<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://0daynews.com/articles/2026-09-20-kcp-cve-2026-61682-user-impersonation-front-proxy/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T10:00:00.000Z</news:publication_date>
      <news:title>kcp Front-Proxy Lets Attackers Impersonate Any User</news:title>
      <news:keywords>kcp, CVE-2026-61682, Kubernetes, user impersonation, front-proxy, cloud</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-20-kcp-cve-2026-61682-user-impersonation-front-proxy/cover.jpg</image:loc>
      <image:title>kcp Front-Proxy Lets Attackers Impersonate Any User</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-20-icinga2-cve-2026-61550-auth-bypass-dos-patched/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T09:00:00.000Z</news:publication_date>
      <news:title>Icinga 2 Patches CVSS 9.8 Auth Bypass and Stack Overflow</news:title>
      <news:keywords>Icinga, CVE-2026-61550, CVE-2026-61551, cluster security, monitoring, patch</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-20-icinga2-cve-2026-61550-auth-bypass-dos-patched/cover.jpg</image:loc>
      <image:title>Icinga 2 Patches CVSS 9.8 Auth Bypass and Stack Overflow</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-20-bragjack-ai-browser-agent-hijack/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T08:00:00.000Z</news:publication_date>
      <news:title>BragJack PoC Hijacks AI Browser Agents via Extensions</news:title>
      <news:keywords>BragJack, browser extensions, AI agents, Chrome, Edge, extension security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-20-bragjack-ai-browser-agent-hijack/cover.jpg</image:loc>
      <image:title>BragJack PoC Hijacks AI Browser Agents via Extensions</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-20-solarwinds-arm-cve-2026-28326-hardcoded-key-rce/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T04:30:00.000Z</news:publication_date>
      <news:title>SolarWinds ARM Hard-Coded Key Allows Unauthenticated RCE</news:title>
      <news:keywords>SolarWinds, Access Rights Manager, ARM, CVE-2026-28326, RCE, hard-coded key, patch</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-20-solarwinds-arm-cve-2026-28326-hardcoded-key-rce/cover.jpg</image:loc>
      <image:title>SolarWinds ARM Hard-Coded Key Allows Unauthenticated RCE</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-20-shinyhunters-hacks-clop-tor-site/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T04:00:00.000Z</news:publication_date>
      <news:title>ShinyHunters Breaches Clop Tor Site, Steals Onion Keys</news:title>
      <news:keywords>ShinyHunters, Clop, ransomware, extortion, Tor, onion keys, Grav CMS</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-20-shinyhunters-hacks-clop-tor-site/cover.jpg</image:loc>
      <image:title>ShinyHunters Breaches Clop Tor Site, Steals Onion Keys</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-19-microsoft-fabric-cve-2026-69843-cvss10-auth-bypass/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-19T14:00:00.000Z</news:publication_date>
      <news:title>Microsoft Fabric Auth Bypass Reaches CVSS 10.0</news:title>
      <news:keywords>microsoft fabric, CVE-2026-69843, authentication bypass, CVSS 10.0, cloud security, privilege escalation</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-19-microsoft-fabric-cve-2026-69843-cvss10-auth-bypass/cover.jpg</image:loc>
      <image:title>Microsoft Fabric Auth Bypass Reaches CVSS 10.0</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-19-azure-ai-foundry-cve-2026-85889-cvss10-privilege-escalation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-19T12:00:00.000Z</news:publication_date>
      <news:title>Microsoft Fixes CVSS 10.0 Flaw in Azure AI Foundry</news:title>
      <news:keywords>CVE-2026-85889, Azure AI Foundry, Microsoft, CVSS 10.0, privilege escalation, missing authentication, cloud security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-19-azure-ai-foundry-cve-2026-85889-cvss10-privilege-escalation/cover.jpg</image:loc>
      <image:title>Microsoft Fixes CVSS 10.0 Flaw in Azure AI Foundry</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-19-waterplum-north-korea-job-seekers-30k-devices/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-19T10:00:00.000Z</news:publication_date>
      <news:title>WaterPlum: North Korea Targets Job Seekers, 30K Devices Hit</news:title>
      <news:keywords>North Korea, WaterPlum, infostealers, fake job interviews, cryptocurrency theft, BeaverTail</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-19-waterplum-north-korea-job-seekers-30k-devices/cover.jpg</image:loc>
      <image:title>WaterPlum: North Korea Targets Job Seekers, 30K Devices Hit</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-19-cisa-kev-three-linux-kernel-exploited/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-19T08:30:00.000Z</news:publication_date>
      <news:title>CISA Adds Three Exploited Linux Kernel Flaws to KEV</news:title>
      <news:keywords>linux kernel, CISA KEV, CVE-2025-39682, CVE-2026-53266, CVE-2025-39964, exploitation, patch</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-19-cisa-kev-three-linux-kernel-exploited/cover.jpg</image:loc>
      <image:title>CISA Adds Three Exploited Linux Kernel Flaws to KEV</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-19-gyazo-breach-23m-records-oauth-tokens/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-19T08:00:00.000Z</news:publication_date>
      <news:title>Gyazo Breach Exposes 23M Records and OAuth Tokens</news:title>
      <news:keywords>data breach, Gyazo, OAuth tokens, Helpfeel, password hashes, image sharing</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-19-gyazo-breach-23m-records-oauth-tokens/cover.jpg</image:loc>
      <image:title>Gyazo Breach Exposes 23M Records and OAuth Tokens</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-18-ransomware-manufacturers-surge-supply-chain-2026/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T13:00:00.000Z</news:publication_date>
      <news:title>Ransomware Attacks on Manufacturers Up 40% in H1 2026</news:title>
      <news:keywords>ransomware, manufacturing, supply-chain, operational-technology, threat-intel, The-Gentlemen</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-18-ransomware-manufacturers-surge-supply-chain-2026/cover.jpg</image:loc>
      <image:title>Ransomware Attacks on Manufacturers Up 40% in H1 2026</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-18-orkes-conductor-cve-2026-58138-rce-exploited/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T12:00:00.000Z</news:publication_date>
      <news:title>Orkes Conductor RCE CVE-2026-58138 Exploited in Attacks</news:title>
      <news:keywords>orkes, conductor, CVE-2026-58138, RCE, workflow-orchestration, unauthenticated</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-18-orkes-conductor-cve-2026-58138-rce-exploited/cover.jpg</image:loc>
      <image:title>Orkes Conductor RCE CVE-2026-58138 Exploited in Attacks</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-18-unbound-cve-2026-81642-dnssec-rce/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-18T10:00:00.000Z</news:publication_date>
      <news:title>Unbound 1.26.1 Fixes Critical DNSSEC Heap Overflow</news:title>
      <news:keywords>unbound, dns, dnssec, heap-overflow, rce, CVE-2026-81642, nlnetlabs</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-18-unbound-cve-2026-81642-dnssec-rce/cover.jpg</image:loc>
      <image:title>Unbound 1.26.1 Fixes Critical DNSSEC Heap Overflow</image:title>
    </image:image>
  </url>
</urlset>