Dutch Institute for Vulnerability Disclosure
19
MENTIONS
12
EPISODES
11
PODCASTS
Search complete. 19 mentions across 12 episodes found for "Dutch Institute for Vulnerability Disclosure".
Oct 8, 2026
This Week in AI Security - 8th October 2026
J
7:01Jeremy SnyderHOST
Um, so there's a lot of interesting stuff going on on this side, and I think we're gonna have to monitor and continue to monitor this space of, you know, agent sandbox escape, what's it doing, et cetera, et cetera, as we go over time.
J
7:12Jeremy SnyderHOST
All right, on the, uh, theme of AI agents moving into networks, the Dutch Institute for Vulnerability Disclosure, or DIVD, uh, does now say that the breach of its network was the chaining of two zero-day vulnerabilities in the open source Zammad ticketing system, which they're using on that platform, and that it was loud and, quote, "loud and very, very messy," end quote, and it was driven by an AI agent that moved autonomously and decided its next steps through navigating the DIVD network on its own.
J
7:42Jeremy SnyderHOST
And they are reporting this based on log data from their side, and so they've seen, uh, actually clear explanations of the decisions allowing them to reconstruct the incident, and some of those decisions are left in plain text, and so that's kind of interesting.
J
7:55Jeremy SnyderHOST
It started with a hijack session, moved to m-remote code execution, uh, and then moved to root access in a matter of seconds.
Ep. 84 - ShinyHunters Leaked 5,000 Agents' Home Addresses Over One FBI Advisory
A
12:15Adrian CulleyHOST
According to the register, he was convicted in 2023 for hacking and extortion, and was on supervised release.
A
12:21Adrian CulleyHOST
He was also working as a software engineer at an offensive security startup well known, and volunteering with the Dutch Institute for Vulnerability Disclosure.
T
12:30Tova DvorinHOST
So allegedly, someone helping an extortion crew was also sitting inside the cybersecurity community, quite literally on the defender's side of the fence.
A
12:40Adrian CulleyHOST
Allegedly, and he hasn't been convicted of anything connected to this case, but the structural point holds whatever a court decides.
AI-led helpdesk breach reaches root access within seconds
S
0:08speaker_0NARRATOR
An intruder gained full control of a helpdesk server within seconds after an AI agent chained two previously unknown Zomid weaknesses.
S
0:16speaker_0NARRATOR
The September 21st attack hijacked a session, executed code as the Zamed service account, and then escalated to root at the Dutch Institute for Vulnerability Disclosure.
S
0:25speaker_0NARRATOR
The intrusion was detected the next day, and access to systems in the data center was blocked.
S
0:31speaker_0NARRATOR
Volunteer email addresses were confirmed stolen.
Authorities dismantle KillSec group
C
8:12Claire AirdHOST
A successful exploit grants attackers admin level access to the device's API management component.
C
8:20Claire AirdHOST
Hackers exploited two zero days in the Zammad help desk and issue tracking platform to breach Dutch cybersecurity nonprofit DIVD.
C
8:30Claire AirdHOST
The vulnerabilities allow attackers to hijack sessions, elevate privileges, and run remote code on Zammad servers.
C
8:36Claire AirdHOST
DIVD has reported the issues to the vendor, who's now working on patches.
C
8:42Claire AirdHOST
DIVD disclosed the hack over the weekend and said it suspects the attacker used AI tooling due to the speed at which the attack took place.
C
8:52Claire AirdHOST
And finally, internet infrastructure company Cloudflare is launching a certificate authority.
C
8:58Claire AirdHOST
The new CA will provide free certificates with automated issuance and renewal like Let's Encrypt.
Cyber Daily News for October 1st, 2026
S
0:05speaker_0HOST
It's a patch-heavy day, with active exploitation hitting enterprise network gear and an unusual breach at the very group that hunts software bugs for a living.
S
0:14speaker_0HOST
The Dutch Institute for Vulnerability Disclosure, a non-profit of volunteer researchers, says it was breached through two previously unknown flaws in its Xamod helpdesk software.
S
0:24speaker_0HOST
The group reports that an automated AI agent chained the two bugs to gain root access within seconds, steal data and start pivoting to other systems before it was stopped, a rare case of the bug hunters getting hunted.
S
0:36speaker_0HOST
Several security firms confirmed that attackers have spent weeks exploiting two nil-day floors in Citrix Netscaler devices, with government and financial organisations among the targets.
Cyber Security News for October 1 2026 - Daily DefSec Brief
J
0:27Jerry BellHOST
If yours was reachable from the internet, treat it as an incident until the logs say otherwise.
J
0:32Jerry BellHOST
Two, an AI agent broke into the Dutch Institute for Vulnerability Disclosure through its Zamed help desk.
J
0:40Jerry BellHOST
It chained two flaws that weren't public yet.
J
0:42Jerry BellHOST
The first one runs code on the server without a login and the second one takes that access to root.
A Zammad zero-day chain let an AI agent breach the people who find zero-days
S
0:14speaker_0HOST
The organization that finds other people's security holes has been breached through two of them.
S
0:20speaker_0HOST
The Dutch Institute for Vulnerability Disclosure, DIVD, said this week that attackers got into its network through two previously unknown flaws in Zammad, an open-source help desk system.
S
0:34speaker_0HOST
And the way the intruder worked points to an agentic AI at the controls.
S
0:39speaker_0HOST
For UK organizations, the lesson isn't the AI, it's how much a help desk server was trusted.
ShinyHunters Leader Busted
D
9:14David ShipleyHOST
And he apparently admitted as much in a 2023 trial.
D
9:19David ShipleyHOST
By day, he was a software engineer at the time at Amsterdam cybersecurity startup Hadrian and a volunteer at the Dutch Institute for Vulnerability Disclosure.
D
9:29David ShipleyHOST
By night, he was Umbreon, extorting victims and posting their data on criminal forums.
D
9:35David ShipleyHOST
He was convicted of data thefts and extortions that prosecutors said earned him between 1.5 and 2.7 million euros.
🔴 Sep 30's Top Cyber News NOW! - Ep 1255
J
42:19Jesse JohnsonHOST
Next attack.
J
42:20Jesse JohnsonHOST
The Dutch Institute for Vulnerability Disclosure, or DIVD, suffered a major cyber attack.
J
42:26Jesse JohnsonHOST
DIVD is a nonprofit organization that searches for known vulnerabilities in internet-exposed systems and notifies owners.
J
42:35Jesse JohnsonHOST
The organization said the attack exploited a technical vulnerability in an undisclosed system, noting that the attack's speed and sloppy logic pattern indicated it originated from an AI agent.
P
Unknown podcast
Daily News, Sep, 30 - Citrix zero day
Sep 30 · 1 Mention
M
1:11MayaHOST
classic bait-and-switch with a modern AI twist.
M
1:14MayaHOST
And speaking of AI, the Dutch Institute for Vulnerability Disclosure, the DIVD, just got hit by an automated AI agent.
M
1:22MayaHOST
They described the attack as loud and very, very messy.
M
1:26MayaHOST
It really underscores that attackers are now using autonomous agents to scale their efforts.
2 more episodes mention Dutch Institute for Vulnerability Disclosure.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.