安全
AI 代理入侵了黑客,从安全研究机构窃取电子邮件地址
链式 Zammad 漏洞使攻击者能够在数秒内劫持会话、执行代码并提升权限至 root。
AI 代理入侵了黑客——荷兰漏洞披露研究所(DIVD)——利用其 Zammad 支持平台中的两个零日漏洞,滥用这些缺陷以劫持会话、以本地 zammad 用户身份远程运行代码,并将权限提升至 root。
这组链式攻击从会话劫持到获取 root 访问权限仅耗时数秒。周四,这家非营利性的漏洞挖掘组织表示,不法分子窃取了其志愿者安全研究人员的数据,包括 DIVD 的电子邮件地址以及可能其他联系方式。
“我们仍在调查具体哪些志愿者的哪些数据受到影响,”DIVD 在其事件报告中称。“对于 DIVD 志愿者(及其他人)而言,这意味着面临更高的社会工程学风险,因为这使他人更容易伪装成 DIVD 成员。”
随后发布在 LinkedIn 上的帖子建议,任何收到来自 DIVD 人员“感觉略有异常”的电子邮件或联系请求的人,都应通过向 communications@divd.nl 发送邮件来验证其合法性。
DIVD 还是一家 CVE 编号机构(CNA),它为 Zammad(一个开源帮助台和客户支持工单系统)中现已公开的漏洞分配了 CVE ID。它们是 CVE-2026-102489 和 CVE-2026-102490,在链式攻击场景下评估时,这两个漏洞的 CVSS 4.0 评分均为 9.4。
CVE-2026-102489 使未经身份验证的攻击者能够实现远程代码执行并泄露用户会话,而 CVE-2026-102490 允许本地用户将权限提升至 root。
Zammad 版本 6.3.0 至 6.5.4 易受 CVE-2026-102489 影响,该漏洞也存在于 7.0.0 至 7.1.3 版本中——但根据 DIVD 的通告,由于环境条件限制,它无法被利用。
所有 Zammad 版本均易受 CVE-2026-102490 影响。DIVD 建议“所有 Zammad 用户升级到 Zammad 7 版本或将其下线。”
事件经过
根据该非营利组织的时间线,攻击发生在 9 月 21 日,“恶意行为者”通过其工单支持软件中的两个零日漏洞入侵了其 IT 系统。
漏洞挖掘者在次日发现了攻击者,阻止了对其所有数据中心系统的访问,并与 Merlon Security 组成了事件响应团队。
9 月 24 日,DIVD 向供应商报告了 Zammad 漏洞,通知了荷兰数据保护局和国家网络安全中心该事件,并与警方讨论了应对方案。它还在 LinkedIn 上发布了首次披露信息。
“我们花了(几乎)七年时间,但现在我们可以说,我们是那个被黑掉的黑客。”该帖子称,并补充道,DIVD 仍致力于以“我们认为应该的方式”处理此次事件,“即开放、透明和诚实,即使这很糟糕。”
‘作案手法’表明是代理式 AI
DIVD 还指出,其团队此前从未见过此类攻击。
“这是我们前所未见的攻击,”帖子称。“这不是因为这是我们的第一次遭遇,而是因为作案手法表明这是一次由代理式 AI 驱动的攻击。”
DIVD 表示,这次攻击“声势浩大且非常混乱”。 “我们可以看到代理在自动工作,因为它在每一步行动后都以光速和粗糙的逻辑或模式自行决定下一步。”
随后发布的包含调查中发现的日志截图的帖子揭示了攻击脚本中嵌入的注释——这进一步表明这是一次代理式操作,或者至少是 AI 辅助的。
“人类攻击者会在自己的脚本中留下给自己看的注释,解释为什么他们的行为是可以接受的,而且绝对不是网络钓鱼吗?AI 只是接到任务,并在代码中以注释形式不断为自己的行为辩护,而人类根本不会在乎这些。”帖子写道,“谁有工夫做那个呢?”
要是所有组织都能像这样应对黑客攻击就好了
尽管调查仍在进行中,安全研究人员对DIVD在披露和回应此次黑客事件时所展现的透明度表示赞赏。
VulnCheck的安全研究员Patrick Garrity在LinkedIn上发帖称:“为DIVD在处理活跃事件和调查过程中所展现的诚实与透明点赞。如果所有组织都能对其安全事件保持如此高的透明度,那就太好了!”
随后在接受The Register采访时,Garrity称赞了DIVD对此次数据泄露事件的“毫不掩饰的坦诚”。他表示:“他们正在践行自己产品的理念,这非常棒,并且能够快速向其他可能使用该产品的组织提供信息,以便它们在遭受攻击之前采取行动。”®
security
AI agents hacked the hackers, stealing email addresses from security research org
Chained Zammad flaws enabled session hijacking, code execution, and root escalation in seconds
AI agents hacked the hackers - the Dutch Institute for Vulnerability Disclosure (DIVD) - via two zero-day bugs in its Zammad support platform, abusing the flaws to hijack sessions, run code remotely as the local zammad user, and escalate privileges to root.
The chained exploits took just seconds to move from session hijacking to root access, and on Thursday, the nonprofit bug hunting organization said the miscreants stole data belonging to its volunteer security researchers, including DIVD email addresses and potentially other contact details.
“We’re still investigating exactly which data of which volunteers is affected,” DIVD said in its incident report . “For DIVD volunteers (and others) this means a higher risk of social engineering, because this makes it easier for someone to pose as a DIVD’er.”
A subsequent LinkedIn post advised anyone receiving an email or contact request from someone at DIVD “that feels slightly off” to verify that it’s legit by emailing communications@divd.nl.
DIVD is also a CVE Numbering Authority (CNA), and it assigned CVE IDs to the now-public security holes in Zammad, an open-source helpdesk and customer support ticketing system. They are CVE-2026-102489 and CVE-2026-102490 , and both bugs received CVSS 4.0 scores of 9.4, when assessed in the chained attack scenario.
CVE-2026-102489 enables unauthenticated attackers to achieve remote code execution and leak user sessions, while CVE-2026-102490 allows a local user to elevate their privileges to root.
Zammad versions 6.3.0 to 6.5.4 are vulnerable to CVE-2026-102489, and it also exists in versions 7.0.0 through 7.1.3 - but it’s not exploitable “due to environment conditions,” according to DIVD’s advisory.
All Zammad versions are vulnerable to CVE-2026-102490. DIVD advises “all users of Zammad to upgrade to version 7 of Zammad or to take it offline.”
What happened
According to the nonprofit’s timeline , the attack happened on September 21, when "malicious actors” broke into its IT system via the two zero-days in its ticketing support software.
The bug hunters discovered the attackers the following day, blocked access to all of its data center systems, and formed an incident response team with Merlon Security.
On September 24, DIVD reported the Zammad vulnerability to the vendor, notified the Dutch Data Protection Authority and the National Cyber Security Centre about the incident, and discussed its options with police. It also posted its first disclosure on LinkedIn.
“It took us (almost) seven years but we can now say that we're the hackers that got hacked,” the post said, adding that DIVD remained committed to handling the incident in “the way we think it should be handled. That is open, transparent and honest, even if it sucks.”
'Modus operandi' indicates agentic AI
DIVD also noted that its team had never seen an attack like this before.
“This is an attack we have not seen before,” according to the post. “Not because it’s our first, but because the modus operandi indicates that this is an agentic AI powered attack.”
The attack was "loud and very very messy," DIVD said . "We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern."
Subsequent posts with screenshots of logs found during the investigation reveal embedded notes found in the attack script - another indication that this was an agentic operation or at least AI-enabled.
“What human attacker leaves notes to themself in their scripts, explaining why what they're doing is okay and really not phishing? The AI just got a task and keeps justifying its own actions in the code as comments, a human wouldn’t care less," the post said. "Who has time for that anyway?”
If only all orgs responded to hacks like this
While the investigation remains ongoing, security researchers applauded DIVD for its transparency in disclosing and responding to the hack.
“Kudos to DIVD for their level of honesty and transparency working through their active incident and investigation,” VulnCheck security researcher Patrick Garrity posted on LinkedIn. “It would be nice if all organizations were this transparent about their security incidents!”
In a subsequent interview with The Register , Garrity said he applauded DIVD’s “brutal honesty” about the breach. “They're eating their own dog food, which is great, and getting information out quickly to other organizations that potentially use this product so they can take action before they get hit.”®
首次收录 · 2026-10-02 · 8.94 分