<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://0daynews.com/articles/2026-07-23-void-blizzard-zimbra-zero-click-email-theft-airgap/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T18:00:00.000Z</news:publication_date>
      <news:title>Void Blizzard Exploits Zimbra Flaw for Email Theft</news:title>
      <news:keywords>Void Blizzard, Laundry Bear, Zimbra, email theft, CISA, state-sponsored, Russia</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-23-void-blizzard-zimbra-zero-click-email-theft-airgap/cover.jpg</image:loc>
      <image:title>Void Blizzard Exploits Zimbra Flaw for Email Theft</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-23-jadeprox-triback-loader-group-ib-china-nexus-apt/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T17:00:00.000Z</news:publication_date>
      <news:title>China-Linked JadeProx Deploys TriBack Loader in Gov Attacks</news:title>
      <news:keywords>JadeProx, TriBack Loader, China APT, Group-IB, government, healthcare, threat intelligence, Windows loader</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-23-jadeprox-triback-loader-group-ib-china-nexus-apt/cover.jpg</image:loc>
      <image:title>China-Linked JadeProx Deploys TriBack Loader in Gov Attacks</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-23-claude-cowork-vm-escape-mac-files-airgap/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T16:00:00.000Z</news:publication_date>
      <news:title>Claude Cowork VM Escape Reaches Mac Files</news:title>
      <news:keywords>Claude Cowork, VM escape, sandbox escape, Anthropic, Accomplish AI, macOS, AI agent security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-23-claude-cowork-vm-escape-mac-files-airgap/cover.jpg</image:loc>
      <image:title>Claude Cowork VM Escape Reaches Mac Files</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-23-fedramp-20x-rev5-transition-continuous-monitoring-loop/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T15:00:00.000Z</news:publication_date>
      <news:title>FedRAMP 20x Ends Point-in-Time Authorization</news:title>
      <news:keywords>FedRAMP, FedRAMP 20x, cloud compliance, continuous monitoring, OSCAL, ATO, federal cloud</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-23-fedramp-20x-rev5-transition-continuous-monitoring-loop/cover.jpg</image:loc>
      <image:title>FedRAMP 20x Ends Point-in-Time Authorization</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-23-github-actions-packagist-cpanel-whm-supply-chain/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T13:00:00.000Z</news:publication_date>
      <news:title>Attackers Weaponize GitHub Actions Against cPanel Hosts</news:title>
      <news:keywords>supply chain, GitHub Actions, Packagist, cPanel, WHM, CI/CD abuse, malicious packages</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-23-github-actions-packagist-cpanel-whm-supply-chain/cover.jpg</image:loc>
      <image:title>Attackers Weaponize GitHub Actions Against cPanel Hosts</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-23-refluxfs-cve-2026-64600-linux-kernel-lpe-rhel/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T12:00:00.000Z</news:publication_date>
      <news:title>RefluXFS LPE Hits Default RHEL, Fedora, Amazon Linux</news:title>
      <news:keywords>CVE-2026-64600, Linux kernel, XFS, privilege escalation, LPE, RHEL, Qualys</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-23-refluxfs-cve-2026-64600-linux-kernel-lpe-rhel/cover.jpg</image:loc>
      <image:title>RefluXFS LPE Hits Default RHEL, Fedora, Amazon Linux</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-23-chaos-ransomware-msarat-browser-c2-webrtc-airgap/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T11:00:00.000Z</news:publication_date>
      <news:title>Chaos Ransomware&apos;s msaRAT Hides C2 in Browser Traffic</news:title>
      <news:keywords>ransomware, msaRAT, Chaos ransomware, browser C2, WebRTC, TURN relay, command-and-control</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-23-chaos-ransomware-msarat-browser-c2-webrtc-airgap/cover.jpg</image:loc>
      <image:title>Chaos Ransomware&apos;s msaRAT Hides C2 in Browser Traffic</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-23-exchange-online-mailbox-quarantine-error-airgap/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T10:00:00.000Z</news:publication_date>
      <news:title>Exchange Online Quarantining Mailboxes in Error Since Sunday</news:title>
      <news:keywords>Exchange Online, Microsoft, mailbox quarantine, Microsoft 365, email security, false positive</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-23-exchange-online-mailbox-quarantine-error-airgap/cover.jpg</image:loc>
      <image:title>Exchange Online Quarantining Mailboxes in Error Since Sunday</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-23-moveit-cve-2023-34362-three-years-clop-data-breach/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T08:00:00.000Z</news:publication_date>
      <news:title>MOVEit Transfer and the Breach That Defined 2023</news:title>
      <news:keywords>CVE-2023-34362, MOVEit Transfer, Cl0p, SQL injection, data breach, managed file transfer, EPSS</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-23-moveit-cve-2023-34362-three-years-clop-data-breach/cover.jpg</image:loc>
      <image:title>MOVEit Transfer and the Breach That Defined 2023</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-23-eclypsium-infratrust-pulse-firmware-patch-priority/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T07:00:00.000Z</news:publication_date>
      <news:title>Eclypsium Launches InfraTrust for Firmware Patch Priority</news:title>
      <news:keywords>firmware security, infrastructure vulnerabilities, patch prioritization, Eclypsium, InfraTrust, edge devices, networking</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-23-eclypsium-infratrust-pulse-firmware-patch-priority/cover.jpg</image:loc>
      <image:title>Eclypsium Launches InfraTrust for Firmware Patch Priority</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-23-kratos-phishing-kit-dismantled-microsoft-365-mfa-bypass-fuse/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T05:00:00.000Z</news:publication_date>
      <news:title>Kratos Phishing Kit Dismantled in Global Takedown</news:title>
      <news:keywords>phishing, MFA bypass, Microsoft 365, AiTM, Kratos, law enforcement, session hijacking</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-23-kratos-phishing-kit-dismantled-microsoft-365-mfa-bypass-fuse/cover.jpg</image:loc>
      <image:title>Kratos Phishing Kit Dismantled in Global Takedown</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-n-day-n-hour-patch-window-sharepoint-wp2shell/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T02:00:00.000Z</news:publication_date>
      <news:title>N-Day Is Now N-Hour: The Vanishing Patch Window</news:title>
      <news:keywords>n-day exploitation, patch management, CVE, exploit window, SharePoint, wp2shell, vulnerability response</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-n-day-n-hour-patch-window-sharepoint-wp2shell/cover.jpg</image:loc>
      <image:title>N-Day Is Now N-Hour: The Vanishing Patch Window</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-google-deepmind-gemini-35-flash-cyber-codemender-loop/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T23:00:00.000Z</news:publication_date>
      <news:title>Google Gemini 3.5 Flash Cyber Targets Vuln Discovery</news:title>
      <news:keywords>google, deepmind, gemini, vulnerability-discovery, ai-security, codemender, patch-generation</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-google-deepmind-gemini-35-flash-cyber-codemender-loop/cover.jpg</image:loc>
      <image:title>Google Gemini 3.5 Flash Cyber Targets Vuln Discovery</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-sharepoint-cve-2026-50522-kev-machine-keys-fuse/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T23:00:00.000Z</news:publication_date>
      <news:title>SharePoint RCE on KEV; Attackers Pivot to Machine Keys</news:title>
      <news:keywords>CVE-2026-50522, SharePoint, CISA KEV, machine keys, RCE, deserialization, Microsoft</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-sharepoint-cve-2026-50522-kev-machine-keys-fuse/cover.jpg</image:loc>
      <image:title>SharePoint RCE on KEV; Attackers Pivot to Machine Keys</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-check-point-smartconsole-cve-2026-16232-kev-admin-bypass/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:00:00.000Z</news:publication_date>
      <news:title>Check Point SmartConsole Flaw Gives Attackers Admin Access</news:title>
      <news:keywords>Check Point, SmartConsole, CVE-2026-16232, CISA KEV, authentication bypass, firewall management</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-check-point-smartconsole-cve-2026-16232-kev-admin-bypass/cover.jpg</image:loc>
      <image:title>Check Point SmartConsole Flaw Gives Attackers Admin Access</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-upbound-acima-13m-lease-fraud-breach/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:00:00.000Z</news:publication_date>
      <news:title>Stolen Upbound Data Fueled $13M Acima Lease Fraud</news:title>
      <news:keywords>Upbound, Acima, data breach, lease fraud, fintech, identity fraud</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-upbound-acima-13m-lease-fraud-breach/cover.jpg</image:loc>
      <image:title>Stolen Upbound Data Fueled $13M Acima Lease Fraud</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-github-bug-bounty-payouts-halved-vip-tier/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:00:00.000Z</news:publication_date>
      <news:title>GitHub Cuts Public Bug Bounty Payouts by Half July 27</news:title>
      <news:keywords>github, bug bounty, vulnerability research, security research, responsible disclosure, vrt, hacker incentives</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-github-bug-bounty-payouts-halved-vip-tier/cover.jpg</image:loc>
      <image:title>GitHub Cuts Public Bug Bounty Payouts by Half July 27</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-south-korea-mfa-diplomatic-academy-breach-airgap/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:00:00.000Z</news:publication_date>
      <news:title>South Korea MFA Breach: Diplomat Data Exposed 10 Months</news:title>
      <news:keywords>South Korea, MFA breach, diplomatic data, National Diplomatic Academy, data breach, espionage</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-south-korea-mfa-diplomatic-academy-breach-airgap/cover.jpg</image:loc>
      <image:title>South Korea MFA Breach: Diplomat Data Exposed 10 Months</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-snap-confine-lpe-ubuntu-desktop-root-fuse/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T20:00:00.000Z</news:publication_date>
      <news:title>snap-confine LPE Hits Default Ubuntu Desktop Installs</news:title>
      <news:keywords>CVE-2026-8933, snap-confine, Ubuntu, privilege escalation, LPE, local root</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-snap-confine-lpe-ubuntu-desktop-root-fuse/cover.jpg</image:loc>
      <image:title>snap-confine LPE Hits Default Ubuntu Desktop Installs</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-adobe-acrobat-chrome-extension-whatsapp-web-data-access/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T17:30:00.000Z</news:publication_date>
      <news:title>Adobe Acrobat Extension Let Sites Read WhatsApp Chats</news:title>
      <news:keywords>adobe acrobat, chrome extension, whatsapp, browser security, privacy, extension permissions</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-adobe-acrobat-chrome-extension-whatsapp-web-data-access/cover.jpg</image:loc>
      <image:title>Adobe Acrobat Extension Let Sites Read WhatsApp Chats</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-stadler-rail-everest-ransom-rejected/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T17:30:00.000Z</news:publication_date>
      <news:title>Stadler Rail Refuses $12.3M Ransom from Everest</news:title>
      <news:keywords>stadler rail, everest ransomware, ransomware, third-party risk, supply chain, switzerland, data extortion</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-stadler-rail-everest-ransom-rejected/cover.jpg</image:loc>
      <image:title>Stadler Rail Refuses $12.3M Ransom from Everest</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-microsoft-exchange-2016-2019-esu-ends-october/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T16:00:00.000Z</news:publication_date>
      <news:title>Exchange 2016 and 2019 Lose ESU Patches in October</news:title>
      <news:keywords>Exchange 2016, Exchange 2019, ESU, end of support, Microsoft, patch management, migration</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-microsoft-exchange-2016-2019-esu-ends-october/cover.jpg</image:loc>
      <image:title>Exchange 2016 and 2019 Lose ESU Patches in October</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-ostium-23-7m-off-chain-oracle-compromise-airgap/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T15:45:00.000Z</news:publication_date>
      <news:title>Ostium Loses $23.7M to Off-Chain Oracle Compromise</news:title>
      <news:keywords>Ostium, oracle compromise, price manipulation, off-chain infrastructure, DeFi, crypto breach, liquidity provider</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-ostium-23-7m-off-chain-oracle-compromise-airgap/cover.jpg</image:loc>
      <image:title>Ostium Loses $23.7M to Off-Chain Oracle Compromise</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-windmill-cve-2026-29059-path-traversal-active-exploitation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T15:00:00.000Z</news:publication_date>
      <news:title>CVE-2026-29059: Windmill Path Traversal Actively Exploited</news:title>
      <news:keywords>CVE-2026-29059, Windmill, path traversal, active exploitation, VulnCheck, arbitrary file read, developer platform</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-windmill-cve-2026-29059-path-traversal-active-exploitation/cover.jpg</image:loc>
      <image:title>CVE-2026-29059: Windmill Path Traversal Actively Exploited</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-langflow-cve-2026-0770-fifth-kev-entry-federal-friday/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T13:20:00.000Z</news:publication_date>
      <news:title>Langflow&apos;s fifth KEV entry: CVE-2026-0770, patch by Friday</news:title>
      <news:keywords>CVE-2026-0770, Langflow, CISA KEV, Zero Day Initiative, Trend Research, unauthenticated RCE, BOD 26-04</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-langflow-cve-2026-0770-fifth-kev-entry-federal-friday/cover.jpg</image:loc>
      <image:title>Langflow&apos;s fifth KEV entry: CVE-2026-0770, patch by Friday</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-lg-webos-residential-proxy-sdk-ban-spur-brightdata-42-percent/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T10:00:00.000Z</news:publication_date>
      <news:title>LG bans residential-proxy SDKs from webOS TV apps</news:title>
      <news:keywords>LG, webOS, residential proxies, Bright Data, Spur, smart TV, Samsung Tizen</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-lg-webos-residential-proxy-sdk-ban-spur-brightdata-42-percent/cover.jpg</image:loc>
      <image:title>LG bans residential-proxy SDKs from webOS TV apps</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-azure-devops-mcp-manifold-hidden-pr-comments-hijack-ai-reviewers-fuse/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T09:15:00.000Z</news:publication_date>
      <news:title>Azure DevOps MCP: hidden PR text hijacks AI reviewers</news:title>
      <news:keywords>Azure DevOps MCP, prompt injection, Manifold Security, Microsoft, AI coding agent, indirect prompt injection</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-azure-devops-mcp-manifold-hidden-pr-comments-hijack-ai-reviewers-fuse/cover.jpg</image:loc>
      <image:title>Azure DevOps MCP: hidden PR text hijacks AI reviewers</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-chick-fil-a-june-credential-stuffing-2182-texans-airgap/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T08:00:00.000Z</news:publication_date>
      <news:title>Chick-fil-A discloses June credential-stuffing breach</news:title>
      <news:keywords>Chick-fil-A, credential stuffing, data breach, loyalty program, password reuse, Chick-fil-A One</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-chick-fil-a-june-credential-stuffing-2182-texans-airgap/cover.jpg</image:loc>
      <image:title>Chick-fil-A discloses June credential-stuffing breach</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-jfrog-nuget-newtonsoftt-typosquat-digitain-fg-crash-kilobaud/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T07:00:00.000Z</news:publication_date>
      <news:title>A NuGet Typosquat That Rigged Games Instead of Wallets</news:title>
      <news:keywords>supply-chain, nuget, typosquat, newtonsoft-json, jfrog, digitain, dotnet</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-jfrog-nuget-newtonsoftt-typosquat-digitain-fg-crash-kilobaud/cover.jpg</image:loc>
      <image:title>A NuGet Typosquat That Rigged Games Instead of Wallets</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-openai-attributes-hugging-face-breach-gpt-5-6-sol-exploitgym/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T06:15:00.000Z</news:publication_date>
      <news:title>OpenAI attributes Hugging Face breach to GPT-5.6 Sol</news:title>
      <news:keywords>Hugging Face, OpenAI, GPT-5.6 Sol, ExploitGym, autonomous agent, AI safety, package registry</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-openai-attributes-hugging-face-breach-gpt-5-6-sol-exploitgym/cover.jpg</image:loc>
      <image:title>OpenAI attributes Hugging Face breach to GPT-5.6 Sol</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-cisa-kev-wp2shell-both-cves-added-bod-26-04-federal-clock/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T03:00:00.000Z</news:publication_date>
      <news:title>Both wp2shell CVEs land on CISA KEV — federal clock runs</news:title>
      <news:keywords>CISA KEV, wp2shell, CVE-2026-63030, CVE-2026-60137, WordPress, BOD 26-04</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-cisa-kev-wp2shell-both-cves-added-bod-26-04-federal-clock/cover.jpg</image:loc>
      <image:title>Both wp2shell CVEs land on CISA KEV — federal clock runs</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-zimbra-10-1-20-nine-bugs-snmp-command-injection-tops-list/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T23:45:00.000Z</news:publication_date>
      <news:title>Zimbra 10.1.20 patches nine, SNMP injection at the top</news:title>
      <news:keywords>Zimbra, Zimbra Collaboration Suite, Zimbra 10.1.20, SNMP command injection, Classic Web Client XSS, Nextcloud SSRF, patch release</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-zimbra-10-1-20-nine-bugs-snmp-command-injection-tops-list/cover.jpg</image:loc>
      <image:title>Zimbra 10.1.20 patches nine, SNMP injection at the top</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-kratos-phaas-olympus-blade-takedown-m365-passkeys-fuse/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T23:30:00.000Z</news:publication_date>
      <news:title>Kratos phishing platform seized. M365 exposure is not.</news:title>
      <news:keywords>Kratos PhaaS, phishing-as-a-service, Operation Olympus Blade, Microsoft 365, AiTM, passkeys, phishing-resistant MFA</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-kratos-phaas-olympus-blade-takedown-m365-passkeys-fuse/cover.jpg</image:loc>
      <image:title>Kratos phishing platform seized. M365 exposure is not.</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-sharepoint-cve-2026-50522-machine-keys-stolen-rotate-credentials-fuse/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:05:00.000Z</news:publication_date>
      <news:title>SharePoint attackers stealing keys — rotate credentials now</news:title>
      <news:keywords>CVE-2026-50522, Microsoft SharePoint, machine keys, watchTowr, Defused, credential rotation, persistence</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-sharepoint-cve-2026-50522-machine-keys-stolen-rotate-credentials-fuse/cover.jpg</image:loc>
      <image:title>SharePoint attackers stealing keys — rotate credentials now</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-thn-picus-n-hour-patching-mythos-verizon-dbir-analysis/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:15:00.000Z</news:publication_date>
      <news:title>Patch-to-exploit is hours. Patching still isn&apos;t optional.</news:title>
      <news:keywords>N-day, patch race, Mythos, Verizon DBIR, exposure validation, control effectiveness</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-thn-picus-n-hour-patching-mythos-verizon-dbir-analysis/cover.jpg</image:loc>
      <image:title>Patch-to-exploit is hours. Patching still isn&apos;t optional.</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-anubis-fairlife-1tb-nutanix-claim-declines-comment/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:15:00.000Z</news:publication_date>
      <news:title>Anubis claims Fairlife hit, 1TB and Nutanix encrypted</news:title>
      <news:keywords>Anubis ransomware, Coca-Cola Fairlife, Nutanix encryption, ransomware leak site, food and beverage ransomware</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-anubis-fairlife-1tb-nutanix-claim-declines-comment/cover.jpg</image:loc>
      <image:title>Anubis claims Fairlife hit, 1TB and Nutanix encrypted</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-apple-hide-my-email-mail-logs-july3-fix-year-disclosure/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:15:00.000Z</news:publication_date>
      <news:title>Apple fixes Hide My Email leak, year after disclosure</news:title>
      <news:keywords>Apple Hide My Email, iCloud+ alias leak, responsible disclosure, Mail logs metadata, 404 Media, Tyler Murphy</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-apple-hide-my-email-mail-logs-july3-fix-year-disclosure/cover.jpg</image:loc>
      <image:title>Apple fixes Hide My Email leak, year after disclosure</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-cisa-kev-dd-wrt-cve-2021-27137-upnp-ssdp-strcpy-r45724/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:15:00.000Z</news:publication_date>
      <news:title>DD-WRT UPnP flaw CVE-2021-27137 added to CISA KEV</news:title>
      <news:keywords>dd-wrt, cve-2021-27137, cisa-kev, upnp, ssdp, router, buffer-overflow</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-cisa-kev-dd-wrt-cve-2021-27137-upnp-ssdp-strcpy-r45724/cover.jpg</image:loc>
      <image:title>DD-WRT UPnP flaw CVE-2021-27137 added to CISA KEV</image:title>
    </image:image>
  </url>
</urlset>