{"ok":true,"trend":{"id":685237,"platform":"mastodon","region":"global","key":"divd reported a compromise involving two chained zammad vulnerabilities, with session hijacking, remote code execution,","title":"DIVD reported a compromise involving two chained Zammad vulnerabilities, with session hijacking, remote code execution,","url":"https://infosec.exchange/@cyberworldops/117369038503258933","first_seen":"2026-10-02T03:16:45.440358Z","last_seen":"2026-10-02T03:16:45.440358Z","last_rank":5,"peak_rank":5,"last_volume":2,"peak_volume":2,"seen_count":1,"score":0.52046875,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"The Dutch Institute for Vulnerability Disclosure has reported a security compromise involving two chained vulnerabilities in the open-source ticketing system Zammad. The attack combined session hijacking, remote code execution, privilege escalation and data exfiltration, showing how separate flaws in a single service can be combined into a full intrusion path. Security professionals are circulating the report as a case study in chained exploits and the importance of patching interconnected components.","why":"The DIVD disclosure is fresh and highlights a real intrusion combining multiple vulnerabilities, making it highly relevant to security teams running Zammad.","tone":"neutral","entities":["DIVD","Zammad"],"summarized_at":"2026-10-02T03:17:48.940997Z","meta":{"tag":"cybersecurity","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1329},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"DIVD reports compromise via chained Zammad vulnerabilities","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-02T03:16:45.440358Z","rank":5,"volume":2}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@cyberworldops/117369038503258933","author":"cyberworldops@infosec.exchange","title":null,"snippet":"DIVD reported a compromise involving two chained Zammad vulnerabilities, with session hijacking, remote code execution, privilege escalation, and data exfiltration. The case matters because flaws in one service can provide a path to broader access. # ThreatIntel #…","posted_at":"2026-10-02T02:50:00Z","likes":2}],"elsewhere":[],"window":"7d"}}