The Knowledge Hub Is Itself a Crown Jewel
A vulnerability-disclosure organization is not only a defender. It is also a repository of other organizations’ weaknesses.
On September 21, 2026, the Dutch Institute for Vulnerability Disclosure (DIVD) was breached through its Zammad ticketing environment. DIVD says two previously unknown Zammad vulnerabilities were chained to obtain session hijacking, remote code execution, and privilege escalation to root. DIVD attributes the speed and operating pattern to an agentic-AI-powered attack, while making clear that the actor and specific AI system remain unidentified.
The record system was part of the attack surface
DIVD’s October 1 investigation update confirmed that volunteer data, including DIVD email addresses and possibly contact information, was exfiltrated. It also confirmed that the attackers entered through the CSIRT ticketing system. That system contains every email sent to the CSIRT mailbox and every reply. DIVD warns organizations and individuals that exchanged messages with the CSIRT to assume that some of that information may have been obtained.
The potentially affected corpus is operationally sensitive: follow-up requests involving scan data and vulnerable IP addresses, vulnerability reports, masked credential material, and possibly information related to zero-days and proof-of-concept attacks. DIVD says the investigation is continuing and that only part of the information appears to have been extracted.
The continuity failure
The CSIRT ticketing system is not just a communications tool. It is institutional evidence. Researchers and affected organizations provide source material; DIVD turns it into authoritative case correspondence; and that record supports later notification, remediation, and coordinated response.
The break is therefore Source / researcher or affected organization → Evidence / CSIRT correspondence → Authority / DIVD case handling → Record / ticketing system. Root compromise allowed an unauthorized actor to traverse that relationship and extract part of the record.
A second continuity risk follows from exposed identity and correspondence. If an attacker can impersonate a DIVD volunteer using real context, future recipients may struggle to distinguish an authentic remediation request from an attacker-generated message. The breach can therefore damage not only confidentiality, but the future authority of the institution’s communications.
The GovKM interpretation
Knowledge hubs are crown jewels because they preserve the relationships required to coordinate action across organizations. In vulnerability disclosure, the record often contains who reported the issue, which systems are affected, what evidence supports the finding, which parties have been contacted, and what remediation state currently governs the case.
Protecting that repository is therefore a continuity requirement. If the record is exposed, altered, fragmented, or rendered untrustworthy, the institution can lose both its historical evidence and its future ability to act with recognized authority.
Continuity path: Source / vulnerability report → Evidence / technical findings and correspondence → Authority / CSIRT validation and notification role → Context / affected organization and vulnerable system → Decision / notify, coordinate, or remediate → Action → Record / case file → Institutional Memory / vulnerability history and responder identity → Future Reuse / continued remediation and trusted outreach.
Sources
DIVD CSIRT, DIVD-2026-00014 – When, not if…, published September 29 and updated October 1, 2026. https://csirt.divd.nl/cases/DIVD-2026-00014/
DIVD CSIRT, Overview of data investigation, October 1, 2026. https://csirt.divd.nl/cases/DIVD-2026-00014/overview_data_investigation/
DIVD CSIRT, DIVD-2026-00015 – Vulnerabilities in Zammad during investigation of case DIVD-2026-00014, updated October 1, 2026. https://csirt.divd.nl/cases/DIVD-2026-00015/


