<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://skopnix.com/news/449ec06352ad-bitget-blames-north-korea-for-3875m-crypto-wallet-raid</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T17:04:07.000Z</news:publication_date>
      <news:title>Bitget blames North Korea for $387.5M crypto wallet raid</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-921-ghsa-g7vj-c29h-3h5m-friendsofflarum-oauth-unauthenticated-ac</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T15:55:07.000Z</news:publication_date>
      <news:title>GHSA-g7vj-c29h-3h5m: FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/74ab0bc29886-storm-3168-agentic-driven-cloud-attacks-using-compromised-se</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T15:35:08.000Z</news:publication_date>
      <news:title>Storm-3168: Agentic-driven cloud attacks using compromised service principals</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-574-ghsa-v65j-hff3-753c-mediawiki-embedvideo-extension-has-store</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T15:03:43.000Z</news:publication_date>
      <news:title>GHSA-v65j-hff3-753c: Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-618-ghsa-qxg3-46rw-79j8-code16-sharp-vulnerable-to-stored-xss-vi</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T15:02:11.000Z</news:publication_date>
      <news:title>GHSA-qxg3-46rw-79j8: code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/8b1ba443ae92-bitget-says-suspected-north-korean-hackers-stole-3516m-after</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T10:35:55.000Z</news:publication_date>
      <news:title>Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-488-roundcube-pre-auth-sql-injection-flaw-actively-exploited-in</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T10:14:02.000Z</news:publication_date>
      <news:title>Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/6a804f54cfab-salesbleed-flaws-in-salesforce-agentforce-enabled-zero-click</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T09:27:51.000Z</news:publication_date>
      <news:title>‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-571-ghsa-3c93-f73f-qc9h-social-auth-core-vk-app-backend-accepts</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:57:22.000Z</news:publication_date>
      <news:title>GHSA-3c93-f73f-qc9h: social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-571-ghsa-r4vp-3vw6-r2x5-trestle-is-vulnerable-to-arbitrary-file</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:52:34.000Z</news:publication_date>
      <news:title>GHSA-r4vp-3vw6-r2x5: Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix o</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-597-ghsa-3cj3-hqcr-g934-cline-cross-origin-websocket-hijacking-i</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:48:34.000Z</news:publication_date>
      <news:title>GHSA-3cj3-hqcr-g934: Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-618-ghsa-36h5-qg4p-q2qf-zbatesonmail-mime-parser-has-crlf-header</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:46:32.000Z</news:publication_date>
      <news:title>GHSA-36h5-qg4p-q2qf: zbateson/mail-mime-parser has CRLF header injection via attachment filename</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-618-ghsa-f6v3-2qmr-vfjx-zbatesonmail-mime-parser-has-uncontrolle</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:45:05.000Z</news:publication_date>
      <news:title>GHSA-f6v3-2qmr-vfjx: zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-617-ghsa-jmg2-rcxh-w8q3-rsdoctorrspack-plugin-has-unauthenticate</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:42:10.000Z</news:publication_date>
      <news:title>GHSA-jmg2-rcxh-w8q3: @rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build Metadata</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-572-ghsa-4hq8-gpf5-8p68-podman-malformed-image-can-trick-podman</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:40:20.000Z</news:publication_date>
      <news:title>GHSA-4hq8-gpf5-8p68: Podman: Malformed Image can trick podman run into leaking host environment variables into the container</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-617-ghsa-mwwr-p57h-56pf-bytebasedbhubs-read-only-mode-does-not-p</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:37:59.000Z</news:publication_date>
      <news:title>GHSA-mwwr-p57h-56pf: @bytebase/dbhub's read-only mode does not prevent database writes</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-617-ghsa-fm8p-53ww-hf6w-dbhub-http-transport-dns-rebinding-allow</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:36:57.000Z</news:publication_date>
      <news:title>GHSA-fm8p-53ww-hf6w: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-617-ghsa-cjx3-73hr-rpw7-http4s-scala-xml-has-an-xml-external-ent</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:35:16.000Z</news:publication_date>
      <news:title>GHSA-cjx3-73hr-rpw7: http4s-scala-xml has an XML External Entity (XXE) processing issue</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-567-ghsa-36f9-7rg5-cpf8-bsvwallet-toolbox--client--mobile-dont-v</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:32:00.000Z</news:publication_date>
      <news:title>GHSA-36f9-7rg5-cpf8: `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against c</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-567-ghsa-rw77-vq4g-x3hp-phpmyfaq-has-sql-injection-in-stopwordsa</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:30:07.000Z</news:publication_date>
      <news:title>GHSA-rw77-vq4g-x3hp: phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-567-ghsa-8gpw-xvpf-hvx5-phpmyfaqs-two-factor-authentication-logi</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:29:27.000Z</news:publication_date>
      <news:title>GHSA-8gpw-xvpf-hvx5: phpMyFAQ's two-factor authentication login bypasses the password factor</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-567-ghsa-pgwp-vc7q-cvj3-phpmyfaq-has-stored-xss-in-admin-faq-edi</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:28:43.000Z</news:publication_date>
      <news:title>GHSA-pgwp-vc7q-cvj3: phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/c5b9968833d4-ghsa-g28h-2cmm-rj9x-langchain-nvidia-ai-endpoints-has-local</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:25:36.000Z</news:publication_date>
      <news:title>GHSA-g28h-2cmm-rj9x: langchain-nvidia-ai-endpoints has local file disclosure through VLM image inputs</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-616-ghsa-w3rp-4cm2-4wgc-ixo-blockchain-xbonds-did-resolved-payer</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:22:53.000Z</news:publication_date>
      <news:title>GHSA-w3rp-4cm2-4wgc: ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-617-ghsa-g5f9-3xfg-p9mf-decepticon-role-boundary-forgery-via-cha</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T19:17:49.000Z</news:publication_date>
      <news:title>GHSA-g5f9-3xfg-p9mf: Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM cont</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-634-ghsa-396x-xmvh-p563-snipe-it-stored-xss-via-inline-xml-rende</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T18:19:38.000Z</news:publication_date>
      <news:title>GHSA-396x-xmvh-p563: Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-850-ghsa-9993-rfwp-rhwf-zitadel-mfa-bypass-via-session-reuse-in</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T18:19:35.000Z</news:publication_date>
      <news:title>GHSA-9993-rfwp-rhwf: ZITADEL: MFA bypass via session reuse in Login V2</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-850-ghsa-fgmf-7rf8-m6vf-zitadel-actions-v1-sandbox-escape-host-f</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T18:19:32.000Z</news:publication_date>
      <news:title>GHSA-fgmf-7rf8-m6vf: ZITADEL: Actions V1 sandbox escape: host file read via require()</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-623-ghsa-p9h3-gvpq-5539-snipe-it-stored-xss-via-custom-field-nam</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T18:19:30.000Z</news:publication_date>
      <news:title>GHSA-p9h3-gvpq-5539: Snipe-IT: Stored XSS via Custom Field name in asset-list column headers</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-591-ghsa-6rf4-v2fh-m6p4-suneditor-critical-xss-vulnerability---s</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T14:57:55.000Z</news:publication_date>
      <news:title>GHSA-6rf4-v2fh-m6p4: SunEditor: Critical XSS vulnerability - sanitizer bypass</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/54c1206098ba-kyiv-internet-providers-report-major-outages-after-russian-a</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T13:30:00.000Z</news:publication_date>
      <news:title>Kyiv internet providers report major outages after Russian attacks damage data centers</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/8ae4194eda2b-hackers-now-exploit-critical-roundcube-flaw-in-code-injectio</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T13:27:57.000Z</news:publication_date>
      <news:title>Hackers now exploit critical Roundcube flaw in code injection attacks</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/da7f985e1c2e-one-week-five-flaws-same-weak-point-the-management-layer</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T13:15:42.000Z</news:publication_date>
      <news:title>One Week, Five Flaws, Same Weak Point: The Management Layer</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2024-455-when-business-email-compromise-starts-rewriting-reality</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T13:00:00.000Z</news:publication_date>
      <news:title>When Business Email Compromise Starts Rewriting Reality</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/f90f2426c716-openai-agent-breached-australian-government-health-website-a</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T12:30:00.000Z</news:publication_date>
      <news:title>OpenAI agent breached Australian government health website, Albanese says</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/849a3d02ea1a-cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T10:42:37.000Z</news:publication_date>
      <news:title>CISA: Ransomware gangs now exploiting critical TeamCity flaw</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-820-ncsc-2026-0393-100-mh-kwetsbaarheden-verholpen-in-adobe-camp</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T06:43:17.000Z</news:publication_date>
      <news:title>NCSC-2026-0393 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/639e8904565a-closedquorum-the-malware-that-asks-four-ai-models-what-to-do</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T05:44:13.000Z</news:publication_date>
      <news:title>CLOSEDQUORUM, the malware that asks four AI models what to do next</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/9df47e688838-your-security-program-knows-about-the-firewall-but-does-it-k</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T04:30:14.000Z</news:publication_date>
      <news:title>Your security program knows about the firewall, but does it know about the elevator?</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-566-ghsa-9643-4qgh-g8mx-elysia-has-inefficient-algorithmic-compl</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T21:54:50.000Z</news:publication_date>
      <news:title>GHSA-9643-4qgh-g8mx: elysia has Inefficient Algorithmic Complexity and Interpretation Conflict</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-616-ghsa-wmw4-mw6x-6vfm-reactpress-has-sql-injection-via-dynamic</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T21:51:59.000Z</news:publication_date>
      <news:title>GHSA-wmw4-mw6x-6vfm: ReactPress has SQL injection via dynamic column names in TypeORM query builders</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-773-ghsa-gvf2-2rh5-mpgf-openc3-cosmos-stored-cross-user-xss-via</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T21:24:11.000Z</news:publication_date>
      <news:title>GHSA-gvf2-2rh5-mpgf: OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-824-ghsa-9wh6-9hq7-9688-klever-go-validator-registration-accepts</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T21:24:08.000Z</news:publication_date>
      <news:title>GHSA-9wh6-9hq7-9688: Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-824-ghsa-7c7c-373r-gfjj-klever-go-elasticsearch-bulk-painless-in</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T21:24:06.000Z</news:publication_date>
      <news:title>GHSA-7c7c-373r-gfjj: Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -&gt; explorer/indexer data forgery</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-824-ghsa-26r5-4mm2-px5c-klever-go-zombie-order-theft-buy-missing</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T21:24:03.000Z</news:publication_date>
      <news:title>GHSA-26r5-4mm2-px5c: Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-760-ghsa-9rg8-2wvr-fgjh-formie-missing-authorization-on-sent-not</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T21:24:01.000Z</news:publication_date>
      <news:title>GHSA-9rg8-2wvr-fgjh: Formie: Missing authorization on sent notification resend modal exposes submission PII</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-618-ghsa-w4cm-gvhj-cgw6-jawn-quadratic-parsing-effort-in-asyncpa</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T21:23:58.000Z</news:publication_date>
      <news:title>GHSA-w4cm-gvhj-cgw6: Jawn: Quadratic parsing effort in AsyncParser</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-599-ghsa-cc4v-rvgp-2pf3-jawn-uncontrolled-nesting-depth-in-json</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T21:23:54.000Z</news:publication_date>
      <news:title>GHSA-cc4v-rvgp-2pf3: Jawn: Uncontrolled nesting depth in JSON parser</news:title>
    </news:news>
  </url>
</urlset>