DIVD 尚未公开所用 AI 系统或操作者身份。Zammad 管理员应按具体版本核对两项漏洞,并调查是否存在入侵迹象。
How did the September 21, 2026 breach of the Dutch Institute for Vulnerability Disclosure unfold, including how an attacker used an AI agentIllustration; it does not depict the actual DIVD incident.
AI 提示
Create a landscape editorial hero image for this Studio Global article: How did the September 21, 2026 breach of the Dutch Institute for Vulnerability Disclosure unfold, including how an attacker used an AI agent. Article summary: On September 21, 2026, an attacker breached DIVD through its Zammad helpdesk. DIVD assessed that an AI agent helped chain two previously unknown flaws, taking the attacker from an ordinary account to root access in secon. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clic
openai.com
2026 年 9 月 21 日,荷兰漏洞披露机构(Dutch Institute for Vulnerability Disclosure,DIVD)遭到入侵,攻击者从该机构使用的 Zammad 服务台切入。DIVD 称,攻击涉及一个 AI 代理和两处此前未公开的漏洞:一处可劫持会话并远程执行代码,另一处可将权限提升至 root。漏洞链据称在数秒内完成。公开报道介绍了攻击造成的影响,但没有确认所用 AI 系统或其操作者身份。3917