AI-led attack reaches root access in seconds through helpdesk system
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, October 2nd, 2026.
A Dutch vulnerability disclosure nonprofit suffered data access and exfiltration after an AI-powered attack chained two previously unknown flaws in its Zammad helpdesk system. Used together, the weaknesses allowed session hijacking, remote code execution and privilege escalation from the Zammad user to root within seconds. The attacker then reached other services before the response team intervened.
Network segmentation and rapid containment limited deeper movement, but investigators are still assessing the damage. The purpose of the attack also remains unknown. One flaw affects Zammad 6.3.0 through 6.5.4, while the privilege escalation issue affects all versions. Version 7 avoids the first attack path because of its environment, but the second issue remains without a fix.
Support platforms should be treated as connected business systems because they may contain sensitive conversations and credentials. Defenders should preserve logs, use the available checking script and isolate systems that can’t be moved to version 7. Move Zammad to version 7 or take it offline while preserving evidence for investigation. The broader warning is that AI can compress a multi-step intrusion into a response window measured in seconds.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.