Mmastodon TechnologyCybersecurity first seen 10 h ago, last 10 h ago, peak #5
DIVD reports compromise via chained Zammad vulnerabilities
Original: DIVD reported a compromise involving two chained Zammad vulnerabilities, with session hijacking, remote code execution,
The Dutch Institute for Vulnerability Disclosure has reported a security compromise involving two chained vulnerabilities in the open-source ticketing system Zammad. The attack combined session hijacking, remote code execution, privilege escalation and data exfiltration, showing how separate flaws in a single service can be combined into a full intrusion path. Security professionals are circulating the report as a case study in chained exploits and the importance of patching interconnected components.
Why now: The DIVD disclosure is fresh and highlights a real intrusion combining multiple vulnerabilities, making it highly relevant to security teams running Zammad.
Evidence
- DIVD reported a compromise involving two chained Zammad vulnerabilities, with session hijacking, remote code execution, privilege escalation, and data exfiltration. The case matters because flaws in one service can provide a path to broader access. # ThreatIntel #… · cyberworldops@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/685237