cd /news/ai-safety/case-update-divd-2026-00014-when-not… · home › topics › ai-safety › article
[ARTICLE · art-142662] src=csirt.divd.nl ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Case update: DIVD-2026-00014 - When, not if...

The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed that it was breached by hackers who gained access through AI agents exploiting two 0-day vulnerabilities in Zammad, tracked as CVE-2026-102489 and CVE-2026-102490. DIVD's Crisis Management Team said first malicious access occurred on 21 Sep 2026, the organization detected the activity on 22 Sep 2026 and blocked access to all systems in its datacenter, and an incident response team began a forensic investigation with Merlon Security the same day. DIVD opened case DIVD-2026-00015 for target and victim notification of the two known exploited vulnerabilities and is scanning for vulnerable Microtick appliances.

by read2 min views5 publishedSep 29, 2026

| Our reference | DIVD-2026-00014 | | Case lead | DIVD Crisis Management Team | | Author | Various |

| Researcher(s) |  | 
| CVE(s) |  | 
| Product | [nil] | 
| Versions | [nil] | 

| Status | Open | | Last modified | 30 Sep 2026 18:14 CEST |

Summary #

DIVD got hacked through AI agents and is currently investigating the breach. Incident investigation is ongoing.

We have identified that the hackers got in via two 0-day vulnerabilities in Zammad. We have assigned the CVE IDs CVE-2026-102489 and CVE-2026-102490 to these vulnerabilities and started case DIVD-2026-00015 to do target and victim notification for these two known exploited vulnerabilities.

We will update this page shortly with more information on the incident.

Timeline #

Date Description
21 Sep 2026 First access by malicious actor on DIVD systems
22 Sep 2026 DIVD becomes aware of malicious activity. Access to all systems in the datacenter is blocked
22 Sep 2026 Incident response team formed and forensic investigation started together with Merlon Security
29 Sep 2026 Publication of casefile
29 Sep 2026 Publication of overview of which data is compromised and which data is not.
gantt
	    title DIVD-2026-00014 - When, not if...
	    dateFormat  YYYY-MM-DD
    axisFormat  %e %b %Y
    section Case
    DIVD-2026-00014 - When, not if... (still open)           :2026-09-22, 2026-10-07
    section Events
	First access by malicious actor on DIVD systems :  milestone, 2026-09-21, 0d
			DIVD becomes aware of malicious activity. Access to all systems in the datacenter is blocked :  milestone, 2026-09-22, 0d
			Incident response team formed and forensic investigation started together with Merlon Security :  milestone, 2026-09-22, 0d
			Publication of casefile :  milestone, 2026-09-29, 0d
			Publication of overview of which data is compromised and which data is not. :  milestone, 2026-09-29, 0d

What we are doing #

DIVD is currently scanning for vulnerable Microtick appliances and notifying affected parties.

── more in #ai-safety 4 stories · sorted by recency
── more on @divd 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/case-update-divd-202…] indexed:0 read:2min 2026-09-29 · —