Zammad Zero-Days Exploited in AI-Powered DIVD Hack
The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root.
Excerpt from the primary source: SecurityWeek
Who is affected
Security professionals
What you should do · Review
Review whether your organization uses the affected products and assess exposure using the linked advisories.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Original reporting
Related
DIVD says Zammad zero-days enabled AI-driven network breach
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system.
There are signs this may already be exploited, which usually shortens the time available to patch.
Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers
The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.
