<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://skopnix.com/news/CVE-2026-911-ghsa-wx4m-69m9-gx3m-home-assistant-xss-in-statistics-graph-c</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T20:40:55.000Z</news:publication_date>
      <news:title>GHSA-wx4m-69m9-gx3m: Home Assistant: XSS in Statistics Graph Card</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-857-ghsa-vv3m-f8x4-7377-lightrag-hku-ssrf-via-ipv6-transition-ad</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T20:40:25.000Z</news:publication_date>
      <news:title>GHSA-vv3m-f8x4-7377: lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown im</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-857-ghsa-frch-4w6v-q5xx-lightrag-hku-no-rate-limiting-on-login-e</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T20:40:22.000Z</news:publication_date>
      <news:title>GHSA-frch-4w6v-q5xx: lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-775-ghsa-328g-jx67-v94g-tinyauth-forward-auth-per-app-acl-is-mat</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T20:37:08.000Z</news:publication_date>
      <news:title>GHSA-328g-jx67-v94g: Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, lettin</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-623-ghsa-5jpj-293f-rhvj-kubeedge-command-injection-in-nodeupgrad</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T20:37:04.000Z</news:publication_date>
      <news:title>GHSA-5jpj-293f-rhvj: KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-623-ghsa-9vm9-pqxx-x83v-kubeedge-keadm-decompresstargz-path-trav</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T20:36:59.000Z</news:publication_date>
      <news:title>GHSA-9vm9-pqxx-x83v: KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-631-ghsa-34fc-gh42-pj53-openbaos-recovery-mode-vulnerable-to-tok</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T20:36:51.000Z</news:publication_date>
      <news:title>GHSA-34fc-gh42-pj53: OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-715-ghsa-59w7-v8rr-pr4p-openbaos-templated-policies-allow-privil</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T20:36:49.000Z</news:publication_date>
      <news:title>GHSA-59w7-v8rr-pr4p: OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-621-ghsa-m3c6-2p7h-cfr3-kubeedge-configupdatejob-updatefields-en</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T20:36:44.000Z</news:publication_date>
      <news:title>GHSA-m3c6-2p7h-cfr3: KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-772-ghsa-93xw-j965-9mx3-mcp-atlassian-arbitrary-file-readexfiltr</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T20:36:37.000Z</news:publication_date>
      <news:title>GHSA-93xw-j965-9mx3: MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-566-ghsa-5mj8-gf6m-fhw8-9router-has-an-authentication-bypass-in</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T16:34:06.000Z</news:publication_date>
      <news:title>GHSA-5mj8-gf6m-fhw8: 9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/4bf76d623443-check-point-warns-of-management-server-zero-day-exploited-in</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T16:32:47.000Z</news:publication_date>
      <news:title>Check Point warns of Management Server zero-day exploited in attacks</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/bbe00974ebe1-eviltokens-phaas-disrupted-after-compromising-12000-microsof</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T15:00:00.000Z</news:publication_date>
      <news:title>EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/1bbc2c4488af-unmasking-eviltokens-getting-to-the-root-of-device-code-phis</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T15:00:00.000Z</news:publication_date>
      <news:title>Unmasking EvilTokens: Getting to the root of device code phishing</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-582-ghsa-92cr-jxw4-5wjg-sync-in-server-has-a-complete-2fa-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T14:46:30.000Z</news:publication_date>
      <news:title>GHSA-92cr-jxw4-5wjg: Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-616-ghsa-jjhp-8crj-mppq-roomi-fieldsnotebooklm-mcp-has-a-path-tr</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T14:43:26.000Z</news:publication_date>
      <news:title>GHSA-jjhp-8crj-mppq: @roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/5daab5673438-ncsc-2026-0386-100-hh-kwetsbaarheid-verholpen-in-f5-networks</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T14:39:41.000Z</news:publication_date>
      <news:title>NCSC-2026-0386 [1.00] [H/H] Kwetsbaarheid verholpen in F5 Networks BIG-IP Access Policy Manager</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/21e9d048815c-recent-zyxel-switch-vulnerability-exploited-by-chinese-hacke</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T11:55:20.000Z</news:publication_date>
      <news:title>Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/f7013485135e-ransomware-qilin-columbus-informatica</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T11:41:44.805Z</news:publication_date>
      <news:title>Ransomware: qilin → Columbus Informatica</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-897-new-linux-kernel-flaw-gives-arm64-kvm-guests-read-write-acce</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T11:38:40.000Z</news:publication_date>
      <news:title>New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/55a3a0ffa997-malicious-b-tree-npm-package-accumulates-millions-of-downloa</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T11:33:59.000Z</news:publication_date>
      <news:title>Malicious B-tree NPM Package Accumulates Millions of Downloads</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-656-sharepoint-flaw-initially-listed-as-spoofing-by-microsoft-en</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T11:17:41.000Z</news:publication_date>
      <news:title>SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/c82b46f73d01-researchers-have-spotted-a-campaign-targeting-iranian-dissid</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T11:00:54.000Z</news:publication_date>
      <news:title>Researchers have spotted a campaign targeting Iranian dissidents in June that tried to deploy the ParsaStealer infostealer on users' devices https:// labs.infoguard.ch/posts/iranop</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/328603788eb7-public-poc-exposes-critical-veeam-agent-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T10:13:28.000Z</news:publication_date>
      <news:title>Public PoC Exposes Critical Veeam Agent Privilege Escalation</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/4c4cb6380811-the-closed-quorum-inside-the-first-reported-autonomous-ai-c2</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T10:00:58.000Z</news:publication_date>
      <news:title>The Closed Quorum: Inside the first reported autonomous AI C2 implant</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/9ec5079fab2a-new-windows-defender-zero-day-blocks-microsoft-antivirus-upd</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T09:55:11.000Z</news:publication_date>
      <news:title>New Windows Defender zero-day blocks Microsoft antivirus updates</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/b8f1171f5339-malicious-npm-package-indexed-btree-hid-its-loader-in-runtim</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T09:38:18.000Z</news:publication_date>
      <news:title>Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/3ddf58e86eff-cisa-orders-feds-to-patch-zyxel-flaw-exploited-for-data-thef</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T08:53:09.000Z</news:publication_date>
      <news:title>CISA orders feds to patch Zyxel flaw exploited for data theft</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/a51bfa53bb0a-japan-dismantles-first-north-korean-laptop-farm-as-us-and-al</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T08:37:06.000Z</news:publication_date>
      <news:title>Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/8ccc97a0b799-sidecopy-broadens-india-targeting-to-academia-with-reversera</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T07:52:03.000Z</news:publication_date>
      <news:title>SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-616-ghsa-pxcx-fv34-x9p5-nginx-ignition-has-unauthenticated-admin</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T21:54:42.000Z</news:publication_date>
      <news:title>GHSA-pxcx-fv34-x9p5: nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-616-ghsa-jr34-h97m-9hpx-nginx-ignition-has-parseacceptlanguage-s</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T21:49:03.000Z</news:publication_date>
      <news:title>GHSA-jr34-h97m-9hpx: nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Lan</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-727-cisa-adds-cve-2026-7273-zyxel-gs1900-series-switches-to-the</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T19:43:55.051Z</news:publication_date>
      <news:title>CISA adds CVE-2026-7273 (Zyxel GS1900 Series Switches) to the Known Exploited Vulnerabilities catalog</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-616-ghsa-phg3-3g28-wq9v-hatchet---unauthenticated-oauth-state-cs</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T15:47:01.000Z</news:publication_date>
      <news:title>GHSA-phg3-3g28-wq9v: Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/hefte-AZ-202-weekly-brief-azerbaijan-2026-w39</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T13:21:38.282Z</news:publication_date>
      <news:title>Weekly brief — Azerbaijan (2026-W39)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/AZ-2026-W39-weekly-exposure-digest-azerbaijan-2026-w39</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T13:21:34.733Z</news:publication_date>
      <news:title>Weekly exposure digest — Azerbaijan (2026-W39)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/c64188f52a80-rathat-android-trojan-uses-ai-for-automation</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T12:51:41.000Z</news:publication_date>
      <news:title>RatHat Android Trojan Uses AI for Automation</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/e8a3b2edefd8-north-koreas-job-interview-scam-runs-both-ways</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T12:27:05.000Z</news:publication_date>
      <news:title>North Korea’s job interview scam runs both ways</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/235c3bfe61f7-crowdsec-confirms-source-code-stolen-in-supply-chain-attack</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T10:55:46.000Z</news:publication_date>
      <news:title>CrowdSec Confirms Source Code Stolen in Supply Chain Attack</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/24ce00a91522-terminalfix-png-steganography-mon-sep-21st</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T10:33:53.000Z</news:publication_date>
      <news:title>TerminalFix: PNG Steganography, (Mon, Sep 21st)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/63aa8c538632-rustaceans-warned-of-job-interviews-with-a-malicious-payload</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T10:33:00.000Z</news:publication_date>
      <news:title>Rustaceans warned of job interviews with a malicious payload</news:title>
    </news:news>
  </url>
</urlset>