<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://skopnix.com/news/2e4be0073b4d-fragnesia-primitive-via-open-vswitch-deterministic-local-pri</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T07:06:38.000Z</news:publication_date>
      <news:title>Fragnesia primitive via Open vSwitch. Deterministic local privilege escalation.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-636-ghsa-mxm6-v9r6-r94c-nuxtjsmdcs-url-sanitizer-misses-svg-xlin</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T22:14:01.000Z</news:publication_date>
      <news:title>GHSA-mxm6-v9r6-r94c: @nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-631-ghsa-9pj6-vhgr-3mwh-rmcp-unauthenticated-permanent-session-t</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T22:13:34.000Z</news:publication_date>
      <news:title>GHSA-9pj6-vhgr-3mwh: RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote de</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-631-ghsa-33f5-2c5q-wgwj-rmcp-missing-resource-field-validation-i</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T22:13:26.000Z</news:publication_date>
      <news:title>GHSA-33f5-2c5q-wgwj: RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-7prp-2623-8g45-djust-has-an-unauthenticated-arbitrary-m</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T22:09:38.000Z</news:publication_date>
      <news:title>GHSA-7prp-2623-8g45: djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-c7c5-5j6r-q957-djust-has-broken-object-level-access-con</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T22:06:02.000Z</news:publication_date>
      <news:title>GHSA-c7c5-5j6r-q957: djust has broken object-level access control (IDOR)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-689-ghsa-r2pf-9cw4-5j65-node-opcua-tcp-socket-leak-fin-wait-2-vi</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T16:19:21.000Z</news:publication_date>
      <news:title>GHSA-r2pf-9cw4-5j65: node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-201-cisco-advance-notification-for-publication-of-september-16-2</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T16:07:26.000Z</news:publication_date>
      <news:title>Cisco Advance Notification for Publication of September 16, 2026, Security Advisories</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-pg97-jvmf-qfvc-djust-has-cross-site-request-forgery-on</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T15:45:03.000Z</news:publication_date>
      <news:title>GHSA-pg97-jvmf-qfvc: djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a vict</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2025-599-ghsa-5h8j-6crg-7rmw-lmdeploy-has-remote-code-execution-by-pi</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T15:34:27.000Z</news:publication_date>
      <news:title>GHSA-5h8j-6crg-7rmw: LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdepl</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-3492-cvg7-9mr2-djust-multi-tenant-isolation-fails-open</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T15:32:10.000Z</news:publication_date>
      <news:title>GHSA-3492-cvg7-9mr2: djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-cc7c-9jff-58wj-djust-client-mass-assignment-of-arbitrar</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T13:55:48.000Z</news:publication_date>
      <news:title>GHSA-cc7c-9jff-58wj: djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-811-ghsa-v8pv-4842-x354-opentelemetryresourceshost-vulnerable-to</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T13:54:16.000Z</news:publication_date>
      <news:title>GHSA-v8pv-4842-x354: OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-8g2f-g3gq-5rjv-djusts-observability-endpoints-are-netwo</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T13:49:19.000Z</news:publication_date>
      <news:title>GHSA-8g2f-g3gq-5rjv: djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit,</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-cv3r-c5h8-f4g5-zereightmcp-gitlab-unauthenticated-arbit</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T13:48:28.000Z</news:publication_date>
      <news:title>GHSA-cv3r-c5h8-f4g5: @zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and f</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/15d0eead8856-revolut-data-leak-may-trace-back-to-compromised-italian-gove</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T13:09:22.000Z</news:publication_date>
      <news:title>Revolut Data Leak May Trace Back to Compromised Italian Government Accounts</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-908-parallels-desktop-flaw-hands-any-local-user-root-on-a-mac-cv</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T12:36:30.000Z</news:publication_date>
      <news:title>Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/e20ea668ea42-us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillanc</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T12:00:14.000Z</news:publication_date>
      <news:title>US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-581-vulnerabilities-in-wnc-t-mobile-5g-box-idu-routers</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T11:55:00.000Z</news:publication_date>
      <news:title>Vulnerabilities in WNC T-Mobile 5G Box IDU routers</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/95c0c12b4866-critical-screenconnect-flaw-now-actively-exploited-in-attack</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T11:14:28.000Z</news:publication_date>
      <news:title>Critical ScreenConnect flaw now actively exploited in attacks</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-878-acronis-cpanel-backup-plugin-vulnerability-exploited-in-targ</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T11:08:54.000Z</news:publication_date>
      <news:title>Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/d2f267064e99-google-pixel-owners-urged-to-patch-actively-exploited-modem</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T10:39:04.000Z</news:publication_date>
      <news:title>Google Pixel owners urged to patch actively exploited modem flaw</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/9b75cf997b79-atomic-macos-amos-stealer-activity</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T10:00:06.000Z</news:publication_date>
      <news:title>Atomic macOS (AMOS) Stealer Activity</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/98f91b85111c-attackers-exploit-woocommerce-wholesale-lead-capture-flaw-to</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T05:48:28.000Z</news:publication_date>
      <news:title>Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-543-active-exploitation-attempts-target-wso2-api-manager-jwt-byp</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T05:18:06.000Z</news:publication_date>
      <news:title>Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-2h44-8472-frjj-zereightmcp-gitlab-vulnerable-to-server</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:57:28.000Z</news:publication_date>
      <news:title>GHSA-2h44-8472-frjj: @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-vmp7-252j-cwp7-zereightmcp-gitlab-dns-rebinding-reaches</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:54:55.000Z</news:publication_date>
      <news:title>GHSA-vmp7-252j-cwp7: @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/d00579f62b88-ghsa-5648-rgj9-v224-zereightmcp-gitlab-has-multiple-safety-c</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:48:22.000Z</news:publication_date>
      <news:title>GHSA-5648-rgj9-v224: @zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unau</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-4595-rvpx-4q34-emp3r0r-has-an-unauthenticated-http-poll</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:47:17.000Z</news:publication_date>
      <news:title>GHSA-4595-rvpx-4q34: emp3r0r has an unauthenticated HTTP Polling DoS</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-889-ghsa-gq9p-f254-h286-http4s-ember-http2-buffers-a-frames-decl</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:01:22.000Z</news:publication_date>
      <news:title>GHSA-gq9p-f254-h286: Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-5hq8-qhww-jm7q-libp2p-quic-remote-panic-via-certificate</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:01:17.000Z</news:publication_date>
      <news:title>GHSA-5hq8-qhww-jm7q: libp2p-quic: Remote panic via certificate expiry race during QUIC handshake</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-692-ghsa-cp4q-fqw9-4hf6-http4s-ember-http2-unbounded-continuatio</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:01:08.000Z</news:publication_date>
      <news:title>GHSA-cp4q-fqw9-4hf6: Http4s Ember HTTP/2: unbounded continuation frame accumulation</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-692-ghsa-fm4g-76c9-7w69-http4s-digestauth-nonce-map-grows-unboun</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T19:54:37.000Z</news:publication_date>
      <news:title>GHSA-fm4g-76c9-7w69: Http4s: DigestAuth nonce map grows unbounded</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-692-ghsa-9998-894r-fwvr-http4s-ember-transfer-encoding-value-par</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T19:54:25.000Z</news:publication_date>
      <news:title>GHSA-9998-894r-fwvr: Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/19fccc48359e-iranian-cyber-spies-used-fake-mri-scan-results-to-hack-enemy</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T16:28:00.000Z</news:publication_date>
      <news:title>Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/1c819a001b23-cisco-email-security-boxes-can-be-rooted-by-an-email</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T16:01:00.000Z</news:publication_date>
      <news:title>Cisco email security boxes can be rooted by... an email</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/945dfd469d4a-cisco-warns-customers-of-actively-exploited-zero-day-in-emai</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T15:44:41.000Z</news:publication_date>
      <news:title>Cisco warns customers of actively exploited zero-day in email gateways</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/9ac44d4bac52-texas-utility-centerpoint-energy-confirms-breach-after-hacke</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T15:30:24.000Z</news:publication_date>
      <news:title>Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/7b73757944cf-hackers-target-wordpress-sites-via-third-party-woocommerce-p</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T14:45:10.000Z</news:publication_date>
      <news:title>Hackers target WordPress sites via third-party WooCommerce plugin</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/de73330c7ad2-ransomware-qilin-adm</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T14:39:57.188Z</news:publication_date>
      <news:title>Ransomware: qilin → ADM</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/69e2c62ace55-ncsc-2026-0369-100-mh-kwetsbaarheid-verholpen-in-palo-alto-n</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T13:39:51.000Z</news:publication_date>
      <news:title>NCSC-2026-0369 [1.00] [M/H] Kwetsbaarheid verholpen in Palo Alto Networks PAN-OS</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/de4a5189bc6a-iranian-cyber-targeting-of-dissidents-activists-and-journali</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T12:00:00.000Z</news:publication_date>
      <news:title>Iranian cyber targeting of dissidents, activists and journalists</news:title>
    </news:news>
  </url>
</urlset>