<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-aivd-mivd-russian-intel-ip-cameras-nato-military-transport-ukraine/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T14:15:00.000Z</news:publication_date>
      <news:title>AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes</news:title>
      <news:keywords>AIVD, MIVD, IP cameras, Russia, Ukraine, NATO, military logistics</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-aivd-mivd-russian-intel-ip-cameras-nato-military-transport-ukraine/cover.jpg</image:loc>
      <image:title>AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-wsus-sync-fix-new-installs-only-old-servers-metadata-cleanup/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T13:15:00.000Z</news:publication_date>
      <news:title>WSUS sync fix only for new installs, old servers still stuck</news:title>
      <news:keywords>WSUS, Windows Server Update Services, Microsoft, Windows Server, Configuration Manager, patch management, sync failure</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-wsus-sync-fix-new-installs-only-old-servers-metadata-cleanup/cover.jpg</image:loc>
      <image:title>WSUS sync fix only for new installs, old servers still stuck</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-trend-micro-bandcampro-gemini-cli-c2-dental-clinic-eight-node-botnet/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T12:00:00.000Z</news:publication_date>
      <news:title>Trend Micro: &apos;bandcampro&apos; ran botnet ops through Gemini CLI</news:title>
      <news:keywords>Google Gemini CLI, bandcampro, Trend Micro, botnet, OpenDental, Patriot Bait, AI-assisted intrusions</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-trend-micro-bandcampro-gemini-cli-c2-dental-clinic-eight-node-botnet/cover.jpg</image:loc>
      <image:title>Trend Micro: &apos;bandcampro&apos; ran botnet ops through Gemini CLI</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-microsoft-kb5121767-oob-dell-intel-ipf-driver-hold-fix/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T11:15:00.000Z</news:publication_date>
      <news:title>Microsoft ships KB5121767 OOB for Dell IPF driver hold</news:title>
      <news:keywords>Microsoft, KB5121767, Windows 11, Dell, Intel IPF, out-of-band update, KB5101650, safeguard hold</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-microsoft-kb5121767-oob-dell-intel-ipf-driver-hold-fix/cover.jpg</image:loc>
      <image:title>Microsoft ships KB5121767 OOB for Dell IPF driver hold</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-servicenow-ai-platform-cve-2026-6875-defused-exploitation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T10:30:00.000Z</news:publication_date>
      <news:title>ServiceNow AI Platform RCE exploited in wild: CVE-2026-6875</news:title>
      <news:keywords>ServiceNow, CVE-2026-6875, AI Platform, remote code execution, Defused, active exploitation</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-servicenow-ai-platform-cve-2026-6875-defused-exploitation/cover.jpg</image:loc>
      <image:title>ServiceNow AI Platform RCE exploited in wild: CVE-2026-6875</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-hugging-face-autonomous-ai-agent-breach-internal-datasets/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T09:00:00.000Z</news:publication_date>
      <news:title>Hugging Face confirms breach by autonomous AI agent</news:title>
      <news:keywords>Hugging Face, autonomous AI agent, supply chain, dataset loader, template injection, GLM 5.2, AI security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-hugging-face-autonomous-ai-agent-breach-internal-datasets/cover.jpg</image:loc>
      <image:title>Hugging Face confirms breach by autonomous AI agent</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-stepsecurity-sleepergem-rubygems-dormant-accounts-forgejo-loader/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T08:00:00.000Z</news:publication_date>
      <news:title>SleeperGem loader hides in dormant RubyGems, skips CI/CD</news:title>
      <news:keywords>SleeperGem, StepSecurity, RubyGems supply chain, git_credential_manager, Dendreo, Forgejo, dormant maintainer accounts</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-stepsecurity-sleepergem-rubygems-dormant-accounts-forgejo-loader/cover.jpg</image:loc>
      <image:title>SleeperGem loader hides in dormant RubyGems, skips CI/CD</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-wp2shell-first-exploitation-cve-2026-60137-sqli-companion-patched/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T01:15:00.000Z</news:publication_date>
      <news:title>wp2shell: first signs of exploitation; CVE-2026-60137 lands</news:title>
      <news:keywords>CVE-2026-63030, CVE-2026-60137, wp2shell, WordPress, WordPress Core, in-the-wild exploitation, watchTowr, Searchlight Cyber</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-wp2shell-first-exploitation-cve-2026-60137-sqli-companion-patched/cover.jpg</image:loc>
      <image:title>wp2shell: first signs of exploitation; CVE-2026-60137 lands</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-19-nginx-cve-2026-42533-map-regex-heap-overflow-worker-patch/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-19T22:05:00.000Z</news:publication_date>
      <news:title>nginx patches heap overflow in worker (CVE-2026-42533)</news:title>
      <news:keywords>nginx, CVE-2026-42533, F5, heap overflow, map directive, NGINX Plus, memory safety</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-19-nginx-cve-2026-42533-map-regex-heap-overflow-worker-patch/cover.jpg</image:loc>
      <image:title>nginx patches heap overflow in worker (CVE-2026-42533)</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-19-cert-ua-uac-0145-sandworm-clickfix-ukraine/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-19T18:00:00.000Z</news:publication_date>
      <news:title>CERT-UA: UAC-0145 (Sandworm) runs ClickFix on Ukraine</news:title>
      <news:keywords>CERT-UA, UAC-0145, Sandworm, ClickFix, Ukraine, EtherHiding, COWARDDUCK</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-19-cert-ua-uac-0145-sandworm-clickfix-ukraine/cover.jpg</image:loc>
      <image:title>CERT-UA: UAC-0145 (Sandworm) runs ClickFix on Ukraine</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-19-kaspersky-hellonet-vipnet-updater-dll-sideload-russian-orgs/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-19T16:30:00.000Z</news:publication_date>
      <news:title>Kaspersky details HelloNet abuse of ViPNet updater</news:title>
      <news:keywords>HelloNet, ViPNet, InfoTeCS, Kaspersky, DLL sideloading, HelloInjector, APT</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-19-kaspersky-hellonet-vipnet-updater-dll-sideload-russian-orgs/cover.jpg</image:loc>
      <image:title>Kaspersky details HelloNet abuse of ViPNet updater</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-19-volexity-uta0533-sma1000-rootrun-knuckleball-orangetail/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-19T15:00:00.000Z</news:publication_date>
      <news:title>SonicWall SMA1000: Volexity names UTA0533, IoC list out</news:title>
      <news:keywords>SonicWall SMA1000, UTA0533, Volexity, CVE-2026-15409, CVE-2026-15410, ROOTRUN, ORANGETAIL</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-19-volexity-uta0533-sma1000-rootrun-knuckleball-orangetail/cover.jpg</image:loc>
      <image:title>SonicWall SMA1000: Volexity names UTA0533, IoC list out</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-19-legacyhive-nightmare-eclipse-windows-user-profile-usrclass-lpe-unpatched/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-19T06:15:00.000Z</news:publication_date>
      <news:title>LegacyHive: PoC drops for unpatched Windows LPE zero-day</news:title>
      <news:keywords>LegacyHive, Windows zero-day, local privilege escalation, User Profile Service, usrclass.dat, Nightmare Eclipse</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-19-legacyhive-nightmare-eclipse-windows-user-profile-usrclass-lpe-unpatched/cover.jpg</image:loc>
      <image:title>LegacyHive: PoC drops for unpatched Windows LPE zero-day</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-19-metasploit-weekly-http-smb-relay-riscv-fetch-payloads/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-19T03:20:00.000Z</news:publication_date>
      <news:title>Metasploit adds HTTP-to-SMB NTLM relay, RISC-V payloads</news:title>
      <news:keywords>Metasploit, Rapid7, NTLM relay, SMB signing, RISC-V, fetch payloads</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-19-metasploit-weekly-http-smb-relay-riscv-fetch-payloads/cover.jpg</image:loc>
      <image:title>Metasploit adds HTTP-to-SMB NTLM relay, RISC-V payloads</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-18-microsoft-acr-stealer-april-june-webdav-etherhiding/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-18T22:20:00.000Z</news:publication_date>
      <news:title>Microsoft ties ACR Stealer surge to WebDAV, blockchain C2</news:title>
      <news:keywords>ACR Stealer, Amatera, ClickFix, WebDAV, EtherHiding, Microsoft Threat Intelligence, DPAPI</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-18-microsoft-acr-stealer-april-june-webdav-etherhiding/cover.jpg</image:loc>
      <image:title>Microsoft ties ACR Stealer surge to WebDAV, blockchain C2</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-18-7-zip-26-02-xz-heap-overflow-rce-zdi-26-444/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-18T21:00:00.000Z</news:publication_date>
      <news:title>7-Zip 26.02 patches XZ heap overflow, no auto-update</news:title>
      <news:keywords>7-Zip, ZDI-26-444, XZ, heap overflow, remote code execution, patch, Windows</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-18-7-zip-26-02-xz-heap-overflow-rce-zdi-26-444/cover.jpg</image:loc>
      <image:title>7-Zip 26.02 patches XZ heap overflow, no auto-update</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-18-doj-chen-zhang-queens-brooklyn-43m-investment-fraud-laundering-140-accounts-45-shells/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-18T18:15:00.000Z</news:publication_date>
      <news:title>Two indicted over $43M laundered from investment scams</news:title>
      <news:keywords>money laundering, investment fraud, pig butchering, DOJ indictment, shell companies, HSI</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-18-doj-chen-zhang-queens-brooklyn-43m-investment-fraud-laundering-140-accounts-45-shells/cover.jpg</image:loc>
      <image:title>Two indicted over $43M laundered from investment scams</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-18-nadmesh-go-botnet-shodan-comfyui-ollama-3811-aws-keys/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-18T16:15:00.000Z</news:publication_date>
      <news:title>NadMesh botnet raids exposed AI tools for 3,811 AWS keys</news:title>
      <news:keywords>nadmesh, ollama, comfyui, langflow, n8n, open-webui, gradio, aws-keys, kubernetes, shodan, cloud-security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-18-nadmesh-go-botnet-shodan-comfyui-ollama-3811-aws-keys/cover.jpg</image:loc>
      <image:title>NadMesh botnet raids exposed AI tools for 3,811 AWS keys</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-18-expel-digicert-goldeneyedog-cylindricalcanine-27-ev-code-signing-certs-zhong-stealer/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-18T15:00:00.000Z</news:publication_date>
      <news:title>Expel: GoldenEyeDog stole 27 EV certs from DigiCert</news:title>
      <news:keywords>digicert, goldeneyedog, cylindricalcanine, ev-code-signing, zhong-stealer, expel, supply-chain</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-18-expel-digicert-goldeneyedog-cylindricalcanine-27-ev-code-signing-certs-zhong-stealer/cover.jpg</image:loc>
      <image:title>Expel: GoldenEyeDog stole 27 EV certs from DigiCert</image:title>
    </image:image>
  </url>
</urlset>