<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-teleshim-east-asia-apt-telegram-c2-middle-east/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T10:00:00.000Z</news:publication_date>
      <news:title>TELESHIM Uses Telegram C2 Against Middle East Governments</news:title>
      <news:keywords>TELESHIM, MIXEDKEY, BINDCLOAK, Zscaler ThreatLabz, East Asia APT, Telegram C2, Middle East</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-teleshim-east-asia-apt-telegram-c2-middle-east/cover.jpg</image:loc>
      <image:title>TELESHIM Uses Telegram C2 Against Middle East Governments</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-27-steam-forum-clickfix-xmrig-cryptominer/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-27T08:00:00.000Z</news:publication_date>
      <news:title>Steam Forums Used to Deliver XMRig via ClickFix</news:title>
      <news:keywords>ClickFix, XMRig, Steam, cryptominer, Monero, social engineering, gaming</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-27-steam-forum-clickfix-xmrig-cryptominer/cover.jpg</image:loc>
      <image:title>Steam Forums Used to Deliver XMRig via ClickFix</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-26-insurance-phishing-realtime-aitm-account-hijacking/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-26T23:00:00.000Z</news:publication_date>
      <news:title>Insurance Phishing Moves to Real-Time Account Hijacking</news:title>
      <news:keywords>phishing, AiTM, adversary-in-the-middle, account takeover, insurance, MFA bypass, session hijacking</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-26-insurance-phishing-realtime-aitm-account-hijacking/cover.jpg</image:loc>
      <image:title>Insurance Phishing Moves to Real-Time Account Hijacking</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-26-github-pypi-dependabot-time-based-supply-chain-defenses/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-26T14:30:00.000Z</news:publication_date>
      <news:title>GitHub, PyPI Add Time-Gated Supply Chain Defenses</news:title>
      <news:keywords>supply-chain, dependabot, pypi, github, package security, dependency management, open source security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-26-github-pypi-dependabot-time-based-supply-chain-defenses/cover.jpg</image:loc>
      <image:title>GitHub, PyPI Add Time-Gated Supply Chain Defenses</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-26-chick-fil-a-credential-stuffing-13000-accounts/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-26T14:00:00.000Z</news:publication_date>
      <news:title>Chick-fil-A: 13,000 Accounts Hit in Credential Stuffing</news:title>
      <news:keywords>credential stuffing, chick-fil-a, data breach, account takeover, mobile security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-26-chick-fil-a-credential-stuffing-13000-accounts/cover.jpg</image:loc>
      <image:title>Chick-fil-A: 13,000 Accounts Hit in Credential Stuffing</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-26-bluenoroff-zoom-phishing-kit-crypto-wallets/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-26T08:00:00.000Z</news:publication_date>
      <news:title>BlueNoroff Active: Zoom Phishing Profiles Crypto Wallets</news:title>
      <news:keywords>BlueNoroff, North Korea, DPRK, phishing, cryptocurrency, wallet theft, ClickFix</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-26-bluenoroff-zoom-phishing-kit-crypto-wallets/cover.jpg</image:loc>
      <image:title>BlueNoroff Active: Zoom Phishing Profiles Crypto Wallets</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-26-slopsquatting-ai-coding-agent-supply-chain/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-26T07:00:00.000Z</news:publication_date>
      <news:title>Slopsquatting Has Three Names. The Attack Is the Same.</news:title>
      <news:keywords>slopsquatting, HalluSquatting, supply-chain, AI coding agents, package hallucination, phantom packages, software supply chain</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-26-slopsquatting-ai-coding-agent-supply-chain/cover.jpg</image:loc>
      <image:title>Slopsquatting Has Three Names. The Attack Is the Same.</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-26-hermes-ai-agent-yolo-post-exploitation-thai-finance/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-26T06:00:00.000Z</news:publication_date>
      <news:title>Open-Source AI Agent Used in Gov Post-Exploitation Attack</news:title>
      <news:keywords>ai-agent, hermes, post-exploitation, thailand, government, threat-intel, automation</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-26-hermes-ai-agent-yolo-post-exploitation-thai-finance/cover.jpg</image:loc>
      <image:title>Open-Source AI Agent Used in Gov Post-Exploitation Attack</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-26-hotel-wifi-dns-hijack-m365-credential-theft/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-26T03:00:00.000Z</news:publication_date>
      <news:title>Hotel Wi-Fi DNS Hijacked to Serve Fake M365 Pages</news:title>
      <news:keywords>dns hijacking, microsoft 365, hotel wifi, credential theft, phishing, network security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-26-hotel-wifi-dns-hijack-m365-credential-theft/cover.jpg</image:loc>
      <image:title>Hotel Wi-Fi DNS Hijacked to Serve Fake M365 Pages</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-25-steam-clickfix-xmrig-cryptominer-gamers/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-25T23:30:00.000Z</news:publication_date>
      <news:title>Steam Forums Weaponized in ClickFix Cryptominer Campaign</news:title>
      <news:keywords>clickfix, xmrig, steam, cryptominer, cryptojacking, social-engineering, gaming</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-25-steam-clickfix-xmrig-cryptominer-gamers/cover.jpg</image:loc>
      <image:title>Steam Forums Weaponized in ClickFix Cryptominer Campaign</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-25-bing-images-cve-2026-32194-32191-svg-system-rce/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-25T21:00:00.000Z</news:publication_date>
      <news:title>Bing Image Workers Ran SYSTEM Commands via Crafted SVGs</news:title>
      <news:keywords>ImageMagick, Bing, SVG, RCE, Microsoft, XBOW, command-injection</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-25-bing-images-cve-2026-32194-32191-svg-system-rce/cover.jpg</image:loc>
      <image:title>Bing Image Workers Ran SYSTEM Commands via Crafted SVGs</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-25-certighost-ad-cs-domain-controller-exploit/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-25T21:00:00.000Z</news:publication_date>
      <news:title>Certighost: Working Exploit Reaches AD Domain Controllers</news:title>
      <news:keywords>Active Directory, Certighost, AD CS, DCSync, domain controller, Kerberos</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-25-certighost-ad-cs-domain-controller-exploit/cover.jpg</image:loc>
      <image:title>Certighost: Working Exploit Reaches AD Domain Controllers</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-25-ctm360-aitm-insurance-phishing-real-time-mfa/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-25T17:00:00.000Z</news:publication_date>
      <news:title>Insurance Sector Phishing Has Evolved to Real-Time AiTM</news:title>
      <news:keywords>phishing, AiTM, MFA bypass, account takeover, insurance, adversary-in-the-middle, session hijacking</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-25-ctm360-aitm-insurance-phishing-real-time-mfa/cover.jpg</image:loc>
      <image:title>Insurance Sector Phishing Has Evolved to Real-Time AiTM</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-25-shinyhunters-breach-data-sextortion-2000-bitcoin/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-25T15:30:00.000Z</news:publication_date>
      <news:title>ShinyHunters Breach Data Now Fueling Sextortion Emails</news:title>
      <news:keywords>shinyhunters, sextortion, bitcoin, data breach, extortion, email scam</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-25-shinyhunters-breach-data-sextortion-2000-bitcoin/cover.jpg</image:loc>
      <image:title>ShinyHunters Breach Data Now Fueling Sextortion Emails</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-25-malvertising-javascript-in-memory-malware/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-25T15:21:09.000Z</news:publication_date>
      <news:title>JS Malvertising Assembles Malware in Browser Memory</news:title>
      <news:keywords>malvertising, in-memory malware, fileless malware, JavaScript, browser security, Solana, TradingView</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-25-malvertising-javascript-in-memory-malware/cover.jpg</image:loc>
      <image:title>JS Malvertising Assembles Malware in Browser Memory</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-25-fastjson-1x-cve-2026-16723-rce-no-patch/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-25T14:00:00.000Z</news:publication_date>
      <news:title>Fastjson 1.x RCE Exploited: No Patch Available</news:title>
      <news:keywords>fastjson, CVE-2026-16723, RCE, Spring Boot, Java, deserialization, unauthenticated</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-25-fastjson-1x-cve-2026-16723-rce-no-patch/cover.jpg</image:loc>
      <image:title>Fastjson 1.x RCE Exploited: No Patch Available</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-07-25-devman-raas-funky-mantis-affiliate-portal/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-25T13:05:00.000Z</news:publication_date>
      <news:title>DevMan RaaS Offers Affiliates Centralized Build Portal</news:title>
      <news:keywords>ransomware, RaaS, DevMan, PRODAFT, Funky Mantis, affiliate, malware-as-a-service</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-07-25-devman-raas-funky-mantis-affiliate-portal/cover.jpg</image:loc>
      <image:title>DevMan RaaS Offers Affiliates Centralized Build Portal</image:title>
    </image:image>
  </url>
</urlset>