What is confirmed
DIVD says attackers first accessed its systems on 21 September and identifies two Zammad zero-days, CVE-2026-102489 and CVE-2026-102490. Its investigation remained open in the case file updated 30 September at 18:14 CEST (16:14 UTC). DIVD describes AI-agent use; that attribution is its assessment, not independently established here. DIVD incident case.
Patch guidance needs precision
DIVD’s companion case advises upgrading to Zammad 7 or taking the service offline, but also describes a local privilege-escalation issue. Do not interpret a major-version upgrade as proof that every part of an intrusion chain is resolved. Check current vendor guidance for your exact release and deployment. DIVD vulnerability case.
Security posture: support is a privileged workflow
Editorial assessment: help-desk systems concentrate technical conversations and often trigger password resets, access changes, or other trusted work. Their security boundary should include attachments, mail integrations, service accounts, and the actions staff will take in response to a ticket.
A version inventory is the start. Ask whether the application account can change privileged files, reach management services, or access secrets that enable movement elsewhere. Test those assumptions against configuration and permission evidence rather than a network diagram alone.
Which teams should act
| Team | Practical next step |
|---|---|
| IT operations | Identify Zammad instances, exact versions and installation methods; obtain vendor remediation guidance and preserve evidence before rebuilding. |
| EDR | Review unusual child processes and privilege changes on covered support servers, with administrator activity as a baseline. |
| SIEM / SOC | Correlate application sessions, host events, privilege changes and connections to management systems. |
| Email security | Review the support system’s mail integration and trusted ticket workflows; this is a boundary review, not a claim that email caused this incident. |
| Legal / privacy | Establish which ticket content and attachments could be exposed; scope decisions to evidence. |
IOCs and hunting
The case files reviewed do not provide a usable attacker-IP/hash list. CVE numbers identify vulnerabilities; they are not network IOCs. No invented IOC query is included.
A behavior hunt needs your own service-account name and process telemetry. Review shell or interpreter launches by the application and correlate them with maintenance records. That activity can be legitimate; a generic process match alone is not evidence of exploitation. Obtain vendor-specific detection guidance before treating a search as coverage for these CVEs.
Reporting note
The case-file update falls inside the collection window 30 September 14:42 to 1 October 14:42 UTC. Initial access was earlier. BleepingComputer’s report was a discovery source; the two DIVD case files above are the technical references. Investigation and remediation details may change.