Skip to main content
Zammad

Zammad

Computer programWikipedia

Search complete. 10 mentions across 4 episodes found for "Zammad".

Oct 8, 2026

Michael HouschHOST
6:41
Patch management, vulnerability scanning, and continuous monitoring are essential components of an effective defense.
Michael HouschHOST
6:48
A similar story is unfolding with Zammad, an open-source help desk platform.
Michael HouschHOST
6:53
A proof-of-concept exploit has been released for a critical vulnerability that enables session hijacking and remote code execution.
Michael HouschHOST
7:01
For organizations relying on Zammad for customer support, this poses a high risk, not just to the integrity of the help desk system, but to the broader environment if attackers can use compromised sessions to pivot further into the network.
Michael HouschHOST
7:16
Prompt patching and a review of session management practices are strongly advised.
Michael HouschHOST
7:21
But it's not just software vulnerabilities that are being exploited.
Jeremy SnyderHOST
7:01
Um, so there's a lot of interesting stuff going on on this side, and I think we're gonna have to monitor and continue to monitor this space of, you know, agent sandbox escape, what's it doing, et cetera, et cetera, as we go over time.
Jeremy SnyderHOST
7:12
All right, on the, uh, theme of AI agents moving into networks, the Dutch Institute for Vulnerability Disclosure, or DIVD, uh, does now say that the breach of its network was the chaining of two zero-day vulnerabilities in the open source Zammad ticketing system, which they're using on that platform, and that it was loud and, quote, "loud and very, very messy," end quote, and it was driven by an AI agent that moved autonomously and decided its next steps through navigating the DIVD network on its own.
Jeremy SnyderHOST
7:42
And they are reporting this based on log data from their side, and so they've seen, uh, actually clear explanations of the decisions allowing them to reconstruct the incident, and some of those decisions are left in plain text, and so that's kind of interesting.
Jeremy SnyderHOST
7:55
It started with a hijack session, moved to m-remote code execution, uh, and then moved to root access in a matter of seconds.
Claire AirdHOST
8:12
A successful exploit grants attackers admin level access to the device's API management component.
Claire AirdHOST
8:20
Hackers exploited two zero days in the Zammad help desk and issue tracking platform to breach Dutch cybersecurity nonprofit DIVD.
Claire AirdHOST
8:30
The vulnerabilities allow attackers to hijack sessions, elevate privileges, and run remote code on Zammad servers.
Claire AirdHOST
8:36
DIVD has reported the issues to the vendor, who's now working on patches.
Claire AirdHOST
8:42
DIVD disclosed the hack over the weekend and said it suspects the attacker used AI tooling due to the speed at which the attack took place.
speaker_0HOST
0:00
[upbeat music] This is Decrypted, Thursday the first of October.
speaker_0HOST
0:07
A Zammad zero-day chain let an AI agent breach the people who find zero-days.
speaker_0HOST
0:14
The organization that finds other people's security holes has been breached through two of them.
speaker_0HOST
0:20
The Dutch Institute for Vulnerability Disclosure, DIVD, said this week that attackers got into its network through two previously unknown flaws in Zammad, an open-source help desk system.
speaker_0HOST
0:34
And the way the intruder worked points to an agentic AI at the controls.
speaker_0HOST
0:39
For UK organizations, the lesson isn't the AI, it's how much a help desk server was trusted.
speaker_0HOST
0:57
DIVD spotted it the next day.
speaker_0HOST
1:00
It disconnected its data center systems and brought in Merlin Security for forensics.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.