Skip to main content
Dutch Institute for Vulnerability Disclosure

Dutch Institute for Vulnerability Disclosure

Search complete. 19 mentions across 12 episodes found for "Dutch Institute for Vulnerability Disclosure".

Oct 8, 2026

Jeremy SnyderHOST
7:01
Um, so there's a lot of interesting stuff going on on this side, and I think we're gonna have to monitor and continue to monitor this space of, you know, agent sandbox escape, what's it doing, et cetera, et cetera, as we go over time.
Jeremy SnyderHOST
7:12
All right, on the, uh, theme of AI agents moving into networks, the Dutch Institute for Vulnerability Disclosure, or DIVD, uh, does now say that the breach of its network was the chaining of two zero-day vulnerabilities in the open source Zammad ticketing system, which they're using on that platform, and that it was loud and, quote, "loud and very, very messy," end quote, and it was driven by an AI agent that moved autonomously and decided its next steps through navigating the DIVD network on its own.
Jeremy SnyderHOST
7:42
And they are reporting this based on log data from their side, and so they've seen, uh, actually clear explanations of the decisions allowing them to reconstruct the incident, and some of those decisions are left in plain text, and so that's kind of interesting.
Jeremy SnyderHOST
7:55
It started with a hijack session, moved to m-remote code execution, uh, and then moved to root access in a matter of seconds.
Adrian CulleyHOST
12:15
According to the register, he was convicted in 2023 for hacking and extortion, and was on supervised release.
Adrian CulleyHOST
12:21
He was also working as a software engineer at an offensive security startup well known, and volunteering with the Dutch Institute for Vulnerability Disclosure.
Tova DvorinHOST
12:30
So allegedly, someone helping an extortion crew was also sitting inside the cybersecurity community, quite literally on the defender's side of the fence.
Adrian CulleyHOST
12:40
Allegedly, and he hasn't been convicted of anything connected to this case, but the structural point holds whatever a court decides.
speaker_0NARRATOR
0:08
An intruder gained full control of a helpdesk server within seconds after an AI agent chained two previously unknown Zomid weaknesses.
speaker_0NARRATOR
0:16
The September 21st attack hijacked a session, executed code as the Zamed service account, and then escalated to root at the Dutch Institute for Vulnerability Disclosure.
speaker_0NARRATOR
0:25
The intrusion was detected the next day, and access to systems in the data center was blocked.
speaker_0NARRATOR
0:31
Volunteer email addresses were confirmed stolen.
Claire AirdHOST
8:12
A successful exploit grants attackers admin level access to the device's API management component.
Claire AirdHOST
8:20
Hackers exploited two zero days in the Zammad help desk and issue tracking platform to breach Dutch cybersecurity nonprofit DIVD.
Claire AirdHOST
8:30
The vulnerabilities allow attackers to hijack sessions, elevate privileges, and run remote code on Zammad servers.
Claire AirdHOST
8:36
DIVD has reported the issues to the vendor, who's now working on patches.
Claire AirdHOST
8:42
DIVD disclosed the hack over the weekend and said it suspects the attacker used AI tooling due to the speed at which the attack took place.
Claire AirdHOST
8:52
And finally, internet infrastructure company Cloudflare is launching a certificate authority.
Claire AirdHOST
8:58
The new CA will provide free certificates with automated issuance and renewal like Let's Encrypt.
speaker_0HOST
0:05
It's a patch-heavy day, with active exploitation hitting enterprise network gear and an unusual breach at the very group that hunts software bugs for a living.
speaker_0HOST
0:14
The Dutch Institute for Vulnerability Disclosure, a non-profit of volunteer researchers, says it was breached through two previously unknown flaws in its Xamod helpdesk software.
speaker_0HOST
0:24
The group reports that an automated AI agent chained the two bugs to gain root access within seconds, steal data and start pivoting to other systems before it was stopped, a rare case of the bug hunters getting hunted.
speaker_0HOST
0:36
Several security firms confirmed that attackers have spent weeks exploiting two nil-day floors in Citrix Netscaler devices, with government and financial organisations among the targets.
Jerry BellHOST
0:27
If yours was reachable from the internet, treat it as an incident until the logs say otherwise.
Jerry BellHOST
0:32
Two, an AI agent broke into the Dutch Institute for Vulnerability Disclosure through its Zamed help desk.
Jerry BellHOST
0:40
It chained two flaws that weren't public yet.
Jerry BellHOST
0:42
The first one runs code on the server without a login and the second one takes that access to root.
speaker_0HOST
0:14
The organization that finds other people's security holes has been breached through two of them.
speaker_0HOST
0:20
The Dutch Institute for Vulnerability Disclosure, DIVD, said this week that attackers got into its network through two previously unknown flaws in Zammad, an open-source help desk system.
speaker_0HOST
0:34
And the way the intruder worked points to an agentic AI at the controls.
speaker_0HOST
0:39
For UK organizations, the lesson isn't the AI, it's how much a help desk server was trusted.
David ShipleyHOST
9:14
And he apparently admitted as much in a 2023 trial.
David ShipleyHOST
9:19
By day, he was a software engineer at the time at Amsterdam cybersecurity startup Hadrian and a volunteer at the Dutch Institute for Vulnerability Disclosure.
David ShipleyHOST
9:29
By night, he was Umbreon, extorting victims and posting their data on criminal forums.
David ShipleyHOST
9:35
He was convicted of data thefts and extortions that prosecutors said earned him between 1.5 and 2.7 million euros.
Jesse JohnsonHOST
42:19
Next attack.
Jesse JohnsonHOST
42:20
The Dutch Institute for Vulnerability Disclosure, or DIVD, suffered a major cyber attack.
Jesse JohnsonHOST
42:26
DIVD is a nonprofit organization that searches for known vulnerabilities in internet-exposed systems and notifies owners.
Jesse JohnsonHOST
42:35
The organization said the attack exploited a technical vulnerability in an undisclosed system, noting that the attack's speed and sloppy logic pattern indicated it originated from an AI agent.

Unknown podcast

Daily News, Sep, 30 - Citrix zero day

Sep 30 · 1 Mention

MayaHOST
1:11
classic bait-and-switch with a modern AI twist.
MayaHOST
1:14
And speaking of AI, the Dutch Institute for Vulnerability Disclosure, the DIVD, just got hit by an automated AI agent.
MayaHOST
1:22
They described the attack as loud and very, very messy.
MayaHOST
1:26
It really underscores that attackers are now using autonomous agents to scale their efforts.

2 more episodes mention Dutch Institute for Vulnerability Disclosure.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.