Security news from the BlueTeamSec community for Tuesday the 6th of October 2026. Quite a lot to get through today — fourteen stories spanning everything from coordinated attacks on energy infrastructure to malware baked into cheap projectors.
GitLab's Threat Research Group disclosed a command execution vulnerability in DeepSeek-Reasonix Studio that lets attackers run arbitrary code when a developer views a file diff. The flaw exploits poisoned git configurations and filter settings, bypassing the usual git client hardening — so it's one for anyone using AI coding assistants. We've covered related supply chain risks around coding agents before, most recently in September.
Debian issued a security advisory patching roughly a thousand CVEs in the Linux kernel for the stable distribution. The vulnerabilities span 2024 through to this year and cover privilege escalation, denial of service, and information leaks across multiple subsystems — so worth flagging if you're running Debian Trixie.
Security researchers disclosed a local privilege escalation bug in the adm-zip library, where an overly permissive bitmask incorrectly preserved SUID and SGID bits during extraction. Attackers can craft malicious ZIP files that extract with elevated permissions — it's fixed in version 0.6.1, and we've seen Node.js-based malware exploiting similar patterns over the past few months.
Thomas Naunheim documented a privilege escalation flaw in Microsoft Entra Identity Governance, where catalog owners could inject high-privilege API permissions into access packages without proper checks after the initial permission. The issue allowed non-privileged users to escalate to sensitive directory roles — Microsoft's since addressed the validation logic, and we've tracked similar Entra tooling over recent weeks.
UAE's head of cybersecurity confirmed that Iranian physical strikes on energy facilities, refineries, and ports have been synchronised with cyberattacks against the same targets. Attackers exploit IT-OT bridgeheads to compromise domain controllers and manipulate industrial controllers — and daily incidents in the region have reportedly tripled since late February.
Security researchers published a breakdown of a supply chain attack affecting inexpensive Android projectors using the Allwinner chipset. The devices ship with pre-installed malware embedded in the firmware, functioning as botnet nodes with active command and control as soon as they connect to the internet — the compromise affects shared firmware across multiple vendors. We've covered similar embedded botnet infrastructure in past months.
Security researchers released a JScript utility for enumerating Windows certificate enrollment COM objects by querying the registry. It's designed as a reconnaissance tool for analysing the attack surface of certificate infrastructure, with safeguards to prevent actual system modification — useful if you're mapping out Windows trust boundaries.
Cantina Security and Yeta Labs released Apex Flash, a pair of open-weights AI models fine-tuned on real-world vulnerabilities for security research. The models are trained on authorization, identity, and scope-binding bugs and can run locally for automated vulnerability detection — achieving roughly sixty-seven percent success on internal evaluations.
SigLens is a Windows binary analysis tool that pinpoints exactly which regions in a file trigger antivirus detections. It uses prefix-based narrowing for executables and AMSI scanning for scripts to map detection offsets without modifying the file — one for artifact triage and detection engineering workflows.
InfoGuard introduced velociraptor-skills, an open-source project that integrates AI capabilities with the Velociraptor DFIR framework to automate forensic analysis and threat hunting workflows. The tool generates structured reports and supports cross-platform investigations, though it does introduce data residency and indirect prompt injection risks when sending artifacts to LLM providers.
Structio released N0xis, a source-available reverse engineering toolkit that combines static decompilation with live memory analysis. The tool traces runtime values back to specific code paths in stripped and obfuscated binaries, targeting formats like NativeAOT and IL2CPP — bridges the gap between static and dynamic analysis workflows.
Security researchers released Lockjaw, a modular command-and-control framework combining a Rust-based teamserver with a Zig and Assembly implant. It implements indirect syscalls, AMSI bypass via hardware breakpoints, and PoolParty injection to evade endpoint detection — supports multiple communication channels and in-memory beacon object file loading.
NuGuard is an open-source AI red-teaming toolkit for assessing security vulnerabilities in large language model and agentic AI applications. The framework performs prompt injection testing, vulnerability assessment, and static analysis to identify risks like cross-account data leakage and unauthorised tool use — designed for developers and security teams building AI-driven applications.
Security researchers published UnifiedThreatHunting, a standardised methodology for conducting threat hunts within organisations. It integrates concepts from the Hunting Maturity Model and other frameworks, providing a repeatable process for SOC teams and threat hunters — operates on an assumed breach model for proactive detection.
And that's your briefing for today. Attribution goes to the original authors — the analysis here was automated.