<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://skopnix.com/news/CVE-2026-550-rapid7-analysis-microsoft-sharepoint-jwt-token-authenticatio</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-27T14:17:19.289Z</news:publication_date>
      <news:title>Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/7a588a29884d-that-reddit-rumor-about-citrix-notifying-customers-to-take-n</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T22:14:57.000Z</news:publication_date>
      <news:title>That Reddit rumor about Citrix notifying customers to take Netscaler servers offline because of actively exploited zero-days is apparently real: https://www. reddit.com/r/Citrix/co</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/06ab9a4d91a4-elementor-csrf-flaw-lets-attackers-take-over-sites-after-adm</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T09:55:22.000Z</news:publication_date>
      <news:title>Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-352-shinyhunters-targets-education-sector-with-oracle-peoplesoft</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T00:52:11.045Z</news:publication_date>
      <news:title>ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-574-ghsa-q986-4x7x-gx39-scbe-aethermoore-unauthenticated-aetherb</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T21:48:03.000Z</news:publication_date>
      <news:title>GHSA-q986-4x7x-gx39: SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/6073b2d64854-ghsa-vj8p-hp9x-gh47-mpp-vulnerable-to-gas-draining-with-low</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T21:47:36.000Z</news:publication_date>
      <news:title>GHSA-vj8p-hp9x-gh47: mpp vulnerable to Gas Draining with low gas limit</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-100-ghsa-wrvw-254r-wpmv-cliinvokespecializations-has-command-inj</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T21:41:48.000Z</news:publication_date>
      <news:title>GHSA-wrvw-254r-wpmv: CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-100-ghsa-j73w-8hfr-4gc9-cliinvoke-argument-injection-in-extensib</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T21:41:36.000Z</news:publication_date>
      <news:title>GHSA-j73w-8hfr-4gc9: CliInvoke: Argument Injection in Extensibility Runner Factory</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/bdcdb2d24781-kiteworks-urges-6-hour-server-shutdown-over-potential-zero-d</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T21:41:07.000Z</news:publication_date>
      <news:title>Kiteworks urges 6-hour server shutdown over potential zero-day attacks</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/ceecedb340d7-ghsa-62mm-xwmv-crhg-khoj-has-an-unauthenticated-path-travers</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T21:38:15.000Z</news:publication_date>
      <news:title>GHSA-62mm-xwmv-crhg: khoj has an unauthenticated path traversal in /home/ endpoint that allows file read from server filesystem</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/483bc5c8d70e-ghsa-29h2-jr22-frmh-openzeppelin-confidential-contracts-vest</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T19:31:08.000Z</news:publication_date>
      <news:title>GHSA-29h2-jr22-frmh: OpenZeppelin Confidential Contracts `VestingWalletConfidential`: a malicious ERC-7984 token is able to extract</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/821a58d5ae59-ransomware-metaencryptor-ge-vernova-inc</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T19:01:27.889Z</news:publication_date>
      <news:title>Ransomware: metaencryptor → GE Vernova Inc.</news:title>
    </news:news>
  </url>
</urlset>