Technology newsroom
Cybersecurity Shockwave! DIVD Hacked via Zammad Zero-Day Vulnerabilities, Attackers Leveraged AI 🤖
The Dutch security institute DIVD was hacked via two Zero-Day vulnerabilities on the Zammad system, with attackers using AI tools to assist in the breach. This serves as a warning of increasingly sophisticated threats.
📌 Key Takeaways:
- The Dutch Institute for Vulnerability Disclosure (DIVD), a non-profit cybersecurity organization, was breached via two co-operating zero-day vulnerabilities on its Zammad system.
- Attackers utilized AI-driven tools to assist in finding vulnerabilities and escalating the attack, making the breach more complex and faster.
- Zammad, a popular open-source ticketing system, has released an emergency patch. All system administrators using Zammad should update urgently.
Major news in the cybersecurity industry: the Dutch Institute for Vulnerability Disclosure (DIVD), a Dutch vulnerability research organization, has revealed that its own network was breached! This incident is particularly shocking because DIVD is an organization tasked with finding and reporting vulnerabilities to others, yet it fell victim itself.
Investigations revealed that hackers gained access to the system by exploiting two previously unknown (zero-day) vulnerabilities on Zammad, an open-source helpdesk and ticketing system used by DIVD. The two vulnerabilities were exploited together to completely take over the system. One of the disclosed vulnerabilities is CVE-2024-6473.
🚨 What is noteworthy and concerning is that DIVD stated the attackers used AI-driven tools to scan for vulnerabilities and develop the attack process. This is a clear signal that future cyberattacks will become significantly more complex and harder to detect, as AI can operate autonomously and faster than humans.
However, DIVD detected the intrusion and responded rapidly, collaborating with the Zammad team to develop and release an emergency patch. The institute has recommended that all system administrators using Zammad immediately update their software to the latest version to close the vulnerability and prevent potential damage.
💬 What open-source systems does your organization use, and how swift and consistent is your security patch update policy?