<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-check-point-smartconsole-cve-2026-16232-kev-admin-bypass/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:00:00.000Z</news:publication_date>
      <news:title>Check Point SmartConsole Flaw Gives Attackers Admin Access</news:title>
      <news:keywords>Check Point, SmartConsole, CVE-2026-16232, CISA KEV, authentication bypass, firewall management</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-check-point-smartconsole-cve-2026-16232-kev-admin-bypass/cover.jpg</image:loc>
      <image:title>Check Point SmartConsole Flaw Gives Attackers Admin Access</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-upbound-acima-13m-lease-fraud-breach/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:00:00.000Z</news:publication_date>
      <news:title>Stolen Upbound Data Fueled $13M Acima Lease Fraud</news:title>
      <news:keywords>Upbound, Acima, data breach, lease fraud, fintech, identity fraud</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-upbound-acima-13m-lease-fraud-breach/cover.jpg</image:loc>
      <image:title>Stolen Upbound Data Fueled $13M Acima Lease Fraud</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-south-korea-mfa-diplomatic-academy-breach-airgap/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:00:00.000Z</news:publication_date>
      <news:title>South Korea MFA Breach: Diplomat Data Exposed 10 Months</news:title>
      <news:keywords>South Korea, MFA breach, diplomatic data, National Diplomatic Academy, data breach, espionage</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-south-korea-mfa-diplomatic-academy-breach-airgap/cover.jpg</image:loc>
      <image:title>South Korea MFA Breach: Diplomat Data Exposed 10 Months</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-snap-confine-lpe-ubuntu-desktop-root-fuse/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T20:00:00.000Z</news:publication_date>
      <news:title>snap-confine LPE Hits Default Ubuntu Desktop Installs</news:title>
      <news:keywords>CVE-2026-8933, snap-confine, Ubuntu, privilege escalation, LPE, local root</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-snap-confine-lpe-ubuntu-desktop-root-fuse/cover.jpg</image:loc>
      <image:title>snap-confine LPE Hits Default Ubuntu Desktop Installs</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-adobe-acrobat-chrome-extension-whatsapp-web-data-access/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T17:30:00.000Z</news:publication_date>
      <news:title>Adobe Acrobat Extension Let Sites Read WhatsApp Chats</news:title>
      <news:keywords>adobe acrobat, chrome extension, whatsapp, browser security, privacy, extension permissions</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-adobe-acrobat-chrome-extension-whatsapp-web-data-access/cover.jpg</image:loc>
      <image:title>Adobe Acrobat Extension Let Sites Read WhatsApp Chats</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-stadler-rail-everest-ransom-rejected/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T17:30:00.000Z</news:publication_date>
      <news:title>Stadler Rail Refuses $12.3M Ransom from Everest</news:title>
      <news:keywords>stadler rail, everest ransomware, ransomware, third-party risk, supply chain, switzerland, data extortion</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-stadler-rail-everest-ransom-rejected/cover.jpg</image:loc>
      <image:title>Stadler Rail Refuses $12.3M Ransom from Everest</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-microsoft-exchange-2016-2019-esu-ends-october/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T16:00:00.000Z</news:publication_date>
      <news:title>Exchange 2016 and 2019 Lose ESU Patches in October</news:title>
      <news:keywords>Exchange 2016, Exchange 2019, ESU, end of support, Microsoft, patch management, migration</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-microsoft-exchange-2016-2019-esu-ends-october/cover.jpg</image:loc>
      <image:title>Exchange 2016 and 2019 Lose ESU Patches in October</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-ostium-23-7m-off-chain-oracle-compromise-airgap/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T15:45:00.000Z</news:publication_date>
      <news:title>Ostium Loses $23.7M to Off-Chain Oracle Compromise</news:title>
      <news:keywords>Ostium, oracle compromise, price manipulation, off-chain infrastructure, DeFi, crypto breach, liquidity provider</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-ostium-23-7m-off-chain-oracle-compromise-airgap/cover.jpg</image:loc>
      <image:title>Ostium Loses $23.7M to Off-Chain Oracle Compromise</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-windmill-cve-2026-29059-path-traversal-active-exploitation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T15:00:00.000Z</news:publication_date>
      <news:title>CVE-2026-29059: Windmill Path Traversal Actively Exploited</news:title>
      <news:keywords>CVE-2026-29059, Windmill, path traversal, active exploitation, VulnCheck, arbitrary file read, developer platform</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-windmill-cve-2026-29059-path-traversal-active-exploitation/cover.jpg</image:loc>
      <image:title>CVE-2026-29059: Windmill Path Traversal Actively Exploited</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-langflow-cve-2026-0770-fifth-kev-entry-federal-friday/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T13:20:00.000Z</news:publication_date>
      <news:title>Langflow&apos;s fifth KEV entry: CVE-2026-0770, patch by Friday</news:title>
      <news:keywords>CVE-2026-0770, Langflow, CISA KEV, Zero Day Initiative, Trend Research, unauthenticated RCE, BOD 26-04</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-langflow-cve-2026-0770-fifth-kev-entry-federal-friday/cover.jpg</image:loc>
      <image:title>Langflow&apos;s fifth KEV entry: CVE-2026-0770, patch by Friday</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-lg-webos-residential-proxy-sdk-ban-spur-brightdata-42-percent/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T10:00:00.000Z</news:publication_date>
      <news:title>LG bans residential-proxy SDKs from webOS TV apps</news:title>
      <news:keywords>LG, webOS, residential proxies, Bright Data, Spur, smart TV, Samsung Tizen</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-lg-webos-residential-proxy-sdk-ban-spur-brightdata-42-percent/cover.jpg</image:loc>
      <image:title>LG bans residential-proxy SDKs from webOS TV apps</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-azure-devops-mcp-manifold-hidden-pr-comments-hijack-ai-reviewers-fuse/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T09:15:00.000Z</news:publication_date>
      <news:title>Azure DevOps MCP: hidden PR text hijacks AI reviewers</news:title>
      <news:keywords>Azure DevOps MCP, prompt injection, Manifold Security, Microsoft, AI coding agent, indirect prompt injection</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-azure-devops-mcp-manifold-hidden-pr-comments-hijack-ai-reviewers-fuse/cover.jpg</image:loc>
      <image:title>Azure DevOps MCP: hidden PR text hijacks AI reviewers</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-chick-fil-a-june-credential-stuffing-2182-texans-airgap/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T08:00:00.000Z</news:publication_date>
      <news:title>Chick-fil-A discloses June credential-stuffing breach</news:title>
      <news:keywords>Chick-fil-A, credential stuffing, data breach, loyalty program, password reuse, Chick-fil-A One</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-chick-fil-a-june-credential-stuffing-2182-texans-airgap/cover.jpg</image:loc>
      <image:title>Chick-fil-A discloses June credential-stuffing breach</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-jfrog-nuget-newtonsoftt-typosquat-digitain-fg-crash-kilobaud/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T07:00:00.000Z</news:publication_date>
      <news:title>A NuGet Typosquat That Rigged Games Instead of Wallets</news:title>
      <news:keywords>supply-chain, nuget, typosquat, newtonsoft-json, jfrog, digitain, dotnet</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-jfrog-nuget-newtonsoftt-typosquat-digitain-fg-crash-kilobaud/cover.jpg</image:loc>
      <image:title>A NuGet Typosquat That Rigged Games Instead of Wallets</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-22-openai-attributes-hugging-face-breach-gpt-5-6-sol-exploitgym/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T06:15:00.000Z</news:publication_date>
      <news:title>OpenAI attributes Hugging Face breach to GPT-5.6 Sol</news:title>
      <news:keywords>Hugging Face, OpenAI, GPT-5.6 Sol, ExploitGym, autonomous agent, AI safety, package registry</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-22-openai-attributes-hugging-face-breach-gpt-5-6-sol-exploitgym/cover.jpg</image:loc>
      <image:title>OpenAI attributes Hugging Face breach to GPT-5.6 Sol</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-cisa-kev-wp2shell-both-cves-added-bod-26-04-federal-clock/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T03:00:00.000Z</news:publication_date>
      <news:title>Both wp2shell CVEs land on CISA KEV — federal clock runs</news:title>
      <news:keywords>CISA KEV, wp2shell, CVE-2026-63030, CVE-2026-60137, WordPress, BOD 26-04</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-cisa-kev-wp2shell-both-cves-added-bod-26-04-federal-clock/cover.jpg</image:loc>
      <image:title>Both wp2shell CVEs land on CISA KEV — federal clock runs</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-zimbra-10-1-20-nine-bugs-snmp-command-injection-tops-list/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T23:45:00.000Z</news:publication_date>
      <news:title>Zimbra 10.1.20 patches nine, SNMP injection at the top</news:title>
      <news:keywords>Zimbra, Zimbra Collaboration Suite, Zimbra 10.1.20, SNMP command injection, Classic Web Client XSS, Nextcloud SSRF, patch release</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-zimbra-10-1-20-nine-bugs-snmp-command-injection-tops-list/cover.jpg</image:loc>
      <image:title>Zimbra 10.1.20 patches nine, SNMP injection at the top</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-kratos-phaas-olympus-blade-takedown-m365-passkeys-fuse/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T23:30:00.000Z</news:publication_date>
      <news:title>Kratos phishing platform seized. M365 exposure is not.</news:title>
      <news:keywords>Kratos PhaaS, phishing-as-a-service, Operation Olympus Blade, Microsoft 365, AiTM, passkeys, phishing-resistant MFA</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-kratos-phaas-olympus-blade-takedown-m365-passkeys-fuse/cover.jpg</image:loc>
      <image:title>Kratos phishing platform seized. M365 exposure is not.</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-sharepoint-cve-2026-50522-machine-keys-stolen-rotate-credentials-fuse/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:05:00.000Z</news:publication_date>
      <news:title>SharePoint attackers stealing keys — rotate credentials now</news:title>
      <news:keywords>CVE-2026-50522, Microsoft SharePoint, machine keys, watchTowr, Defused, credential rotation, persistence</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-sharepoint-cve-2026-50522-machine-keys-stolen-rotate-credentials-fuse/cover.jpg</image:loc>
      <image:title>SharePoint attackers stealing keys — rotate credentials now</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-thn-picus-n-hour-patching-mythos-verizon-dbir-analysis/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:15:00.000Z</news:publication_date>
      <news:title>Patch-to-exploit is hours. Patching still isn&apos;t optional.</news:title>
      <news:keywords>N-day, patch race, Mythos, Verizon DBIR, exposure validation, control effectiveness</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-thn-picus-n-hour-patching-mythos-verizon-dbir-analysis/cover.jpg</image:loc>
      <image:title>Patch-to-exploit is hours. Patching still isn&apos;t optional.</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-anubis-fairlife-1tb-nutanix-claim-declines-comment/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:15:00.000Z</news:publication_date>
      <news:title>Anubis claims Fairlife hit, 1TB and Nutanix encrypted</news:title>
      <news:keywords>Anubis ransomware, Coca-Cola Fairlife, Nutanix encryption, ransomware leak site, food and beverage ransomware</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-anubis-fairlife-1tb-nutanix-claim-declines-comment/cover.jpg</image:loc>
      <image:title>Anubis claims Fairlife hit, 1TB and Nutanix encrypted</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-apple-hide-my-email-mail-logs-july3-fix-year-disclosure/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:15:00.000Z</news:publication_date>
      <news:title>Apple fixes Hide My Email leak, year after disclosure</news:title>
      <news:keywords>Apple Hide My Email, iCloud+ alias leak, responsible disclosure, Mail logs metadata, 404 Media, Tyler Murphy</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-apple-hide-my-email-mail-logs-july3-fix-year-disclosure/cover.jpg</image:loc>
      <image:title>Apple fixes Hide My Email leak, year after disclosure</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-cisa-kev-dd-wrt-cve-2021-27137-upnp-ssdp-strcpy-r45724/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:15:00.000Z</news:publication_date>
      <news:title>DD-WRT UPnP flaw CVE-2021-27137 added to CISA KEV</news:title>
      <news:keywords>dd-wrt, cve-2021-27137, cisa-kev, upnp, ssdp, router, buffer-overflow</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-cisa-kev-dd-wrt-cve-2021-27137-upnp-ssdp-strcpy-r45724/cover.jpg</image:loc>
      <image:title>DD-WRT UPnP flaw CVE-2021-27137 added to CISA KEV</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-watchtowr-sharepoint-cve-2026-50522-devcore-third-july-patch-active-exploitation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T17:30:00.000Z</news:publication_date>
      <news:title>SharePoint CVE-2026-50522 exploited after public PoC</news:title>
      <news:keywords>CVE-2026-50522, Microsoft SharePoint, watchTowr, DEVCORE, deserialization, active exploitation, Patch Tuesday</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-watchtowr-sharepoint-cve-2026-50522-devcore-third-july-patch-active-exploitation/cover.jpg</image:loc>
      <image:title>SharePoint CVE-2026-50522 exploited after public PoC</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-wp2shell-mass-scanning-kevintel-watchtowr-wiz-fuse-triage/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T15:15:00.000Z</news:publication_date>
      <news:title>wp2shell mass scanning confirmed — patch triage tonight</news:title>
      <news:keywords>wp2shell, CVE-2026-63030, WordPress, mass exploitation, KEVIntel, watchTowr, Wiz</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-wp2shell-mass-scanning-kevintel-watchtowr-wiz-fuse-triage/cover.jpg</image:loc>
      <image:title>wp2shell mass scanning confirmed — patch triage tonight</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-aws-kiro-mcp-config-silent-rewrite-intezer-kodem-april-patch-july-disclosure/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T14:20:00.000Z</news:publication_date>
      <news:title>AWS patched a silent Kiro RCE in April, disclosed today</news:title>
      <news:keywords>AWS Kiro, agentic IDE, prompt injection, MCP, supply chain, AI agent security, Intezer</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-aws-kiro-mcp-config-silent-rewrite-intezer-kodem-april-patch-july-disclosure/cover.jpg</image:loc>
      <image:title>AWS patched a silent Kiro RCE in April, disclosed today</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-zhang-arxiv-android-mobile-agent-frameworks-overlay-adb-pivot/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T14:20:00.000Z</news:publication_date>
      <news:title>Android AI agent frameworks: overlay text pivots to host</news:title>
      <news:keywords>Android, AI agents, prompt injection, ADB, AppAgent, Mobile-Agent-v3, arXiv</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-zhang-arxiv-android-mobile-agent-frameworks-overlay-adb-pivot/cover.jpg</image:loc>
      <image:title>Android AI agent frameworks: overlay text pivots to host</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-bit2watt-zhejiang-ches-2026-gpu-cloud-tenant-grid-swings-analysis/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T13:15:00.000Z</news:publication_date>
      <news:title>Bit2Watt: what the GPU cloud tenant abstracts away</news:title>
      <news:keywords>Bit2Watt, Zhejiang University, CHES 2026, GPU cloud, data center grid, power grid harmonics, cloud tenant risk</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-bit2watt-zhejiang-ches-2026-gpu-cloud-tenant-grid-swings-analysis/cover.jpg</image:loc>
      <image:title>Bit2Watt: what the GPU cloud tenant abstracts away</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-qilin-pan-os-cve-2026-0257-globalprotect-arctic-wolf-june-exploitation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T12:00:00.000Z</news:publication_date>
      <news:title>Qilin exploits PAN-OS GlobalProtect CVE-2026-0257</news:title>
      <news:keywords>Qilin, PAN-OS, GlobalProtect, CVE-2026-0257, Arctic Wolf, ransomware, CISA KEV</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-qilin-pan-os-cve-2026-0257-globalprotect-arctic-wolf-june-exploitation/cover.jpg</image:loc>
      <image:title>Qilin exploits PAN-OS GlobalProtect CVE-2026-0257</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-microsoft-wsus-manual-fix-susdb-cleanup-maxxml-reindex-iisreset/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T10:30:00.000Z</news:publication_date>
      <news:title>Microsoft ships manual WSUS fix: SUSDB cleanup, IISReset</news:title>
      <news:keywords>WSUS, Windows Server Update Services, Microsoft, SUSDB, MaxXMLPerRequest, patch management, Configuration Manager</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-microsoft-wsus-manual-fix-susdb-cleanup-maxxml-reindex-iisreset/cover.jpg</image:loc>
      <image:title>Microsoft ships manual WSUS fix: SUSDB cleanup, IISReset</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-acros-0patch-legacyhive-free-micropatches-windows-10-server-2019/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T09:15:00.000Z</news:publication_date>
      <news:title>0patch ships free unofficial fix for LegacyHive zero-day</news:title>
      <news:keywords>LegacyHive, 0patch, ACROS Security, Windows zero-day, micropatch, User Profile Service, LPE</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-acros-0patch-legacyhive-free-micropatches-windows-10-server-2019/cover.jpg</image:loc>
      <image:title>0patch ships free unofficial fix for LegacyHive zero-day</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-jetbrains-teamcity-cve-2024-27198-epss-0999-two-years-past-patch/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T07:05:00.000Z</news:publication_date>
      <news:title>TeamCity CVE-2024-27198: EPSS 0.999 two years past patch</news:title>
      <news:keywords>jetbrains, teamcity, cve-2024-27198, kev, epss, ci-cd, supply-chain</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-jetbrains-teamcity-cve-2024-27198-epss-0999-two-years-past-patch/cover.jpg</image:loc>
      <image:title>TeamCity CVE-2024-27198: EPSS 0.999 two years past patch</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-signature-was-there-trust-wasnt-week-retrospective/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T06:15:00.000Z</news:publication_date>
      <news:title>The signature was there. The trust wasn&apos;t.</news:title>
      <news:keywords>code signing, trust chain, CylindricalCanine, DigiCert, HelloNet, UAT-11795, supply chain</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-signature-was-there-trust-wasnt-week-retrospective/cover.jpg</image:loc>
      <image:title>The signature was there. The trust wasn&apos;t.</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-mythos-three-months-exposure-window-triage-playbook/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T05:15:00.000Z</news:publication_date>
      <news:title>Mythos at three months: measure exposure, not volume</news:title>
      <news:keywords>Mythos, CVE triage, exposure window, KEV, EPSS, patch management, vulnerability management</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-mythos-three-months-exposure-window-triage-playbook/cover.jpg</image:loc>
      <image:title>Mythos at three months: measure exposure, not volume</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-volexity-uta0533-sonicwall-sma1000-knuckleball-orangetail-june22/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T04:15:00.000Z</news:publication_date>
      <news:title>Volexity ties SonicWall SMA1000 zero-days to UTA0533</news:title>
      <news:keywords>SonicWall SMA1000, CVE-2026-15409, CVE-2026-15410, UTA0533, Volexity, KNUCKLEBALL, ORANGETAIL, threat intel</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-volexity-uta0533-sonicwall-sma1000-knuckleball-orangetail-june22/cover.jpg</image:loc>
      <image:title>Volexity ties SonicWall SMA1000 zero-days to UTA0533</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-ai-agent-sandboxes-only-as-tight-as-host-tools/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T04:05:00.000Z</news:publication_date>
      <news:title>AI-agent sandboxes are only as tight as the host tools</news:title>
      <news:keywords>AI coding agents, sandbox escape, Pillar Security, agent security, Cursor, Codex CLI, Gemini CLI</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-ai-agent-sandboxes-only-as-tight-as-host-tools/cover.jpg</image:loc>
      <image:title>AI-agent sandboxes are only as tight as the host tools</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-ostium-arbitrum-off-chain-oracle-forgery-23-75m-lp-vault-drain/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T01:05:00.000Z</news:publication_date>
      <news:title>Ostium&apos;s LP vault down $23.75M after oracle-feed forgery</news:title>
      <news:keywords>Ostium, Arbitrum, price oracle, DEX, Tornado Cash, off-chain infrastructure</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-ostium-arbitrum-off-chain-oracle-forgery-23-75m-lp-vault-drain/cover.jpg</image:loc>
      <image:title>Ostium&apos;s LP vault down $23.75M after oracle-feed forgery</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-estee-lauder-cl0p-oracle-ebs-cve-2025-61882-bi-publisher-11-month-dwell/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T00:20:00.000Z</news:publication_date>
      <news:title>Estée Lauder confirms Cl0p Oracle EBS breach, 11mo dwell</news:title>
      <news:keywords>Estée Lauder, Cl0p, Oracle E-Business Suite, CVE-2025-61882, BI Publisher Integration, data breach, HR system</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-estee-lauder-cl0p-oracle-ebs-cve-2025-61882-bi-publisher-11-month-dwell/cover.jpg</image:loc>
      <image:title>Estée Lauder confirms Cl0p Oracle EBS breach, 11mo dwell</image:title>
    </image:image>
  </url>
</urlset>