Daily briefing · July 26, 2026
Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple Groups
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 26, 2026 registers as a calm day on the vulnerability front, with 15 new CVEs published, one rated Critical, and zero confirmed active exploits or weaponized proof-of-concepts. The Linux kernel leads the highlights with a CVSS 9.8 flaw, followed by a cluster of high-severity issues in NoteGen, Microsoft Edge, and AI tooling. While defenders can take a measured approach to patching today, the ransomware landscape targeting Brazilian organizations demands immediate attention.
Today’s brief
- Linux kernel CVE-2026-64530 scores CVSS 9.8 but has no known exploits yet — patch promptly as kernel flaws attract rapid weaponization
- NoteGen users below 0.32.0 face two chained high-severity risks: arbitrary OS command execution and unsanitized AI-driven HTML injection
- Three Microsoft Edge vulnerabilities disclosed today expose users to information disclosure and spoofing via origin validation errors
- Brazil is under active ransomware pressure: Section9, Global Secret Group, arcusmedia, and blackwater have hit multiple sectors in recent days
Critical highlights
1
A critical use-after-free class flaw in the Linux kernel's traffic control subsystem (cls_api) where tcf_qevent_handle fails to respect the TC_ACT_CONSUMED return, allowing access to an skb no longer owned by the caller — network-reachable scenarios make this CVSS 9.8 rating credible and warrant priority patching across all Linux deployments.
2
NoteGen before 0.32.0 exposes the Tauri shell plugin with broad execution permissions for bash, python, and python3, meaning any JavaScript running in the webview can invoke arbitrary OS commands at the process's privilege level — a critical attack surface for desktop AI note-taking users.
3
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to reflected XSS in the error page component, which could allow attackers to inject and execute malicious scripts in victim browsers interacting with affected XML-RPC endpoints.
4
NoteGen before 0.32.0 renders AI chat responses as raw HTML with no sanitization and a null CSP, meaning attacker-controlled content injected into the model prompt — such as a malicious skill REFERENCE.md — can result in stored or reflected XSS within the application context.
5
datamodel-code-generator before 0.70.0 contains a code injection flaw where a malicious customBasePath value with embedded newlines is written verbatim into generated Python import statements, enabling remote code execution for any workflow that processes attacker-controlled schemas.
6
A file and directory exposure vulnerability in Microsoft Edge (Chromium-based) allows network-adjacent unauthorized attackers to access and disclose sensitive information — organizations relying on Edge for internal or sensitive workflows should prioritize the available update.
7
An origin validation error in Microsoft Edge (Chromium-based) enables unauthorized network attackers to perform information disclosure, potentially leaking cross-origin data from browsing sessions — apply the latest Edge update immediately.
8
A resource allocation flaw in llama.cpp's JSON-Schema-to-GBNF conversion function (json-schema-to-grammar.cpp) can be triggered remotely, with a pending fix not yet merged — organizations running llama.cpp inference services exposed to external input should monitor the upstream pull request closely.
9
A null pointer dereference in llama.cpp's _visit_pattern function can be triggered remotely via crafted JSON schema input; the fix is awaiting acceptance upstream, leaving deployed instances temporarily exposed to potential denial-of-service or worse.
10
A second origin validation error in Microsoft Edge (Chromium-based) enables network-based spoofing attacks, which could be used to deceive users about the origin of content they are viewing — part of a trio of Edge flaws disclosed today that collectively raise the browser's attack surface.
Ransomware today
Brazil is experiencing concentrated ransomware activity across multiple sectors. Section9 has claimed several Brazilian victims recently spanning Financial Services, Technology, Agriculture, and other sectors, while Global Secret Group has targeted Sinop Energia (Energy & Utilities) and SPDM (Healthcare). Additionally, arcusmedia hit Power Moendas and blackwater claimed msgas.com.br in the Energy & Utilities sector, underscoring that no industry vertical in Brazil is out of scope. Among the most active groups over the past 30 days, lockbit5 and lockbit3 each account for nearly 40 or more attacks, with ransomhub, thegentlemen, 8base, and arcusmedia also highly active.
********.com.br BRSection9
Sinop Energia BRGlobal Secret Group · Energy & Utilities
*****.ind.br BRSection9 · Agriculture and Food Production
*****.com.br BRSection9 · Financial Services
****.com.br BRSection9 · Technology
******.net.br BRSection9 · Financial Services
******.com.br BRSection9 · Other
SPDM BRGlobal Secret Group · Healthcare
Power Moendas BRarcusmedia · Other
msgas.com.br BRblackwater · Energy & Utilities
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 20
Active groups & APTs
Several threat actor groups have been flagged as active or updated in recent tracking, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. None of these groups currently have confirmed attributed victims in this reporting window, but their presence in threat intelligence feeds suggests ongoing reconnaissance or preparation activity that defenders should monitor.
Brazil focus
Brazil remains one of the most targeted countries in this reporting period, with ransomware groups hitting organizations across Energy & Utilities, Healthcare, Financial Services, Technology, and Agriculture. Notable named victims include Sinop Energia (Global Secret Group), SPDM (Global Secret Group), and Power Moendas (arcusmedia), alongside multiple redacted Brazilian domains claimed by Section9. The breadth of sectors affected signals that Brazilian organizations of all sizes and industries should treat ransomware preparedness as an operational priority.
******.com.brSection9 · Other
*****.com.brSection9 · Financial Services
****.com.brSection9 · Technology
******.net.brSection9 · Financial Services
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
********.com.brSection9
SPDMGlobal Secret Group · Healthcare
Today’s recommendation: Prioritize patching CVE-2026-64530 in all Linux kernel deployments and update NoteGen to 0.32.0 or later to address the command execution and HTML injection chain; also apply the latest Microsoft Edge update to close the trio of information disclosure and spoofing flaws disclosed today.
Regardless of whether today's vulnerabilities appear in your asset inventory, validating your actual attack surface — including exposed services, AI tooling integrations, and browser policies — is the only reliable way to know if your organization is truly insulated from these risks.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →