Daily briefing · July 26, 2026
Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple Groups
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 26, 2026 registers as a calm day on the vulnerability front, with 15 new CVEs published, one rated Critical, and zero confirmed active exploits or weaponized proof-of-concepts. The Linux kernel leads the highlights with a CVSS 9.8 flaw, followed by a cluster of high-severity issues in NoteGen, Microsoft Edge, and AI tooling. While defenders can take a measured approach to patching today, the ransomware landscape targeting Brazilian organizations demands immediate attention.
Today’s brief
- Linux kernel CVE-2026-64530 scores CVSS 9.8 but has no known exploits yet — patch promptly as kernel flaws attract rapid weaponization
- NoteGen users below 0.32.0 face two chained high-severity risks: arbitrary OS command execution and unsanitized AI-driven HTML injection
- Three Microsoft Edge vulnerabilities disclosed today expose users to information disclosure and spoofing via origin validation errors
- Brazil is under active ransomware pressure: Section9, Global Secret Group, arcusmedia, and blackwater have hit multiple sectors in recent days
Critical highlights
1
A critical use-after-free class flaw in the Linux kernel's traffic control subsystem (cls_api) where tcf_qevent_handle fails to respect the TC_ACT_CONSUMED return, allowing access to an skb no longer owned by the caller — network-reachable scenarios make this CVSS 9.8 rating credible and warrant priority patching across all Linux deployments.
2
NoteGen before 0.32.0 exposes the Tauri shell plugin with broad execution permissions for bash, python, and python3, meaning any JavaScript running in the webview can invoke arbitrary OS commands at the process's privilege level — a critical attack surface for desktop AI note-taking users.
3
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to reflected XSS in the error page component, which could allow attackers to inject and execute malicious scripts in victim browsers interacting with affected XML-RPC endpoints.
4
NoteGen before 0.32.0 renders AI chat responses as raw HTML with no sanitization and a null CSP, meaning attacker-controlled content injected into the model prompt — such as a malicious skill REFERENCE.md — can result in stored or reflected XSS within the application context.
5
datamodel-code-generator before 0.70.0 contains a code injection flaw where a malicious customBasePath value with embedded newlines is written verbatim into generated Python import statements, enabling remote code execution for any workflow that processes attacker-controlled schemas.
6
A file and directory exposure vulnerability in Microsoft Edge (Chromium-based) allows network-adjacent unauthorized attackers to access and disclose sensitive information — organizations relying on Edge for internal or sensitive workflows should prioritize the available update.
7
An origin validation error in Microsoft Edge (Chromium-based) enables unauthorized network attackers to perform information disclosure, potentially leaking cross-origin data from browsing sessions — apply the latest Edge update immediately.
8
A resource allocation flaw in llama.cpp's JSON-Schema-to-GBNF conversion function (json-schema-to-grammar.cpp) can be triggered remotely, with a pending fix not yet merged — organizations running llama.cpp inference services exposed to external input should monitor the upstream pull request closely.
9
A null pointer dereference in llama.cpp's _visit_pattern function can be triggered remotely via crafted JSON schema input; the fix is awaiting acceptance upstream, leaving deployed instances temporarily exposed to potential denial-of-service or worse.
10
A second origin validation error in Microsoft Edge (Chromium-based) enables network-based spoofing attacks, which could be used to deceive users about the origin of content they are viewing — part of a trio of Edge flaws disclosed today that collectively raise the browser's attack surface.
Ransomware today
Brazil is experiencing concentrated ransomware activity across multiple sectors. Section9 has claimed several Brazilian victims recently spanning Financial Services, Technology, Agriculture, and other sectors, while Global Secret Group has targeted Sinop Energia (Energy & Utilities) and SPDM (Healthcare). Additionally, arcusmedia hit Power Moendas and blackwater claimed msgas.com.br in the Energy & Utilities sector, underscoring that no industry vertical in Brazil is out of scope. Among the most active groups over the past 30 days, lockbit5 and lockbit3 each account for nearly 40 or more attacks, with ransomhub, thegentlemen, 8base, and arcusmedia also highly active.
********.com.br BRSection9
Sinop Energia BRGlobal Secret Group · Energy & Utilities
*****.ind.br BRSection9 · Agriculture and Food Production
*****.com.br BRSection9 · Financial Services
****.com.br BRSection9 · Technology
******.net.br BRSection9 · Financial Services
******.com.br BRSection9 · Other
SPDM BRGlobal Secret Group · Healthcare
Power Moendas BRarcusmedia · Other
msgas.com.br BRblackwater · Energy & Utilities
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 20
Active groups & APTs
Several threat actor groups have been flagged as active or updated in recent tracking, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. None of these groups currently have confirmed attributed victims in this reporting window, but their presence in threat intelligence feeds suggests ongoing reconnaissance or preparation activity that defenders should monitor.
Brazil focus
Brazil remains one of the most targeted countries in this reporting period, with ransomware groups hitting organizations across Energy & Utilities, Healthcare, Financial Services, Technology, and Agriculture. Notable named victims include Sinop Energia (Global Secret Group), SPDM (Global Secret Group), and Power Moendas (arcusmedia), alongside multiple redacted Brazilian domains claimed by Section9. The breadth of sectors affected signals that Brazilian organizations of all sizes and industries should treat ransomware preparedness as an operational priority.
******.com.brSection9 · Other
*****.com.brSection9 · Financial Services
****.com.brSection9 · Technology
******.net.brSection9 · Financial Services
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
********.com.brSection9
SPDMGlobal Secret Group · Healthcare
Today’s recommendation: Prioritize patching CVE-2026-64530 in all Linux kernel deployments and update NoteGen to 0.32.0 or later to address the command execution and HTML injection chain; also apply the latest Microsoft Edge update to close the trio of information disclosure and spoofing flaws disclosed today.
Regardless of whether today's vulnerabilities appear in your asset inventory, validating your actual attack surface — including exposed services, AI tooling integrations, and browser policies — is the only reliable way to know if your organization is truly insulated from these risks.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →