字号 ·· | 护眼
theregister

AI代理黑进了黑客,从安全研究机构窃取了电子邮件地址AI agents hacked the hackers, stealing email addresses from security research org

点「原文对照」整页切到原文,或双击某段只看那段的原文。

AI代理攻击了黑客——荷兰漏洞披露研究所(DIVD)——通过其Zammad支持平台中的两个零日漏洞,利用这些缺陷劫持会话、以本地zammad用户身份远程运行代码,并将权限提升至root。链式攻击仅用几秒钟就从会话劫持进展到获取root访问权限,周四,这家非营利漏洞搜寻组织表示,攻击者窃取了其志愿者安全研究人员的数据,包括DIVD邮箱地址和可能的其他联系方式。

AI agents hacked the hackers - the Dutch Institute for Vulnerability Disclosure (DIVD) - via two zero-day bugs in its Zammad support platform, abusing the flaws to hijack sessions, run code remotely as the local zammad user, and escalate privileges to root. The chained exploits took just seconds to move from session hijacking to root access, and on Thursday, the nonprofit bug hunting organization said the miscreants stole data belonging to its volunteer security researchers, including DIVD email addresses and potentially other contact details.

“我们仍在调查具体哪些志愿者的哪些数据受到影响,”DIVD在其事件报告中表示。“对DIVD志愿者(及其他人)而言,这意味着更高的社会工程学攻击风险,因为这让冒充DIVD成员变得更容易。”

“We’re still investigating exactly which data of which volunteers is affected,” DIVD said in its incident report. “For DIVD volunteers (and others) this means a higher risk of social engineering, because this makes it easier for someone to pose as a DIVD’er.”

随后的一条LinkedIn帖子建议,任何收到来自DIVD人员的邮件或联系请求且“感觉略有不对劲”的人,通过发送邮件至communications@divd.nl进行核实。

A subsequent LinkedIn post advised anyone receiving an email or contact request from someone at DIVD “that feels slightly off” to verify that it’s legit by emailing communications@divd.nl.

DIVD也是CVE编号机构(CNA),它为Zammad中现已公开的安全漏洞分配了CVE编号,Zammad是一个开源的帮助台和客户支持工单系统。它们是CVE-2026-102489和CVE-2026-102490,在链式攻击场景下评估,两个漏洞均获得了CVSS 4.0评分9.4。

DIVD is also a CVE Numbering Authority (CNA), and it assigned CVE IDs to the now-public security holes in Zammad, an open-source helpdesk and customer support ticketing system. They are CVE-2026-102489 and CVE-2026-102490, and both bugs received CVSS 4.0 scores of 9.4, when assessed in the chained attack scenario.

CVE-2026-102489允许未经身份验证的攻击者实现远程代码执行并泄露用户会话,而CVE-2026-102490允许本地用户将权限提升至root。Zammad 6.3.0至6.5.4版本受CVE-2026-102489影响,该漏洞也存在于7.0.0至7.1.3版本中——但根据DIVD的通告,由于“环境条件”原因不可利用。所有Zammad版本均受CVE-2026-102490影响。

CVE-2026-102489 enables unauthenticated attackers to achieve remote code execution and leak user sessions, while CVE-2026-102490 allows a local user to elevate their privileges to root. Zammad versions 6.3.0 to 6.5.4 are vulnerable to CVE-2026-102489, and it also exists in versions 7.0.0 through 7.1.3 - but it’s not exploitable “due to environment conditions,” according to DIVD’s advisory. All Zammad versions are vulnerable to CVE-2026-102490.

DIVD 建议“所有 Zammad 用户升级到 Zammad 7 版本或将其下线。”

DIVD advises “all users of Zammad to upgrade to version 7 of Zammad or to take it offline.”

发生了什么根据该非营利组织的时间线,攻击发生在 9 月 21 日,当时“恶意行为者”通过其工单支持软件中的两个零日漏洞闯入了其 IT 系统。第二天,漏洞猎人们发现了攻击者,切断了对其所有数据中心系统的访问,并与 Merlon Security 组建了事件响应团队。

What happened According to the nonprofit’s timeline, the attack happened on September 21, when "malicious actors” broke into its IT system via the two zero-days in its ticketing support software. The bug hunters discovered the attackers the following day, blocked access to all of its data center systems, and formed an incident response team with Merlon Security.

9 月 24 日,DIVD 向供应商报告了 Zammad 漏洞,通知了荷兰数据保护局和国家网络安全中心有关该事件,并与警方讨论了应对方案。它还在 LinkedIn 上发布了首份披露声明。

On September 24, DIVD reported the Zammad vulnerability to the vendor, notified the Dutch Data Protection Authority and the National Cyber Security Centre about the incident, and discussed its options with police. It also posted its first disclosure on LinkedIn.

“花了我们(近)七年时间,但我们现在可以说我们是被黑客攻击的黑客,”帖子写道,并补充说 DIVD 仍致力于以“我们认为应有的方式”处理该事件。“那就是公开、透明和诚实,即使这很糟糕。”

“It took us (almost) seven years but we can now say that we're the hackers that got hacked,” the post said, adding that DIVD remained committed to handling the incident in “the way we think it should be handled. That is open, transparent and honest, even if it sucks.”

“作案手法”指向智能体 AI DIVD 还指出,其团队从未见过此类攻击。

'Modus operandi' indicates agentic AI DIVD also noted that its team had never seen an attack like this before.

“这是我们从未见过的攻击,”帖子称。“不是因为这是我们第一次遭遇,而是因为作案手法表明这是一起由智能体 AI 驱动的攻击。”

“This is an attack we have not seen before,” according to the post. “Not because it’s our first, but because the modus operandi indicates that this is an agentic AI powered attack.”

DIVD 表示,该攻击“吵闹且极其混乱”。“我们能看到智能体在自动化工作,因为每次行动后它都会以光速和粗糙的逻辑或模式自行决定下一步。”

The attack was "loud and very very messy," DIVD said. "We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern."

调查期间发现的日志截图后续帖子揭示了攻击脚本中嵌入的注释——这进一步表明这是一场智能体操作,或至少是 AI 赋能的操作。

Subsequent posts with screenshots of logs found during the investigation reveal embedded notes found in the attack script - another indication that this was an agentic operation or at least AI-enabled.

“哪个人类攻击者会在脚本中给自己留下注释,解释他们正在做的事情为什么是可以的,而且绝对不是网络钓鱼?AI 只是得到了一个任务,然后在代码注释中不断为自己的行为辩护,人类才不会在乎这些,”帖子写道。"谁还有时间管那些事啊?" 要是所有组织应对黑客攻击都能像这样就好了虽然调查仍在进行中,但安全研究人员称赞 DIVD 在披露和应对黑客攻击方面的透明度。

“What human attacker leaves notes to themself in their scripts, explaining why what they're doing is okay and really not phishing? The AI just got a task and keeps justifying its own actions in the code as comments, a human wouldn’t care less," the post said. "Who has time for that anyway?”If only all orgs responded to hacks like this While the investigation remains ongoing, security researchers applauded DIVD for its transparency in disclosing and responding to the hack.

VulnCheck 安全研究员 Patrick Garrity 在 LinkedIn 上发帖称:“向 DIVD 致敬,感谢他们在处理正在进行的事件和调查时表现出的诚实和透明度。”“要是所有组织在安全事件上都能这么透明就好了!”在随后接受 The 采访时,Garrity 表示赞赏 DIVD 对此次泄露事件的“彻底诚实”。“他们正在践行自己的理念,这很棒,并迅速向其他可能使用该产品的组织发布信息,以便它们在遭受攻击前采取行动。”®

“Kudos to DIVD for their level of honesty and transparency working through their active incident and investigation,” VulnCheck security researcher Patrick Garrity posted on LinkedIn. “It would be nice if all organizations were this transparent about their security incidents!”In a subsequent interview with The, Garrity said he applauded DIVD’s “brutal honesty” about the breach. “They're eating their own dog food, which is great, and getting information out quickly to other organizations that potentially use this product so they can take action before they get hit.”®