Security

AI agents hack hackers, stealing emails from security org

1 min readSource: The Register
AI agents hack hackers, stealing emails from security org

The Dutch Institute for Vulnerability Disclosure faced a breach that compromised data of its researchers. The attackers exploited vulnerabilities in its Zammad support platform.

Recently, the Dutch Institute for Vulnerability Disclosure (DIVD) fell victim to a cyberattack carried out by AI agents. The attackers exploited two zero-day vulnerabilities in the Zammad support platform, allowing them to hijack sessions, execute code remotely, and escalate privileges to gain full system access.

This attack was remarkably swift, as the intruders were able to move from session hijacking to root access in mere seconds. Consequently, data belonging to DIVD's volunteer security researchers was compromised, including email addresses and potentially other contact information.

## Why it matters This incident highlights the increasing sophistication of cyberattacks, where even organizations dedicated to cybersecurity can be vulnerable. The attackers' ability to use AI to execute complex exploits raises a new level of risk for both institutions and individuals.

## What we know The DIVD has communicated that they are still investigating the exact extent of the compromised data and that the situation is concerning for their volunteers. The organization has warned that this increases the risk of social engineering attacks, as criminals may impersonate DIVD members to deceive others.

## What remains unclear The total scope of the stolen information has not yet been confirmed, nor how this data will be utilized by the attackers. The investigation is ongoing, and more details are expected to be provided in the near future.

Share:

Read at the original source:

The Register →
#seguridad#hacking#ai#divd#vulnerabilidades

Related news