<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://0daynews.com/articles/2026-07-28-linux-kernel-tc-cve-2026-53264-lpe/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T11:00:00.000Z</news:publication_date>
      <news:title>Linux Kernel tc Race Yields Root Exploit (CVSS 7.8)</news:title>
      <news:keywords>CVE-2026-53264, linux-kernel, privilege-escalation, use-after-free, race-condition, traffic-control, STAR-Labs</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-28-linux-kernel-tc-cve-2026-53264-lpe/cover.jpg</image:loc>
      <image:title>Linux Kernel tc Race Yields Root Exploit (CVSS 7.8)</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-28-mcbs-medical-billing-breach-1-26m/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T10:30:00.000Z</news:publication_date>
      <news:title>MCBS Medical Billing Breach Exposes 1.26M Records</news:title>
      <news:keywords>data breach, healthcare, MCBS, medical billing, PII, HIPAA</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-28-mcbs-medical-billing-breach-1-26m/cover.jpg</image:loc>
      <image:title>MCBS Medical Billing Breach Exposes 1.26M Records</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-28-teamcity-cve-2026-63077-rce-all-onprem/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T10:00:00.000Z</news:publication_date>
      <news:title>TeamCity 9.8 RCE Flaw Hits All On-Prem Versions</news:title>
      <news:keywords>teamcity, jetbrains, CVE-2026-63077, RCE, critical, on-premises, patch</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-28-teamcity-cve-2026-63077-rce-all-onprem/cover.jpg</image:loc>
      <image:title>TeamCity 9.8 RCE Flaw Hits All On-Prem Versions</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-28-microsoft-mai-cyber-1-flash-mdash-security-ai/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T07:00:00.000Z</news:publication_date>
      <news:title>Microsoft Adds Security AI to MDASH at Half the Cost</news:title>
      <news:keywords>microsoft, mdash, mai-cyber-1-flash, ai-security, vulnerability-management, cybersecurity-ai, benchmark</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-28-microsoft-mai-cyber-1-flash-mdash-security-ai/cover.jpg</image:loc>
      <image:title>Microsoft Adds Security AI to MDASH at Half the Cost</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-fastjson-rce-zero-day-active-exploitation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T23:55:00.000Z</news:publication_date>
      <news:title>FastJson Zero-Day Exploited in Attacks on US Firms</news:title>
      <news:keywords>fastjson, rce, zero-day, java, active-exploitation, deserialization</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-fastjson-rce-zero-day-active-exploitation/cover.jpg</image:loc>
      <image:title>FastJson Zero-Day Exploited in Attacks on US Firms</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-operation-bluedash-fake-teams-rmm-lure/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T23:45:00.000Z</news:publication_date>
      <news:title>BlueDash Delivers RMM Agents via Fake Teams Update</news:title>
      <news:keywords>phishing, RMM-abuse, ScreenConnect, Level-RMM, Microsoft-Teams, Operation-BlueDash, remote-access</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-operation-bluedash-fake-teams-rmm-lure/cover.jpg</image:loc>
      <image:title>BlueDash Delivers RMM Agents via Fake Teams Update</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-nvidia-open-secure-ai-alliance-nooa/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T23:30:00.000Z</news:publication_date>
      <news:title>NVIDIA Launches 37-Member Open AI Security Alliance</news:title>
      <news:keywords>nvidia, ai-security, open-secure-ai-alliance, nooa, ai-agents, open-source-security, machine-learning</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-nvidia-open-secure-ai-alliance-nooa/cover.jpg</image:loc>
      <image:title>NVIDIA Launches 37-Member Open AI Security Alliance</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-certighost-poc-adcs-windows-domain-takeover/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T23:00:00.000Z</news:publication_date>
      <news:title>Certighost PoC Drops: AD CS Flaw Enables Domain Takeover</news:title>
      <news:keywords>certighost, active-directory-certificate-services, adcs, windows, domain-takeover, proof-of-concept, microsoft</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-certighost-poc-adcs-windows-domain-takeover/cover.jpg</image:loc>
      <image:title>Certighost PoC Drops: AD CS Flaw Enables Domain Takeover</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-dysphoria-botnet-blockchain-c2-iot-200k/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T22:00:00.000Z</news:publication_date>
      <news:title>Dysphoria Botnet Uses Blockchain C2 to Resist Takedown</news:title>
      <news:keywords>dysphoria, botnet, iot, ddos, blockchain, c2, threat-intel</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-dysphoria-botnet-blockchain-c2-iot-200k/cover.jpg</image:loc>
      <image:title>Dysphoria Botnet Uses Blockchain C2 to Resist Takedown</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-arista-velocloud-cve-2026-16812-kev/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T21:00:00.000Z</news:publication_date>
      <news:title>Arista VeloCloud Orchestrator Hits CISA KEV</news:title>
      <news:keywords>arista, velocloud, command-injection, kev, cisa, sd-wan, cve-2026-16812</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-arista-velocloud-cve-2026-16812-kev/cover.jpg</image:loc>
      <image:title>Arista VeloCloud Orchestrator Hits CISA KEV</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-fortinet-forios-cve-2025-68686-kev/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T20:00:00.000Z</news:publication_date>
      <news:title>Fortinet FortiOS Persistence Bypass Added to CISA KEV</news:title>
      <news:keywords>fortinet, forios, CVE-2025-68686, kev, symbolic-link, persistence, patch-bypass, cisa</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-fortinet-forios-cve-2025-68686-kev/cover.jpg</image:loc>
      <image:title>Fortinet FortiOS Persistence Bypass Added to CISA KEV</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-apple-app-store-fake-sparrow-wallet-1-8m-bitcoin-lawsuit/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T19:00:00.000Z</news:publication_date>
      <news:title>Fake App Store Wallet Drained $1.8M; Apple Faces Lawsuit</news:title>
      <news:keywords>App Store fraud, fake Sparrow Wallet, Bitcoin theft, seed phrase theft, crypto wallet scam, Apple lawsuit, mobile security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-apple-app-store-fake-sparrow-wallet-1-8m-bitcoin-lawsuit/cover.jpg</image:loc>
      <image:title>Fake App Store Wallet Drained $1.8M; Apple Faces Lawsuit</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-vbulletin-preauth-rce-public-exploit/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T18:00:00.000Z</news:publication_date>
      <news:title>Public Exploit Out for vBulletin Pre-Auth RCE</news:title>
      <news:keywords>vbulletin, remote-code-execution, pre-auth, exploit, patch, forum-security, php</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-vbulletin-preauth-rce-public-exploit/cover.jpg</image:loc>
      <image:title>Public Exploit Out for vBulletin Pre-Auth RCE</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-coca-cola-fairlife-data-theft-confirmed/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T17:00:00.000Z</news:publication_date>
      <news:title>Coca-Cola Confirms Fairlife Data Theft</news:title>
      <news:keywords>coca-cola, fairlife, ransomware, data-breach, exfiltration, anubis, data-theft</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-coca-cola-fairlife-data-theft-confirmed/cover.jpg</image:loc>
      <image:title>Coca-Cola Confirms Fairlife Data Theft</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-shinyhunters-claims-ey-breach-supply-chain/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T16:00:00.000Z</news:publication_date>
      <news:title>ShinyHunters Claims EY Breach via Supply-Chain Attack</news:title>
      <news:keywords>ShinyHunters, Ernst &amp; Young, EY, data breach, supply-chain attack, extortion</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-shinyhunters-claims-ey-breach-supply-chain/cover.jpg</image:loc>
      <image:title>ShinyHunters Claims EY Breach via Supply-Chain Attack</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-n8n-sandbox-escape-cve-2026-27577-bypass/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T14:00:00.000Z</news:publication_date>
      <news:title>n8n Sandbox Escape Bypasses February CVE-2026-27577 Patch</news:title>
      <news:keywords>n8n, sandbox-escape, CVE-2026-27577, workflow-automation, RCE, Security-Joes, patch</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-n8n-sandbox-escape-cve-2026-27577-bypass/cover.jpg</image:loc>
      <image:title>n8n Sandbox Escape Bypasses February CVE-2026-27577 Patch</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-cruciferra-crypter-byovd-process-ghosting-india-tax/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T13:00:00.000Z</news:publication_date>
      <news:title>Cruciferra Crypter: BYOVD and Process Ghosting on the Market</news:title>
      <news:keywords>cruciferra, byovd, process-ghosting, crypter, windows-malware, threat-intel, proofpoint</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-cruciferra-crypter-byovd-process-ghosting-india-tax/cover.jpg</image:loc>
      <image:title>Cruciferra Crypter: BYOVD and Process Ghosting on the Market</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-github-pypi-dependabot-cooldown-supply-chain/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T12:00:00.000Z</news:publication_date>
      <news:title>Dependabot Gets 3-Day Cooldown to Block Package Poisoning</news:title>
      <news:keywords>dependabot, github, pypi, supply-chain, dependency-management, package-poisoning, software-supply-chain</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-github-pypi-dependabot-cooldown-supply-chain/cover.jpg</image:loc>
      <image:title>Dependabot Gets 3-Day Cooldown to Block Package Poisoning</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-teleshim-east-asia-apt-telegram-c2-middle-east/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T10:00:00.000Z</news:publication_date>
      <news:title>TELESHIM Uses Telegram C2 Against Middle East Governments</news:title>
      <news:keywords>TELESHIM, MIXEDKEY, BINDCLOAK, Zscaler ThreatLabz, East Asia APT, Telegram C2, Middle East</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-teleshim-east-asia-apt-telegram-c2-middle-east/cover.jpg</image:loc>
      <image:title>TELESHIM Uses Telegram C2 Against Middle East Governments</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-steam-forum-clickfix-xmrig-cryptominer/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T08:00:00.000Z</news:publication_date>
      <news:title>Steam Forums Used to Deliver XMRig via ClickFix</news:title>
      <news:keywords>ClickFix, XMRig, Steam, cryptominer, Monero, social engineering, gaming</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-steam-forum-clickfix-xmrig-cryptominer/cover.jpg</image:loc>
      <image:title>Steam Forums Used to Deliver XMRig via ClickFix</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-26-insurance-phishing-realtime-aitm-account-hijacking/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-26T23:00:00.000Z</news:publication_date>
      <news:title>Insurance Phishing Moves to Real-Time Account Hijacking</news:title>
      <news:keywords>phishing, AiTM, adversary-in-the-middle, account takeover, insurance, MFA bypass, session hijacking</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-26-insurance-phishing-realtime-aitm-account-hijacking/cover.jpg</image:loc>
      <image:title>Insurance Phishing Moves to Real-Time Account Hijacking</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-26-github-pypi-dependabot-time-based-supply-chain-defenses/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-26T14:30:00.000Z</news:publication_date>
      <news:title>GitHub, PyPI Add Time-Gated Supply Chain Defenses</news:title>
      <news:keywords>supply-chain, dependabot, pypi, github, package security, dependency management, open source security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-26-github-pypi-dependabot-time-based-supply-chain-defenses/cover.jpg</image:loc>
      <image:title>GitHub, PyPI Add Time-Gated Supply Chain Defenses</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-26-chick-fil-a-credential-stuffing-13000-accounts/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-26T14:00:00.000Z</news:publication_date>
      <news:title>Chick-fil-A: 13,000 Accounts Hit in Credential Stuffing</news:title>
      <news:keywords>credential stuffing, chick-fil-a, data breach, account takeover, mobile security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-26-chick-fil-a-credential-stuffing-13000-accounts/cover.jpg</image:loc>
      <image:title>Chick-fil-A: 13,000 Accounts Hit in Credential Stuffing</image:title>
    </image:image>
  </url>
</urlset>