<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://skopnix.com/news/cfe7f416ead5-north-korean-waterplum-hackers-infected-30000-devices-worldw</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-19T14:05:15.000Z</news:publication_date>
      <news:title>North Korean WaterPlum hackers infected 30,000 devices worldwide</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/7f63da933d72-ransomware-emperador-cassias-mg-government</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-19T07:50:51.612Z</news:publication_date>
      <news:title>Ransomware: emperador → Cassias MG Government</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/bf0f679dfdf4-crowdsec-says-tanstack-npm-attack-led-to-copy-of-170-private</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-19T07:14:54.000Z</news:publication_date>
      <news:title>CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/c43f571812de-ransomware-n0n-inter-venezuelas-largest-internet-provider</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T19:51:07.604Z</news:publication_date>
      <news:title>Ransomware: N0n → Inter (Venezuela's largest internet provider)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/4d3f93dab4e8-ghsa-jgh3-fggc-mcpm-obot-server-side-request-forgery-via-rem</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:59:46.000Z</news:publication_date>
      <news:title>GHSA-jgh3-fggc-mcpm: Obot: Server-Side Request Forgery via remote MCP server URL</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/f96cff121e40-ghsa-xwmw-prc4-v3cr-obot-oauth-dynamic-client-registration-e</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:59:35.000Z</news:publication_date>
      <news:title>GHSA-xwmw-prc4-v3cr: Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-850-ghsa-9jjc-fw8x-fmwx-iomoquettemoquette-broker-has-a-missing</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:58:39.000Z</news:publication_date>
      <news:title>GHSA-9jjc-fw8x-fmwx: io.moquette:moquette-broker has a Missing Authorization issue</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-591-ghsa-xcw4-53cc-hv32-mnemosyne-has-jwt-signature-verification</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:54:26.000Z</news:publication_date>
      <news:title>GHSA-xcw4-53cc-hv32: Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2025-399-cisa-adds-cve-2025-39964-linux-kernel-to-the-known-exploited</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:51:17.459Z</news:publication_date>
      <news:title>CISA adds CVE-2025-39964 (Linux Kernel) to the Known Exploited Vulnerabilities catalog</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-634-ghsa-vr5f-w35q-98jp-persess-unvalidated-project-parameter-en</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:40:03.000Z</news:publication_date>
      <news:title>GHSA-vr5f-w35q-98jp: Perses's unvalidated project parameter enables filesystem path traversal</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-631-ghsa-4227-9989-jrhx-persess-missing-authorization-in-datasou</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:39:48.000Z</news:publication_date>
      <news:title>GHSA-4227-9989-jrhx: Perses's missing authorization in datasource proxy allows cross-scope secret disclosure</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-634-ghsa-cjgj-2fwf-4c2w-persess-project-query-parameter-authoriz</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:39:31.000Z</news:publication_date>
      <news:title>GHSA-cjgj-2fwf-4c2w: Perses's project query parameter authorization bypass exposes cross-project resources</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-911-ghsa-3753-m2x2-q623-file-viewer-dom-xss-via-unsafe-hyperlink</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:19:42.000Z</news:publication_date>
      <news:title>GHSA-3753-m2x2-q623: File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-773-ghsa-7q85-xj36-vmfc-adm-zip-uncontrolled-memory-allocation-v</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:18:01.000Z</news:publication_date>
      <news:title>GHSA-7q85-xj36-vmfc: adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-815-ghsa-p5vg-v7mj-f6q4-convoy-cross-tenant-source-idor-leaks-pl</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:17:45.000Z</news:publication_date>
      <news:title>GHSA-p5vg-v7mj-f6q4: Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-633-ghsa-3w57-8xmc-8v26-anyio-runprocessopenprocess-ignores-extr</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:17:23.000Z</news:publication_date>
      <news:title>GHSA-3w57-8xmc-8v26: AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-633-ghsa-82r6-8w77-94w6-anyio-tlsstream-idna-2003-host-name-enco</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:17:18.000Z</news:publication_date>
      <news:title>GHSA-82r6-8w77-94w6: AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-581-ghsa-qg2g-g9w3-m5h8-toolhive-containerized-mcp-servers-can-r</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:16:02.000Z</news:publication_date>
      <news:title>GHSA-qg2g-g9w3-m5h8: ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movemen</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-616-ghsa-c8w2-fgvx-vhv4-kcp-front-proxy-does-not-strip-inbound-x</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:15:49.000Z</news:publication_date>
      <news:title>GHSA-c8w2-fgvx-vhv4: kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to injec</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-618-ghsa-qg67-7m6v-qg25-zot-bearer-authentication-maps-delete-to</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:15:19.000Z</news:publication_date>
      <news:title>GHSA-qg67-7m6v-qg25: zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-616-ghsa-gjw4-3v3v-rqxg-capsule-tenant-owner-bypasses-capsules-f</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:14:31.000Z</news:publication_date>
      <news:title>GHSA-gjw4-3v3v-rqxg: Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/f2698508a080-ghsa-39wr-7q6h-cf68-lmdeploy-has-an-ssrf-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:14:06.000Z</news:publication_date>
      <news:title>GHSA-39wr-7q6h-cf68: LMDeploy has an SSRF bypass</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-336-ghsa-3hmm-rh5q-gwwr-lmdeploy-vulnerable-to-arbitrary-code-ex</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T17:04:01.000Z</news:publication_date>
      <news:title>GHSA-3hmm-rh5q-gwwr: LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/7a18a6d2c0ee-ghsa-jr78-w6w5-m8f8-semantic-mediawikia-missing-authorizatio</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T16:59:31.000Z</news:publication_date>
      <news:title>GHSA-jr78-w6w5-m8f8: Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-on</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/166156784f3b-ransomware-n0n-astrazeneca-turkiye</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T16:04:30.007Z</news:publication_date>
      <news:title>Ransomware: n0n → AstraZeneca Türkiye</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/0c5081a0f2d7-ransomware-n0n-paypal-support-operations-transcom-worldwide</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T16:01:08.759Z</news:publication_date>
      <news:title>Ransomware: n0n → PayPal support operations (Transcom WorldWide)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2025-538-ghsa-26vp-8gxg-v4pg-orgxwikirenderingxwiki-rendering-xml-has</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T15:05:13.000Z</news:publication_date>
      <news:title>GHSA-26vp-8gxg-v4pg: org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/010c0e6e5698-ransomware-endzone-att</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T14:33:06.912Z</news:publication_date>
      <news:title>Ransomware: endzone → AT&amp;T</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/a4aa43a6286b-weaselbiscuit-stealer-spreads-via-13-npm-packages-to-harvest</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T10:40:06.000Z</news:publication_date>
      <news:title>WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/e153090477ba-a-vault-with-a-heap-view-the-uncomfortable-space-between-age</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T10:00:36.000Z</news:publication_date>
      <news:title>A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/408ef5d66470-brevo-supply-chain-attack-injects-malware-into-100000-websit</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T09:46:57.000Z</news:publication_date>
      <news:title>Brevo Supply Chain Attack Injects Malware Into 100,000 Websites</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/46d085b9d44f-new-check-point-flaw-lets-hackers-execute-code-with-root-pri</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T09:34:33.000Z</news:publication_date>
      <news:title>New Check Point flaw lets hackers execute code with root privileges</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/96f5f817f677-zero-click-rce-vulnerability-hit-four-major-ai-coding-agents</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T08:49:00.000Z</news:publication_date>
      <news:title>Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-581-critical-orkes-conductor-vulnerability-exploited-in-attacks</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T08:42:18.000Z</news:publication_date>
      <news:title>Critical Orkes Conductor Vulnerability Exploited in Attacks</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/09d722e77700-rathat-android-malware-abuses-adb-to-retain-shell-access-aft</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T06:17:25.000Z</news:publication_date>
      <news:title>RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall</news:title>
    </news:news>
  </url>
</urlset>