{"slug": "case-update-divd-2026-00014-when-not-if", "title": "Case update: DIVD-2026-00014 - When, not if...", "summary": "The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed that it was breached by hackers who gained access through AI agents exploiting two 0-day vulnerabilities in Zammad, tracked as CVE-2026-102489 and CVE-2026-102490. DIVD's Crisis Management Team said first malicious access occurred on 21 Sep 2026, the organization detected the activity on 22 Sep 2026 and blocked access to all systems in its datacenter, and an incident response team began a forensic investigation with Merlon Security the same day. DIVD opened case DIVD-2026-00015 for target and victim notification of the two known exploited vulnerabilities and is scanning for vulnerable Microtick appliances.", "body_md": "# DIVD-2026-00014 - When, not if...\n\n| Our reference | [DIVD-2026-00014](https://csirt.divd.nl/cases/DIVD-2026-00014) | \n| Case lead | DIVD Crisis Management Team | \n| Author | Various | \n| Researcher(s) |  | \n| CVE(s) |  | \n| Product | [nil] | \n| Versions | [nil] | \n| Status | Open | \n| Last modified | 30 Sep 2026 18:14 CEST | \n\n## Summary\n\nDIVD got hacked through AI agents and is currently investigating the breach. Incident investigation is ongoing.\n\nWe have identified that the hackers got in via two 0-day vulnerabilities in Zammad. We have assigned the CVE IDs [CVE-2026-102489](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-102489) and [CVE-2026-102490](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-102490) to these vulnerabilities and started case [DIVD-2026-00015](https://csirt.divd.nl/cases/DIVD-2026-00015) to do target and victim notification for these two known exploited vulnerabilities.\n\nWe will update this page shortly with more information on the incident.\n\n## Timeline\n\n| Date | Description | \n|---|---|\n| 21 Sep 2026 | First access by malicious actor on DIVD systems | \n| 22 Sep 2026 | DIVD becomes aware of malicious activity. Access to all systems in the datacenter is blocked | \n| 22 Sep 2026 | Incident response team formed and forensic investigation started together with Merlon Security | \n| 29 Sep 2026 | Publication of casefile | \n| 29 Sep 2026 | Publication of overview of which data is compromised and which data is not. | \n\n\tgantt\n\t    title DIVD-2026-00014 - When, not if...\n\t    dateFormat  YYYY-MM-DD\n\t    axisFormat  %e %b %Y\n\t    section Case\n\t    DIVD-2026-00014 - When, not if... (still open)           :2026-09-22, 2026-10-07\n\t    section Events\n\t\tFirst access by malicious actor on DIVD systems :  milestone, 2026-09-21, 0d\n\t\t\t\tDIVD becomes aware of malicious activity. Access to all systems in the datacenter is blocked :  milestone, 2026-09-22, 0d\n\t\t\t\tIncident response team formed and forensic investigation started together with Merlon Security :  milestone, 2026-09-22, 0d\n\t\t\t\tPublication of casefile :  milestone, 2026-09-29, 0d\n\t\t\t\tPublication of overview of which data is compromised and which data is not. :  milestone, 2026-09-29, 0d\n\t\t\t\t\n\n## What we are doing\n\nDIVD is currently scanning for vulnerable Microtick appliances and notifying affected parties.", "url": "https://wpnews.pro/news/case-update-divd-2026-00014-when-not-if", "canonical_source": "https://csirt.divd.nl/cases/DIVD-2026-00014/", "published_at": "2026-09-29 00:00:00+00:00", "updated_at": "2026-09-30 16:50:22.209180+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "artificial-intelligence"], "entities": ["DIVD", "Zammad", "Merlon Security", "CVE-2026-102489", "CVE-2026-102490", "DIVD-2026-00014", "DIVD-2026-00015", "Microtick"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/case-update-divd-2026-00014-when-not-if", "markdown": "https://wpnews.pro/news/case-update-divd-2026-00014-when-not-if.md", "text": "https://wpnews.pro/news/case-update-divd-2026-00014-when-not-if.txt", "jsonld": "https://wpnews.pro/news/case-update-divd-2026-00014-when-not-if.jsonld"}}