<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://0daynews.com/articles/2026-08-15-evooo1bot-linux-botnet-routers-socks5-relay/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-15T18:00:00.000Z</news:publication_date>
      <news:title>Evooo1Bot Turns Routers Into SOCKS5 Relay Nodes</news:title>
      <news:keywords>evooo1bot, linux botnet, mirai, socks5, proxy network, router security, threat intel</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-15-evooo1bot-linux-botnet-routers-socks5-relay/cover.jpg</image:loc>
      <image:title>Evooo1Bot Turns Routers Into SOCKS5 Relay Nodes</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-15-mcp-memory-service-cve-2026-50027-auth-bypass/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-15T16:00:00.000Z</news:publication_date>
      <news:title>Unauth Access to AI Memory: CVE-2026-50027 Patched</news:title>
      <news:keywords>CVE-2026-50027, mcp-memory-service, authentication bypass, ai-security, mcp, semantic-memory</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-15-mcp-memory-service-cve-2026-50027-auth-bypass/cover.jpg</image:loc>
      <image:title>Unauth Access to AI Memory: CVE-2026-50027 Patched</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-15-cve-2026-69414-shieldbreak-malware-protection-engine/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-15T14:00:00.000Z</news:publication_date>
      <news:title>ShieldBreak: New Unpatched EoP in Defender Scan Engine</news:title>
      <news:keywords>shieldbreak, microsoft defender, malware protection engine, CVE-2026-69414, elevation of privilege, windows</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-15-cve-2026-69414-shieldbreak-malware-protection-engine/cover.jpg</image:loc>
      <image:title>ShieldBreak: New Unpatched EoP in Defender Scan Engine</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-15-cisa-icsa-26-225-01-ics-deserialization-cve-2025-7639/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-15T12:00:00.000Z</news:publication_date>
      <news:title>CISA ICS Advisory: SCADA Deserialization Bug CVE-2025-7639</news:title>
      <news:keywords>cve-2025-7639, icsa-26-225-01, cisa ics advisory, scada deserialization, industrial control system, privilege escalation, ot security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-15-cisa-icsa-26-225-01-ics-deserialization-cve-2025-7639/cover.jpg</image:loc>
      <image:title>CISA ICS Advisory: SCADA Deserialization Bug CVE-2025-7639</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-15-nist-ai-cve-backlog-vulnerability-surge/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-15T10:00:00.000Z</news:publication_date>
      <news:title>NIST Bets on AI to Clear AI-Created CVE Backlog</news:title>
      <news:keywords>NVD, NIST, CVE, vulnerability management, AI security, CVSS, patch prioritization</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-15-nist-ai-cve-backlog-vulnerability-surge/cover.jpg</image:loc>
      <image:title>NIST Bets on AI to Clear AI-Created CVE Backlog</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-15-geoserver-sqli-rce-zero-day-exploited/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-15T08:00:00.000Z</news:publication_date>
      <news:title>GeoServer Zero-Day Under Active Attack, No Patch Available</news:title>
      <news:keywords>GeoServer, SQL injection, zero-day, RCE, PostGIS, geospatial, active exploitation</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-15-geoserver-sqli-rce-zero-day-exploited/cover.jpg</image:loc>
      <image:title>GeoServer Zero-Day Under Active Attack, No Patch Available</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-15-openwrt-luci-critical-root-rce/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-15T06:00:00.000Z</news:publication_date>
      <news:title>Three Critical OpenWrt LuCI Flaws Allow Root RCE</news:title>
      <news:keywords>openwrt, luci, rce, router, path-traversal, cve, patch</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-15-openwrt-luci-critical-root-rce/cover.jpg</image:loc>
      <image:title>Three Critical OpenWrt LuCI Flaws Allow Root RCE</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-15-trivy-not-litellm-supply-chain-march/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-15T04:30:00.000Z</news:publication_date>
      <news:title>Trivy, Not LiteLLM, Drove the March Supply Chain Breach</news:title>
      <news:keywords>supply chain, Trivy, LiteLLM, SOCRadar, CI/CD security, credential theft, PyPI</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-15-trivy-not-litellm-supply-chain-march/cover.jpg</image:loc>
      <image:title>Trivy, Not LiteLLM, Drove the March Supply Chain Breach</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-14-scotland-copfs-breach-third-party/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T22:00:00.000Z</news:publication_date>
      <news:title>Scottish Crown Office Breach May Spread Across Agencies</news:title>
      <news:keywords>data breach, Scotland, Crown Office, COPFS, third-party, government, supply chain</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-14-scotland-copfs-breach-third-party/cover.jpg</image:loc>
      <image:title>Scottish Crown Office Breach May Spread Across Agencies</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-14-commerzbank-bka-bank-fraud-arrests/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T20:00:00.000Z</news:publication_date>
      <news:title>Seven Arrested in €30M Commerzbank Account Fraud</news:title>
      <news:keywords>commerzbank, bank fraud, cybercrime arrests, BKA, germany, brazil, service-provider breach</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-14-commerzbank-bka-bank-fraud-arrests/cover.jpg</image:loc>
      <image:title>Seven Arrested in €30M Commerzbank Account Fraud</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-14-france-dgfip-tax-breach-600k/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T20:00:00.000Z</news:publication_date>
      <news:title>France Confirms DGFIP Breach; Hacker Claims 600K</news:title>
      <news:keywords>France, DGFIP, data breach, government breach, credential theft, tax authority, Europe</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-14-france-dgfip-tax-breach-600k/cover.jpg</image:loc>
      <image:title>France Confirms DGFIP Breach; Hacker Claims 600K</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-14-amnesiastealer-macos-clickfix-browser-hijack/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T18:00:00.000Z</news:publication_date>
      <news:title>AmnesiaStealer Hijacks macOS Browser Sessions</news:title>
      <news:keywords>macOS, malware, AmnesiaStealer, ClickFix, infostealer, browser hijacking, Jamf</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-14-amnesiastealer-macos-clickfix-browser-hijack/cover.jpg</image:loc>
      <image:title>AmnesiaStealer Hijacks macOS Browser Sessions</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-14-macos-screen-sharing-auth-bypass-exploited/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T18:00:00.000Z</news:publication_date>
      <news:title>macOS Screen Sharing Auth Bypass Exploited in Wild</news:title>
      <news:keywords>macOS, Screen Sharing, authentication bypass, exploitation, Monero miner, NCSC, active exploitation</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-14-macos-screen-sharing-auth-bypass-exploited/cover.jpg</image:loc>
      <image:title>macOS Screen Sharing Auth Bypass Exploited in Wild</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-14-sap-commerce-cloud-rce-exploitation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T16:30:00.000Z</news:publication_date>
      <news:title>SAP Commerce Cloud RCE Exploit Hits Days After Patch</news:title>
      <news:keywords>SAP, Commerce Cloud, RCE, remote code execution, patch, active exploitation, enterprise</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-14-sap-commerce-cloud-rce-exploitation/cover.jpg</image:loc>
      <image:title>SAP Commerce Cloud RCE Exploit Hits Days After Patch</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-14-shell-clop-89gb-data-theft-claim/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T14:30:00.000Z</news:publication_date>
      <news:title>Clop Claims 89GB Shell Theft; Investigation Open</news:title>
      <news:keywords>Clop, Shell, data-theft, extortion, ransomware, oil-gas, investigation</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-14-shell-clop-89gb-data-theft-claim/cover.jpg</image:loc>
      <image:title>Clop Claims 89GB Shell Theft; Investigation Open</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T12:00:00.000Z</news:publication_date>
      <news:title>ShinyHunters Hits RingCentral: 1.6M Accounts Exposed</news:title>
      <news:keywords>ringcentral, shinyhunters, data-breach, extortion, pii, telecom, breach-notification</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts/cover.jpg</image:loc>
      <image:title>ShinyHunters Hits RingCentral: 1.6M Accounts Exposed</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-14-beacon-crm-breach-charities-aws-key/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T10:00:00.000Z</news:publication_date>
      <news:title>Beacon CRM Breach Hits 1,000+ Charities via AWS Key</news:title>
      <news:keywords>beacon, charity, data-breach, aws-credentials, cloud-security, crm, access-key</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-14-beacon-crm-breach-charities-aws-key/cover.jpg</image:loc>
      <image:title>Beacon CRM Breach Hits 1,000+ Charities via AWS Key</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-14-wordpress-704-rce-imagick-ghostscript/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T10:00:00.000Z</news:publication_date>
      <news:title>WordPress 7.0.4 Patches High-Severity RCE Flaw</news:title>
      <news:keywords>wordpress, rce, imagick, ghostscript, postscript, file-upload, patch</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-14-wordpress-704-rce-imagick-ghostscript/cover.jpg</image:loc>
      <image:title>WordPress 7.0.4 Patches High-Severity RCE Flaw</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-14-geoserver-zero-day-rce-active-exploitation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T08:00:00.000Z</news:publication_date>
      <news:title>GeoServer Zero-Day SQL Injection Exploited in Wild</news:title>
      <news:keywords>geoserver, zero-day, sql-injection, rce, active-exploitation, unpatched, geospatial</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-14-geoserver-zero-day-rce-active-exploitation/cover.jpg</image:loc>
      <image:title>GeoServer Zero-Day SQL Injection Exploited in Wild</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-14-apple-mercenary-spyware-threat-notifications/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T02:00:00.000Z</news:publication_date>
      <news:title>Apple Notifies Users of Mercenary Spyware Attacks</news:title>
      <news:keywords>apple, mercenary-spyware, iphone, threat-notification, mobile-security, surveillance, lockdown-mode</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-14-apple-mercenary-spyware-threat-notifications/cover.jpg</image:loc>
      <image:title>Apple Notifies Users of Mercenary Spyware Attacks</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-14-belgium-eid-browser-extension-rce/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T02:00:00.000Z</news:publication_date>
      <news:title>Belgium eID Browser Extension Bugs Enable RCE</news:title>
      <news:keywords>Belgium, eID, browser extension, RCE, authentication, national identity, trust framework</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-14-belgium-eid-browser-extension-rce/cover.jpg</image:loc>
      <image:title>Belgium eID Browser Extension Bugs Enable RCE</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-13-legacyhive-windows-zero-day-patch/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T00:00:00.000Z</news:publication_date>
      <news:title>Microsoft Patches LegacyHive Windows Zero-Day</news:title>
      <news:keywords>legacyhive, microsoft, windows, zero-day, patch, registry, windows-security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-13-legacyhive-windows-zero-day-patch/cover.jpg</image:loc>
      <image:title>Microsoft Patches LegacyHive Windows Zero-Day</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-13-akira-edr-safe-mode-bypass-data-theft/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-13T22:00:00.000Z</news:publication_date>
      <news:title>Akira Disables EDR via Safe Mode Reboot, Steals Data</news:title>
      <news:keywords>akira, ransomware, edr-bypass, safe-mode, exfiltration, endpoint-detection, ttps</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-13-akira-edr-safe-mode-bypass-data-theft/cover.jpg</image:loc>
      <image:title>Akira Disables EDR via Safe Mode Reboot, Steals Data</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-08-13-vcenter-cve-2026-59310-reverse-ssh-persistence/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-13T20:00:00.000Z</news:publication_date>
      <news:title>VMware vCenter Exploit Deploys Reverse SSH Backdoor</news:title>
      <news:keywords>vmware, vcenter, CVE-2026-59310, reverse ssh, persistence, active exploitation, broadcom</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-08-13-vcenter-cve-2026-59310-reverse-ssh-persistence/cover.jpg</image:loc>
      <image:title>VMware vCenter Exploit Deploys Reverse SSH Backdoor</image:title>
    </image:image>
  </url>
</urlset>