<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://skopnix.com/news/09d722e77700-rathat-android-malware-abuses-adb-to-retain-shell-access-aft</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T06:17:25.000Z</news:publication_date>
      <news:title>RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-726-ghsa-jq29-c7v8-rg55-grav-path-traversal-in-mediauploadtraitd</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:34:05.000Z</news:publication_date>
      <news:title>GHSA-jq29-c7v8-rg55: Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-860-ghsa-9gm5-9rfh-m6vx-coredns-dohdoqgrpc-bypass-update-rejecti</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:33:05.000Z</news:publication_date>
      <news:title>GHSA-9gm5-9rfh-m6vx: CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-849-ghsa-x424-64qh-5j54-reacthttp-a-malformed-http-chunked-body</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:32:39.000Z</news:publication_date>
      <news:title>GHSA-x424-64qh-5j54: react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-823-ghsa-mrg3-qvqr-jw29-coredns-unauthenticated-memory-exhaustio</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:32:27.000Z</news:publication_date>
      <news:title>GHSA-mrg3-qvqr-jw29: CoreDNS: Unauthenticated memory exhaustion in custom transports</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-818-ghsa-gq9c-wmrm-5hvr-hapi-fhir-shcparser-deflate-infinite-loo</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:32:21.000Z</news:publication_date>
      <news:title>GHSA-gq9c-wmrm-5hvr: HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/2eda29781a34-ghsa-xjw9-38cr-6372-djust-a-template-binding-inherits-a-cont</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:31:48.000Z</news:publication_date>
      <news:title>GHSA-xjw9-38cr-6372: djust: A template binding inherits a context safety grant it never earned (XSS)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/351960610260-ghsa-9395-2g46-rj3f-djust-six-template-layer-defects-emit-at</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:31:43.000Z</news:publication_date>
      <news:title>GHSA-9395-2g46-rj3f: djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-815-ghsa-67c9-f6v2-qv86-steeltoediscoveryconsul-malformed-secure</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:30:54.000Z</news:publication_date>
      <news:title>GHSA-67c9-f6v2-qv86: Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-815-ghsa-hr73-3gpv-hh6q-steeltoediscoveryeureka-malformed-enumbo</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:30:45.000Z</news:publication_date>
      <news:title>GHSA-hr73-3gpv-hh6q: Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-860-ghsa-c3mw-737p-c7g2-jupyter-server-5xx-request-logging-leaks</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:28:55.000Z</news:publication_date>
      <news:title>GHSA-c3mw-737p-c7g2: Jupyter Server: 5xx request logging leaks token-bearing Referer header values</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-797-ghsa-vjqc-q4mp-2rvf-cakephp-multiple-methods-in-functionsbui</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:28:14.000Z</news:publication_date>
      <news:title>GHSA-vjqc-q4mp-2rvf: CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-768-ghsa-3jhr-mxmx-38cx-grav-userinterface-offsetgetoffsetexists</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:27:30.000Z</news:publication_date>
      <news:title>GHSA-3jhr-mxmx-38cx: Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashe</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-768-ghsa-xjw5-q542-3vmr-grav-configdeniedpaths-default-list-omit</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:27:05.000Z</news:publication_date>
      <news:title>GHSA-xjw5-q542-3vmr: Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-726-ghsa-p597-crqc-m349-grav-the-system-site-and-theme-twig-vari</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:25:42.000Z</news:publication_date>
      <news:title>GHSA-p597-crqc-m349: Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-451-ghsa-g4c3-4g96-6g4m-chamilo-lms-cstudio-upload-flow-allows-u</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T20:23:39.000Z</news:publication_date>
      <news:title>GHSA-g4c3-4g96-6g4m: Chamilo LMS CStudio upload flow allows unauthenticated remote code execution</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/4827eb308ee7-ransomware-ransomhouse-pertamina</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T19:40:27.039Z</news:publication_date>
      <news:title>Ransomware: ransomhouse → Pertamina</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/8b15373ec47a-ransomware-brain-cipher-aecomcom</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T18:36:59.093Z</news:publication_date>
      <news:title>Ransomware: brain cipher → aecom.com</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-201-al26-021---vulnerabilities-impacting-cisco-identity-services</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T17:32:01.000Z</news:publication_date>
      <news:title>AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-857-ghsa-mggc-4xg6-vcxf-sshnet-scpclient-allows-server-side-rce</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T17:18:01.000Z</news:publication_date>
      <news:title>GHSA-mggc-4xg6-vcxf: SSH.NET: ScpClient allows server-side RCE via default SCP path handling</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-656-ghsa-c4wf-2xxc-68qm-grav-flexdirectorydynamicdatafield-execu</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T17:15:33.000Z</news:publication_date>
      <news:title>GHSA-c4wf-2xxc-68qm: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-860-ghsa-5gpm-rgj3-9q76-skipper-has-opa-body-authz-bypass-trunca</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T17:05:57.000Z</news:publication_date>
      <news:title>GHSA-5gpm-rgj3-9q76: Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-774-ghsa-c5pq-fr2g-9jpf-rabbitmq-amqp091-go-protocol-desynchroni</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T17:04:25.000Z</news:publication_date>
      <news:title>GHSA-c5pq-fr2g-9jpf: RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-774-ghsa-r9c8-gcjp-xfwh-rabbitmq-amqp091-go-resource-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T17:04:20.000Z</news:publication_date>
      <news:title>GHSA-r9c8-gcjp-xfwh: RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-774-ghsa-j497-x9hr-x34x-rabbitmq-amqp091-go-silent-data-truncati</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T17:04:15.000Z</news:publication_date>
      <news:title>GHSA-j497-x9hr-x34x: RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-774-ghsa-33mj-cw25-m34h-rabbitmq-amqp091-go-missing-explicit-tls</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T17:04:01.000Z</news:publication_date>
      <news:title>GHSA-33mj-cw25-m34h: RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-774-ghsa-465g-fh3v-9jw4-rabbitmq-amqp091-go-connection-configura</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T17:03:55.000Z</news:publication_date>
      <news:title>GHSA-465g-fh3v-9jw4: RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-774-ghsa-xwwf-m8fg-p9q2-rabbitmq-amqp091-go-denial-of-service-vi</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T17:03:50.000Z</news:publication_date>
      <news:title>GHSA-xwwf-m8fg-p9q2: RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-691-ghsa-wr57-hqmp-fgvh-umbraco-delivery-api-leaks-protected-pub</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T16:29:46.000Z</news:publication_date>
      <news:title>GHSA-wr57-hqmp-fgvh: Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/43429be03088-iranian-strikes-on-aws-facilities-left-customer-data-beyond</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T13:12:47.000Z</news:publication_date>
      <news:title>Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-816-critical-unbound-dnssec-validator-flaw-could-allow-rce-via-a</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T12:30:00.000Z</news:publication_date>
      <news:title>Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/73645a02bd83-ransomware-incidents-in-japan-in-the-first-half-of-2026-inve</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T10:00:43.000Z</news:publication_date>
      <news:title>Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/0c9ce14ba6c6-chinese-hackers-use-sparrowocky-malware-in-govt-espionage-at</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T09:00:00.000Z</news:publication_date>
      <news:title>Chinese hackers use SparroWocky malware in govt espionage attacks</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/2e4be0073b4d-fragnesia-primitive-via-open-vswitch-deterministic-local-pri</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T07:06:38.000Z</news:publication_date>
      <news:title>Fragnesia primitive via Open vSwitch. Deterministic local privilege escalation.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-636-ghsa-mxm6-v9r6-r94c-nuxtjsmdcs-url-sanitizer-misses-svg-xlin</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T22:14:01.000Z</news:publication_date>
      <news:title>GHSA-mxm6-v9r6-r94c: @nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-631-ghsa-9pj6-vhgr-3mwh-rmcp-unauthenticated-permanent-session-t</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T22:13:34.000Z</news:publication_date>
      <news:title>GHSA-9pj6-vhgr-3mwh: RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote de</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-631-ghsa-33f5-2c5q-wgwj-rmcp-missing-resource-field-validation-i</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T22:13:26.000Z</news:publication_date>
      <news:title>GHSA-33f5-2c5q-wgwj: RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-7prp-2623-8g45-djust-has-an-unauthenticated-arbitrary-m</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T22:09:38.000Z</news:publication_date>
      <news:title>GHSA-7prp-2623-8g45: djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-c7c5-5j6r-q957-djust-has-broken-object-level-access-con</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T22:06:02.000Z</news:publication_date>
      <news:title>GHSA-c7c5-5j6r-q957: djust has broken object-level access control (IDOR)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-689-ghsa-r2pf-9cw4-5j65-node-opcua-tcp-socket-leak-fin-wait-2-vi</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T16:19:21.000Z</news:publication_date>
      <news:title>GHSA-r2pf-9cw4-5j65: node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-201-cisco-advance-notification-for-publication-of-september-16-2</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T16:07:26.000Z</news:publication_date>
      <news:title>Cisco Advance Notification for Publication of September 16, 2026, Security Advisories</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-pg97-jvmf-qfvc-djust-has-cross-site-request-forgery-on</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T15:45:03.000Z</news:publication_date>
      <news:title>GHSA-pg97-jvmf-qfvc: djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a vict</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2025-599-ghsa-5h8j-6crg-7rmw-lmdeploy-has-remote-code-execution-by-pi</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T15:34:27.000Z</news:publication_date>
      <news:title>GHSA-5h8j-6crg-7rmw: LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdepl</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-3492-cvg7-9mr2-djust-multi-tenant-isolation-fails-open</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T15:32:10.000Z</news:publication_date>
      <news:title>GHSA-3492-cvg7-9mr2: djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-cc7c-9jff-58wj-djust-client-mass-assignment-of-arbitrar</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T13:55:48.000Z</news:publication_date>
      <news:title>GHSA-cc7c-9jff-58wj: djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-811-ghsa-v8pv-4842-x354-opentelemetryresourceshost-vulnerable-to</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T13:54:16.000Z</news:publication_date>
      <news:title>GHSA-v8pv-4842-x354: OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-8g2f-g3gq-5rjv-djusts-observability-endpoints-are-netwo</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T13:49:19.000Z</news:publication_date>
      <news:title>GHSA-8g2f-g3gq-5rjv: djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit,</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-615-ghsa-cv3r-c5h8-f4g5-zereightmcp-gitlab-unauthenticated-arbit</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T13:48:28.000Z</news:publication_date>
      <news:title>GHSA-cv3r-c5h8-f4g5: @zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and f</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/15d0eead8856-revolut-data-leak-may-trace-back-to-compromised-italian-gove</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T13:09:22.000Z</news:publication_date>
      <news:title>Revolut Data Leak May Trace Back to Compromised Italian Government Accounts</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-908-parallels-desktop-flaw-hands-any-local-user-root-on-a-mac-cv</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T12:36:30.000Z</news:publication_date>
      <news:title>Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/e20ea668ea42-us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillanc</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T12:00:14.000Z</news:publication_date>
      <news:title>US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-581-vulnerabilities-in-wnc-t-mobile-5g-box-idu-routers</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T11:55:00.000Z</news:publication_date>
      <news:title>Vulnerabilities in WNC T-Mobile 5G Box IDU routers</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/95c0c12b4866-critical-screenconnect-flaw-now-actively-exploited-in-attack</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T11:14:28.000Z</news:publication_date>
      <news:title>Critical ScreenConnect flaw now actively exploited in attacks</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/CVE-2026-878-acronis-cpanel-backup-plugin-vulnerability-exploited-in-targ</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T11:08:54.000Z</news:publication_date>
      <news:title>Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://skopnix.com/news/d2f267064e99-google-pixel-owners-urged-to-patch-actively-exploited-modem</loc>
    <news:news>
      <news:publication>
        <news:name>skopnix</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T10:39:04.000Z</news:publication_date>
      <news:title>Google Pixel owners urged to patch actively exploited modem flaw</news:title>
    </news:news>
  </url>
</urlset>