<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-anubis-fairlife-1tb-nutanix-claim-declines-comment/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:15:00.000Z</news:publication_date>
      <news:title>Anubis claims Fairlife hit, 1TB and Nutanix encrypted</news:title>
      <news:keywords>Anubis ransomware, Coca-Cola Fairlife, Nutanix encryption, ransomware leak site, food and beverage ransomware</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-anubis-fairlife-1tb-nutanix-claim-declines-comment/cover.jpg</image:loc>
      <image:title>Anubis claims Fairlife hit, 1TB and Nutanix encrypted</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-cisa-kev-dd-wrt-cve-2021-27137-upnp-ssdp-strcpy-r45724/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:15:00.000Z</news:publication_date>
      <news:title>DD-WRT UPnP flaw CVE-2021-27137 added to CISA KEV</news:title>
      <news:keywords>dd-wrt, cve-2021-27137, cisa-kev, upnp, ssdp, router, buffer-overflow</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-cisa-kev-dd-wrt-cve-2021-27137-upnp-ssdp-strcpy-r45724/cover.jpg</image:loc>
      <image:title>DD-WRT UPnP flaw CVE-2021-27137 added to CISA KEV</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-watchtowr-sharepoint-cve-2026-50522-devcore-third-july-patch-active-exploitation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T17:30:00.000Z</news:publication_date>
      <news:title>SharePoint CVE-2026-50522 exploited after public PoC</news:title>
      <news:keywords>CVE-2026-50522, Microsoft SharePoint, watchTowr, DEVCORE, deserialization, active exploitation, Patch Tuesday</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-watchtowr-sharepoint-cve-2026-50522-devcore-third-july-patch-active-exploitation/cover.jpg</image:loc>
      <image:title>SharePoint CVE-2026-50522 exploited after public PoC</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-wp2shell-mass-scanning-kevintel-watchtowr-wiz-fuse-triage/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T15:15:00.000Z</news:publication_date>
      <news:title>wp2shell mass scanning confirmed — patch triage tonight</news:title>
      <news:keywords>wp2shell, CVE-2026-63030, WordPress, mass exploitation, KEVIntel, watchTowr, Wiz</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-wp2shell-mass-scanning-kevintel-watchtowr-wiz-fuse-triage/cover.jpg</image:loc>
      <image:title>wp2shell mass scanning confirmed — patch triage tonight</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-aws-kiro-mcp-config-silent-rewrite-intezer-kodem-april-patch-july-disclosure/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T14:20:00.000Z</news:publication_date>
      <news:title>AWS patched a silent Kiro RCE in April, disclosed today</news:title>
      <news:keywords>AWS Kiro, agentic IDE, prompt injection, MCP, supply chain, AI agent security, Intezer</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-aws-kiro-mcp-config-silent-rewrite-intezer-kodem-april-patch-july-disclosure/cover.jpg</image:loc>
      <image:title>AWS patched a silent Kiro RCE in April, disclosed today</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-zhang-arxiv-android-mobile-agent-frameworks-overlay-adb-pivot/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T14:20:00.000Z</news:publication_date>
      <news:title>Android AI agent frameworks: overlay text pivots to host</news:title>
      <news:keywords>Android, AI agents, prompt injection, ADB, AppAgent, Mobile-Agent-v3, arXiv</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-zhang-arxiv-android-mobile-agent-frameworks-overlay-adb-pivot/cover.jpg</image:loc>
      <image:title>Android AI agent frameworks: overlay text pivots to host</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-bit2watt-zhejiang-ches-2026-gpu-cloud-tenant-grid-swings-analysis/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T13:15:00.000Z</news:publication_date>
      <news:title>Bit2Watt: what the GPU cloud tenant abstracts away</news:title>
      <news:keywords>Bit2Watt, Zhejiang University, CHES 2026, GPU cloud, data center grid, power grid harmonics, cloud tenant risk</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-bit2watt-zhejiang-ches-2026-gpu-cloud-tenant-grid-swings-analysis/cover.jpg</image:loc>
      <image:title>Bit2Watt: what the GPU cloud tenant abstracts away</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-qilin-pan-os-cve-2026-0257-globalprotect-arctic-wolf-june-exploitation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T12:00:00.000Z</news:publication_date>
      <news:title>Qilin exploits PAN-OS GlobalProtect CVE-2026-0257</news:title>
      <news:keywords>Qilin, PAN-OS, GlobalProtect, CVE-2026-0257, Arctic Wolf, ransomware, CISA KEV</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-qilin-pan-os-cve-2026-0257-globalprotect-arctic-wolf-june-exploitation/cover.jpg</image:loc>
      <image:title>Qilin exploits PAN-OS GlobalProtect CVE-2026-0257</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-microsoft-wsus-manual-fix-susdb-cleanup-maxxml-reindex-iisreset/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T10:30:00.000Z</news:publication_date>
      <news:title>Microsoft ships manual WSUS fix: SUSDB cleanup, IISReset</news:title>
      <news:keywords>WSUS, Windows Server Update Services, Microsoft, SUSDB, MaxXMLPerRequest, patch management, Configuration Manager</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-microsoft-wsus-manual-fix-susdb-cleanup-maxxml-reindex-iisreset/cover.jpg</image:loc>
      <image:title>Microsoft ships manual WSUS fix: SUSDB cleanup, IISReset</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-acros-0patch-legacyhive-free-micropatches-windows-10-server-2019/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T09:15:00.000Z</news:publication_date>
      <news:title>0patch ships free unofficial fix for LegacyHive zero-day</news:title>
      <news:keywords>LegacyHive, 0patch, ACROS Security, Windows zero-day, micropatch, User Profile Service, LPE</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-acros-0patch-legacyhive-free-micropatches-windows-10-server-2019/cover.jpg</image:loc>
      <image:title>0patch ships free unofficial fix for LegacyHive zero-day</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-jetbrains-teamcity-cve-2024-27198-epss-0999-two-years-past-patch/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T07:05:00.000Z</news:publication_date>
      <news:title>TeamCity CVE-2024-27198: EPSS 0.999 two years past patch</news:title>
      <news:keywords>jetbrains, teamcity, cve-2024-27198, kev, epss, ci-cd, supply-chain</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-jetbrains-teamcity-cve-2024-27198-epss-0999-two-years-past-patch/cover.jpg</image:loc>
      <image:title>TeamCity CVE-2024-27198: EPSS 0.999 two years past patch</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-signature-was-there-trust-wasnt-week-retrospective/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T06:15:00.000Z</news:publication_date>
      <news:title>The signature was there. The trust wasn&apos;t.</news:title>
      <news:keywords>code signing, trust chain, CylindricalCanine, DigiCert, HelloNet, UAT-11795, supply chain</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-signature-was-there-trust-wasnt-week-retrospective/cover.jpg</image:loc>
      <image:title>The signature was there. The trust wasn&apos;t.</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-mythos-three-months-exposure-window-triage-playbook/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T05:15:00.000Z</news:publication_date>
      <news:title>Mythos at three months: measure exposure, not volume</news:title>
      <news:keywords>Mythos, CVE triage, exposure window, KEV, EPSS, patch management, vulnerability management</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-mythos-three-months-exposure-window-triage-playbook/cover.jpg</image:loc>
      <image:title>Mythos at three months: measure exposure, not volume</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-volexity-uta0533-sonicwall-sma1000-knuckleball-orangetail-june22/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T04:15:00.000Z</news:publication_date>
      <news:title>Volexity ties SonicWall SMA1000 zero-days to UTA0533</news:title>
      <news:keywords>SonicWall SMA1000, CVE-2026-15409, CVE-2026-15410, UTA0533, Volexity, KNUCKLEBALL, ORANGETAIL, threat intel</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-volexity-uta0533-sonicwall-sma1000-knuckleball-orangetail-june22/cover.jpg</image:loc>
      <image:title>Volexity ties SonicWall SMA1000 zero-days to UTA0533</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-ai-agent-sandboxes-only-as-tight-as-host-tools/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T04:05:00.000Z</news:publication_date>
      <news:title>AI-agent sandboxes are only as tight as the host tools</news:title>
      <news:keywords>AI coding agents, sandbox escape, Pillar Security, agent security, Cursor, Codex CLI, Gemini CLI</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-ai-agent-sandboxes-only-as-tight-as-host-tools/cover.jpg</image:loc>
      <image:title>AI-agent sandboxes are only as tight as the host tools</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-ostium-arbitrum-off-chain-oracle-forgery-23-75m-lp-vault-drain/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T01:05:00.000Z</news:publication_date>
      <news:title>Ostium&apos;s LP vault down $23.75M after oracle-feed forgery</news:title>
      <news:keywords>Ostium, Arbitrum, price oracle, DEX, Tornado Cash, off-chain infrastructure</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-ostium-arbitrum-off-chain-oracle-forgery-23-75m-lp-vault-drain/cover.jpg</image:loc>
      <image:title>Ostium&apos;s LP vault down $23.75M after oracle-feed forgery</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-21-estee-lauder-cl0p-oracle-ebs-cve-2025-61882-bi-publisher-11-month-dwell/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T00:20:00.000Z</news:publication_date>
      <news:title>Estée Lauder confirms Cl0p Oracle EBS breach, 11mo dwell</news:title>
      <news:keywords>Estée Lauder, Cl0p, Oracle E-Business Suite, CVE-2025-61882, BI Publisher Integration, data breach, HR system</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-21-estee-lauder-cl0p-oracle-ebs-cve-2025-61882-bi-publisher-11-month-dwell/cover.jpg</image:loc>
      <image:title>Estée Lauder confirms Cl0p Oracle EBS breach, 11mo dwell</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-jadepuffer-encforge-ai-asset-ransomware-model-weights-vector-dbs/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:15:00.000Z</news:publication_date>
      <news:title>Sysdig: JADEPUFFER now ships EncForge, targets model weights</news:title>
      <news:keywords>JADEPUFFER, EncForge, AI ransomware, Sysdig, Langflow, model checkpoints</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-jadepuffer-encforge-ai-asset-ransomware-model-weights-vector-dbs/cover.jpg</image:loc>
      <image:title>Sysdig: JADEPUFFER now ships EncForge, targets model weights</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-pillar-week-sandbox-escapes-cursor-codex-gemini-cli-antigravity/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:15:00.000Z</news:publication_date>
      <news:title>Cursor, Codex, Gemini CLI, Antigravity: sandbox escapes</news:title>
      <news:keywords>AI coding agents, sandbox escape, Cursor, Codex CLI, Gemini CLI, Antigravity, Pillar Security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-pillar-week-sandbox-escapes-cursor-codex-gemini-cli-antigravity/cover.jpg</image:loc>
      <image:title>Cursor, Codex, Gemini CLI, Antigravity: sandbox escapes</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-island-fakegit-7600-github-mcp-smartloader-agentbaiting/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:00:00.000Z</news:publication_date>
      <news:title>FakeGit: 7,600 GitHub repos push SmartLoader via MCP lure</news:title>
      <news:keywords>FakeGit, SmartLoader, MCP servers, GitHub supply chain, AgentBaiting, Island, StealC, LobeHub</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-island-fakegit-7600-github-mcp-smartloader-agentbaiting/cover.jpg</image:loc>
      <image:title>FakeGit: 7,600 GitHub repos push SmartLoader via MCP lure</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-group-ib-hollowgraph-m365-calendar-events-2050-c2-dead-drop/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T16:20:00.000Z</news:publication_date>
      <news:title>HollowGraph hides M365 C2 in calendar events dated 2050</news:title>
      <news:keywords>hollowgraph, group-ib, microsoft-365, microsoft-graph-api, calendar-c2, dead-drop, entra-id, espionage</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-group-ib-hollowgraph-m365-calendar-events-2050-c2-dead-drop/cover.jpg</image:loc>
      <image:title>HollowGraph hides M365 C2 in calendar events dated 2050</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-rapid7-exposed-webdav-lab-1048-artifacts-mexico-curp-victims/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T15:15:00.000Z</news:publication_date>
      <news:title>Exposed WebDAV lab: 1,048 artifacts, real Mexico victims</news:title>
      <news:keywords>Rapid7, WebDAV, CURP, PureRAT, Mexico, malware delivery, CVE-2025-33053</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-rapid7-exposed-webdav-lab-1048-artifacts-mexico-curp-victims/cover.jpg</image:loc>
      <image:title>Exposed WebDAV lab: 1,048 artifacts, real Mexico victims</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-aivd-mivd-russian-intel-ip-cameras-nato-military-transport-ukraine/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T14:15:00.000Z</news:publication_date>
      <news:title>AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes</news:title>
      <news:keywords>AIVD, MIVD, IP cameras, Russia, Ukraine, NATO, military logistics</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-aivd-mivd-russian-intel-ip-cameras-nato-military-transport-ukraine/cover.jpg</image:loc>
      <image:title>AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-wsus-sync-fix-new-installs-only-old-servers-metadata-cleanup/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T13:15:00.000Z</news:publication_date>
      <news:title>WSUS sync fix only for new installs, old servers still stuck</news:title>
      <news:keywords>WSUS, Windows Server Update Services, Microsoft, Windows Server, Configuration Manager, patch management, sync failure</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-wsus-sync-fix-new-installs-only-old-servers-metadata-cleanup/cover.jpg</image:loc>
      <image:title>WSUS sync fix only for new installs, old servers still stuck</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-trend-micro-bandcampro-gemini-cli-c2-dental-clinic-eight-node-botnet/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T12:00:00.000Z</news:publication_date>
      <news:title>Trend Micro: &apos;bandcampro&apos; ran botnet ops through Gemini CLI</news:title>
      <news:keywords>Google Gemini CLI, bandcampro, Trend Micro, botnet, OpenDental, Patriot Bait, AI-assisted intrusions</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-trend-micro-bandcampro-gemini-cli-c2-dental-clinic-eight-node-botnet/cover.jpg</image:loc>
      <image:title>Trend Micro: &apos;bandcampro&apos; ran botnet ops through Gemini CLI</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-microsoft-kb5121767-oob-dell-intel-ipf-driver-hold-fix/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T11:15:00.000Z</news:publication_date>
      <news:title>Microsoft ships KB5121767 OOB for Dell IPF driver hold</news:title>
      <news:keywords>Microsoft, KB5121767, Windows 11, Dell, Intel IPF, out-of-band update, KB5101650, safeguard hold</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-microsoft-kb5121767-oob-dell-intel-ipf-driver-hold-fix/cover.jpg</image:loc>
      <image:title>Microsoft ships KB5121767 OOB for Dell IPF driver hold</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-servicenow-ai-platform-cve-2026-6875-defused-exploitation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T10:30:00.000Z</news:publication_date>
      <news:title>ServiceNow AI Platform RCE exploited in wild: CVE-2026-6875</news:title>
      <news:keywords>ServiceNow, CVE-2026-6875, AI Platform, remote code execution, Defused, active exploitation</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-servicenow-ai-platform-cve-2026-6875-defused-exploitation/cover.jpg</image:loc>
      <image:title>ServiceNow AI Platform RCE exploited in wild: CVE-2026-6875</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-hugging-face-autonomous-ai-agent-breach-internal-datasets/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T09:00:00.000Z</news:publication_date>
      <news:title>Hugging Face confirms breach by autonomous AI agent</news:title>
      <news:keywords>Hugging Face, autonomous AI agent, supply chain, dataset loader, template injection, GLM 5.2, AI security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-hugging-face-autonomous-ai-agent-breach-internal-datasets/cover.jpg</image:loc>
      <image:title>Hugging Face confirms breach by autonomous AI agent</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-stepsecurity-sleepergem-rubygems-dormant-accounts-forgejo-loader/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T08:00:00.000Z</news:publication_date>
      <news:title>SleeperGem loader hides in dormant RubyGems, skips CI/CD</news:title>
      <news:keywords>SleeperGem, StepSecurity, RubyGems supply chain, git_credential_manager, Dendreo, Forgejo, dormant maintainer accounts</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-stepsecurity-sleepergem-rubygems-dormant-accounts-forgejo-loader/cover.jpg</image:loc>
      <image:title>SleeperGem loader hides in dormant RubyGems, skips CI/CD</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-20-wp2shell-first-exploitation-cve-2026-60137-sqli-companion-patched/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T01:15:00.000Z</news:publication_date>
      <news:title>wp2shell: first signs of exploitation; CVE-2026-60137 lands</news:title>
      <news:keywords>CVE-2026-63030, CVE-2026-60137, wp2shell, WordPress, WordPress Core, in-the-wild exploitation, watchTowr, Searchlight Cyber</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-20-wp2shell-first-exploitation-cve-2026-60137-sqli-companion-patched/cover.jpg</image:loc>
      <image:title>wp2shell: first signs of exploitation; CVE-2026-60137 lands</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-19-nginx-cve-2026-42533-map-regex-heap-overflow-worker-patch/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-19T22:05:00.000Z</news:publication_date>
      <news:title>nginx patches heap overflow in worker (CVE-2026-42533)</news:title>
      <news:keywords>nginx, CVE-2026-42533, F5, heap overflow, map directive, NGINX Plus, memory safety</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-19-nginx-cve-2026-42533-map-regex-heap-overflow-worker-patch/cover.jpg</image:loc>
      <image:title>nginx patches heap overflow in worker (CVE-2026-42533)</image:title>
    </image:image>
  </url>
</urlset>