<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://0daynews.com/articles/2026-08-22-defender-btr-sys-boot-driver-security-bypass/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-22T07:30:00.000Z</news:publication_date>
      <news:title>Defender&apos;s Own Boot Driver Can Kill Security Software</news:title>
      <news:keywords>microsoft defender, BTR.sys, living off the land, endpoint security, EDR bypass, windows, lolbin</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-22-defender-btr-sys-boot-driver-security-bypass/cover.jpg</image:loc>
      <image:title>Defender&apos;s Own Boot Driver Can Kill Security Software</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-22-redc2-npm-backdoor-supply-chain/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-22T06:00:00.000Z</news:publication_date>
      <news:title>AI-Powered RedC2 Backdoor Hidden in 14 npm Packages</news:title>
      <news:keywords>npm, supply chain attack, RedC2, Linux backdoor, TrendAI, trojanized packages, malware</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-22-redc2-npm-backdoor-supply-chain/cover.jpg</image:loc>
      <image:title>AI-Powered RedC2 Backdoor Hidden in 14 npm Packages</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-22-sickkids-hospital-data-breach-third-party/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-22T04:00:00.000Z</news:publication_date>
      <news:title>SickKids Hit Again: Data Theft via Third-Party App</news:title>
      <news:keywords>SickKids, Hospital for Sick Children, healthcare breach, data theft, third-party vendor, Canada</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-22-sickkids-hospital-data-breach-third-party/cover.jpg</image:loc>
      <image:title>SickKids Hit Again: Data Theft via Third-Party App</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-21-entra-id-cve-2026-69836-cvss10-kev/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T22:00:00.000Z</news:publication_date>
      <news:title>Entra ID CVE-2026-69836: CVSS 10, Exploited, KEV</news:title>
      <news:keywords>microsoft, entra-id, cve-2026-69836, deserialization, rce, kev, cisa</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-21-entra-id-cve-2026-69836-cvss10-kev/cover.jpg</image:loc>
      <image:title>Entra ID CVE-2026-69836: CVSS 10, Exploited, KEV</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-21-russian-unc-clusters-oauth-whatsapp-hijack/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T04:30:00.000Z</news:publication_date>
      <news:title>Russian Clusters Exploit OAuth Flows to Hijack Accounts</news:title>
      <news:keywords>russian-apt, oauth, google-oauth, whatsapp, espionage, account-hijacking, unc6293</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-21-russian-unc-clusters-oauth-whatsapp-hijack/cover.jpg</image:loc>
      <image:title>Russian Clusters Exploit OAuth Flows to Hijack Accounts</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-21-zimbra-snmp-rce-exploited/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T02:00:00.000Z</news:publication_date>
      <news:title>Zimbra SNMP RCE Now Exploited in the Wild</news:title>
      <news:keywords>zimbra, CVE-2026-73570, SNMP, RCE, command-injection, active-exploitation, CERT-Polska</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-21-zimbra-snmp-rce-exploited/cover.jpg</image:loc>
      <image:title>Zimbra SNMP RCE Now Exploited in the Wild</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-20-rust-arrayref-supply-chain-infostealer/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T00:10:00.000Z</news:publication_date>
      <news:title>Backdoored Rust Crates Delivered Infostealer at Build Time</news:title>
      <news:keywords>rust, crates-io, supply-chain, infostealer, build-time-malware, arrayref, software-supply-chain</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-20-rust-arrayref-supply-chain-infostealer/cover.jpg</image:loc>
      <image:title>Backdoored Rust Crates Delivered Infostealer at Build Time</image:title>
    </image:image>
  </url>
</urlset>