<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://0daynews.com/articles/2026-09-26-elementor-csrf-admin-account-creation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T14:00:00.000Z</news:publication_date>
      <news:title>Elementor CSRF Flaw Lets Attackers Create Admin Accounts</news:title>
      <news:keywords>wordpress, elementor, csrf, privilege-escalation, plugin-security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-26-elementor-csrf-admin-account-creation/cover.jpg</image:loc>
      <image:title>Elementor CSRF Flaw Lets Attackers Create Admin Accounts</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-26-mikrotik-cve-2026-67279-cisa-kev-chain/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T14:00:00.000Z</news:publication_date>
      <news:title>CISA Adds MikroTik RouterOS Chain Flaw to KEV Catalog</news:title>
      <news:keywords>mikrotik, routeros, cve-2026-67279, cve-2026-86060, cisa kev, vulnerability chain, network security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-26-mikrotik-cve-2026-67279-cisa-kev-chain/cover.jpg</image:loc>
      <image:title>CISA Adds MikroTik RouterOS Chain Flaw to KEV Catalog</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-26-kiteworks-zero-day-warning-server-shutdown/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T12:00:00.000Z</news:publication_date>
      <news:title>Kiteworks Flags Potential Zero-Day, Urges Server Shutdown</news:title>
      <news:keywords>kiteworks, zero-day, managed file transfer, enterprise security, secure file sharing, mft</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-26-kiteworks-zero-day-warning-server-shutdown/cover.jpg</image:loc>
      <image:title>Kiteworks Flags Potential Zero-Day, Urges Server Shutdown</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-26-clop-moves-leak-site-grav-cms-attack-confirmed/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T08:00:00.000Z</news:publication_date>
      <news:title>Clop Moves Leak Site After Grav CMS Attack Confirmed</news:title>
      <news:keywords>Clop, ShinyHunters, Grav CMS, ransomware, path traversal, data leak site, threat actors</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-26-clop-moves-leak-site-grav-cms-attack-confirmed/cover.jpg</image:loc>
      <image:title>Clop Moves Leak Site After Grav CMS Attack Confirmed</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-26-soldier-70-months-att-verizon-telecom-extortion/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T06:00:00.000Z</news:publication_date>
      <news:title>U.S. Soldier Gets 70 Months for Telecom Extortion</news:title>
      <news:keywords>AT&amp;T, Verizon, telecom, extortion, sentencing, data theft, US Army</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-26-soldier-70-months-att-verizon-telecom-extortion/cover.jpg</image:loc>
      <image:title>U.S. Soldier Gets 70 Months for Telecom Extortion</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-25-bitget-dprk-crypto-theft-351-million/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T12:00:00.000Z</news:publication_date>
      <news:title>Suspected DPRK Hackers Steal $351.6M from Bitget</news:title>
      <news:keywords>bitget, north-korea, dprk, crypto-exchange, wallet-theft, backend-compromise</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-25-bitget-dprk-crypto-theft-351-million/cover.jpg</image:loc>
      <image:title>Suspected DPRK Hackers Steal $351.6M from Bitget</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-25-salesbleed-salesforce-agentforce-zero-click-data-exfiltration/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T10:00:00.000Z</news:publication_date>
      <news:title>SalesBleed: Agentforce Flaws Enable Data Exfiltration</news:title>
      <news:keywords>salesforce, agentforce, prompt injection, data exfiltration, agentic ai, salesbleed, cloud security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-25-salesbleed-salesforce-agentforce-zero-click-data-exfiltration/cover.jpg</image:loc>
      <image:title>SalesBleed: Agentforce Flaws Enable Data Exfiltration</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-25-wso2-adobe-commerce-cisa-kev-cve-2026-5430-cve-2026-71362/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T08:00:00.000Z</news:publication_date>
      <news:title>CISA KEV: WSO2 and Adobe Commerce Flaws Exploited</news:title>
      <news:keywords>WSO2, Adobe Commerce, Magento, CISA KEV, CVE-2026-5430, CVE-2026-71362, patch deadline</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-25-wso2-adobe-commerce-cisa-kev-cve-2026-5430-cve-2026-71362/cover.jpg</image:loc>
      <image:title>CISA KEV: WSO2 and Adobe Commerce Flaws Exploited</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-25-macsync-macos-icloud-calendar-c2/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T06:00:00.000Z</news:publication_date>
      <news:title>MacSync macOS Malware Abuses Public iCloud Calendars</news:title>
      <news:keywords>macsync, macos, malware, icloud, infostealer, c2, clickfix, kaspersky</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-25-macsync-macos-icloud-calendar-c2/cover.jpg</image:loc>
      <image:title>MacSync macOS Malware Abuses Public iCloud Calendars</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-25-vardanyan-ryuk-ransomware-sentenced-two-years/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-25T06:00:00.000Z</news:publication_date>
      <news:title>Ryuk Member Gets 2 Years for $1.2M Ransomware Attacks</news:title>
      <news:keywords>Ryuk ransomware, Karen Vardanyan, sentencing, ransomware enforcement, cybercrime prosecution</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-25-vardanyan-ryuk-ransomware-sentenced-two-years/cover.jpg</image:loc>
      <image:title>Ryuk Member Gets 2 Years for $1.2M Ransomware Attacks</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-24-roundcube-cve-2026-48842-active-exploit-sql-injection/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-24T14:30:00.000Z</news:publication_date>
      <news:title>Roundcube SQL Injection Flaw Under Active Attack</news:title>
      <news:keywords>roundcube, sql-injection, CVE-2026-48842, webmail, active-exploitation, patch</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-24-roundcube-cve-2026-48842-active-exploit-sql-injection/cover.jpg</image:loc>
      <image:title>Roundcube SQL Injection Flaw Under Active Attack</image:title>
    </image:image>
  </url>
</urlset>