Back to all lessons
Awareness Lessons
last week

DIVD Breached via Zammad Zero-Day Exploits, Attacker Gains Root Access

The Dutch Institute for Vulnerability Disclosure — an organization dedicated to finding and disclosing vulnerabilities — was itself compromised through two zero-day vulnerabilities in its Zammad helpdesk ticketing system, resulting in remote code execution and full root access. Zero-days, by definition, have no available patch at the time of exploitation, making them among the most difficult threats to defend against, but compensating controls can significantly reduce blast radius. The irony of a vulnerability disclosure body being breached underscores that no organization is immune, and that defensive layers beyond patching are critical. This incident also highlights the danger of AI-assisted attacks, which can accelerate exploitation timelines and reduce the skill threshold required for sophisticated intrusions.

Tactical Insight

Immediate actions

  • Isolate and take offline any internet-facing Zammad instances until vendor-supplied patches or mitigations are available.
  • Audit all accounts and access tokens on compromised systems and rotate credentials immediately.
  • Engage your incident response team to conduct forensic analysis and determine the full scope of the breach.

Long-term improvements

  • Apply the principle of least privilege so that application-layer compromises cannot escalate directly to root/system-level access.
  • Implement network segmentation to isolate ticketing and helpdesk systems from critical internal infrastructure.
  • Establish a formal third-party software risk review process to evaluate the security posture of SaaS and self-hosted tools before deployment.

Detection measures

  • Deploy runtime application self-protection (RASP) or web application firewall (WAF) rules to detect and block anomalous code execution attempts on web-facing applications.
  • Ensure centralized logging and SIEM alerting is configured to flag privilege escalation events and unexpected outbound connections in real time.
  • Conduct regular threat-hunting exercises focused on lateral movement and privilege escalation indicators across internet-exposed services.