sessions, run malicious code, and escalate access to full root control, all within seconds of the initial breach.
The attack took place on 21 September and was discovered the following day, prompting DIVD to cut off access to its data center systems and bring in an incident response team. The organisation confirmed that data belonging to its volunteer researchers was stolen, including DIVD email addresses and possibly other contact details. DIVD warned that this raises the risk of social engineering, since attackers could now impersonate its volunteers more convincingly, and it urged anyone receiving a suspicious contact request claiming to be from DIVD to verify it directly through its communications address.
The two flaws, tracked as CVE-2026-102489 and CVE-2026-102490, both scored 9.4 out of 10 in severity when chained together. The first allows unauthenticated attackers to remotely execute code and steal user sessions, affecting Zammad versions 6.3.0 through 6.5.4. The second allows a local user to gain root privileges and affects all Zammad versions. DIVD has advised all Zammad users to upgrade to version 7 or take affected systems offline immediately.