<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://securelayer7.net/lab/anephenix-hub-websocket-rpc-resource-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:09:42.905Z</news:publication_date>
      <news:title>@anephenix/hub WebSocket RPC Waiter Resource Exhaustion</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/blaze-server-chunked-trailer-header-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:28:38.450Z</news:publication_date>
      <news:title>blaze-server HTTP/1.1 Chunked Trailer Header Injection</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/budibase-app-scoped-builder-privilege-escalation-roles-assign</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:30:45.779Z</news:publication_date>
      <news:title>Budibase: App-Scoped Builder Privilege Escalation via Public Role Assignment API</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/budibase-dns-rebinding-ssrf-openapi-rest-query</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:18:05.055Z</news:publication_date>
      <news:title>Budibase: DNS Rebinding SSRF Bypass in OpenAPI Import and REST Query Execution</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/budibase-email-change-idor-account-takeover-accountid-not-validated</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:24:03.637Z</news:publication_date>
      <news:title>Budibase Email Change IDOR Allows Full Account Takeover via POST /api/v2/email</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/budibase-mongodb-nosql-operator-injection-filter-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:23:01.235Z</news:publication_date>
      <news:title>Budibase MongoDB Integration NoSQL Operator Injection</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/budibase-mongodb-tls-path-filesystem-read-oracle</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:43:55.695Z</news:publication_date>
      <news:title>Budibase MongoDB Datasource Filesystem Read Oracle via Unvalidated TLS Certificate Paths</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/budibase-mysql-describe-backtick-sql-injection-multiplestatements</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:28:39.821Z</news:publication_date>
      <news:title>Budibase MySQL DESCRIBE Backtick Injection via multipleStatements</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/budibase-mysql-multiplestatements-sql-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:44:56.632Z</news:publication_date>
      <news:title>Budibase MySQL Integration SQL Injection via multipleStatements</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/budibase-oidc-sso-account-takeover-email-verified-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:36:07.547Z</news:publication_date>
      <news:title>Budibase OIDC SSO Account Takeover via Unverified Email Claim</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/budibase-rest-datasource-ssrf-dns-rebinding-undici-dispatcher</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:21:52.854Z</news:publication_date>
      <news:title>Budibase REST Datasource SSRF via DNS Rebinding (undici dispatcher bypasses IP pin)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/budibase-rest-datasource-unauthenticated-credential-theft-cross-origin-query-pat</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:34:53.181Z</news:publication_date>
      <news:title>Budibase REST Datasource Unauthenticated Credential Theft via Cross-Origin Query Path</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/budibase-s3-presigned-url-authorization-regression-basic-user-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:42:38.984Z</news:publication_date>
      <news:title>Budibase S3 Presigned URL Authorization Regression (BASIC User Escalation)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/budibase-server-nosql-injection-mongodb-query-parameter-interpolation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:29:51.404Z</news:publication_date>
      <news:title>@budibase/server NoSQL Injection via MongoDB Query Parameter Interpolation</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/budibase-unauthenticated-tenant-user-info-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:30:56.964Z</news:publication_date>
      <news:title>Budibase Unauthenticated Tenant User Information Disclosure</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-14257-brace-expansion-unbounded-expansion-oom-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:54:46.720Z</news:publication_date>
      <news:title>CVE-2026-14257: brace-expansion Unbounded Expansion Length DoS (OOM Crash)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-16584-aws-api-mcp-server-policy-bypass-init-failure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T23:12:09.454Z</news:publication_date>
      <news:title>CVE-2026-16584: AWS API MCP Server Security Policy Bypass via Startup Initialization Failure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-16756-aws-smithy-http-server-slowloris-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:52:16.432Z</news:publication_date>
      <news:title>CVE-2026-16756: aws-smithy-http-server Slowloris Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-16796-bedrock-agentcore-install-packages-argument-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:50:03.750Z</news:publication_date>
      <news:title>CVE-2026-16796: bedrock-agentcore Argument Injection in install_packages()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-33413-etcd-watch-withfromkey-rbac-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T23:21:57.727Z</news:publication_date>
      <news:title>CVE-2026-33413: etcd Watch API RBAC Authorization Bypass via Open-Ended Range</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-44907-react-server-dom-webpack-dos-server-functions</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:31:55.794Z</news:publication_date>
      <news:title>CVE-2026-44907: react-server-dom-webpack Denial of Service in Server Functions</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50132-budibase-chat-link-handoff-csrf-identity-confusion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:16:44.402Z</news:publication_date>
      <news:title>CVE-2026-50132: Budibase Chat-Link Handoff Identity Confusion CSRF</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55404-yt-dlp-write-link-shortcut-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T20:48:51.059Z</news:publication_date>
      <news:title>CVE-2026-55404: yt-dlp Shortcut File Injection Leading to Remote Code Execution</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55502-cloudreve-onedrive-oauth-scope-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:10:55.211Z</news:publication_date>
      <news:title>CVE-2026-55502: Cloudreve Admin.Read OAuth Token Can Overwrite OneDrive Storage Policy Credentials</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59224-open-webui-terminal-proxy-user-id-spoofing</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:09:51.372Z</news:publication_date>
      <news:title>CVE-2026-59224: open-webui Terminal Proxy Authentication Bypass via session_id Query Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62263-openam-webauthn-objectinputfilter-depth-bypass-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T23:24:32.600Z</news:publication_date>
      <news:title>CVE-2026-62263: OpenAM WebAuthn ObjectInputFilter depth&gt;1 Deserialization RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62379-openam-authxmlutils-unsafe-reflection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T23:17:52.339Z</news:publication_date>
      <news:title>CVE-2026-62379: OpenAM Unauthenticated Remote Code Execution via Unsafe Reflection in AuthXMLUtils</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/etcd-tls-listener-unbounded-handshake-goroutine-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:48:52.955Z</news:publication_date>
      <news:title>etcd tlsListener Unbounded TLS Handshake Goroutine DoS</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/frp-ssh-tunnel-gateway-integer-overflow-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:57:43.444Z</news:publication_date>
      <news:title>frp SSH Tunnel Gateway Unauthenticated Remote Denial of Service via Integer Overflow</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-create-remote-env-var-exfiltration-incomplete-fix</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:10:51.082Z</news:publication_date>
      <news:title>GitPython Environment-Variable Exfiltration via Repo.create_remote() URL</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/http4s-blaze-server-http1-request-smuggling-parser-laxities</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:29:28.398Z</news:publication_date>
      <news:title>http4s-blaze-server HTTP/1.1 Request Smuggling (Multiple Parser Laxities)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/http4s-blaze-server-websocket-unbounded-aggregation-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T23:16:36.022Z</news:publication_date>
      <news:title>http4s-blaze-server Unbounded WebSocket Message Aggregation DoS</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/oh-my-posh-template-injection-path-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T23:09:34.401Z</news:publication_date>
      <news:title>Oh My Posh: Arbitrary Command Execution via Template Injection in Path Segment</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/omnifaces-forged-resource-id-xss-push-replay</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T23:10:54.777Z</news:publication_date>
      <news:title>OmniFaces: Forged Resource IDs, XSS via o:hashParam, and Push-Channel Replay</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/opendj-dsml-anyuri-ssrf-file-read-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:50:38.708Z</news:publication_date>
      <news:title>OpenDJ DSMLv2 Gateway Unauthenticated SSRF and Local File Read</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/opendj-sasl-plain-authzid-proxy-aci-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:49:15.065Z</news:publication_date>
      <news:title>OpenDJ SASL PLAIN authzid Proxy ACI Authorization Bypass</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/openlist-batch-rename-src-name-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T23:23:02.663Z</news:publication_date>
      <news:title>OpenList Authenticated Path Traversal in Batch Rename src_name</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/pheditor-authentication-bypass-forced-password-change</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:05:05.570Z</news:publication_date>
      <news:title>Pheditor: Authentication Bypass in Forced Password-Change Flow</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/pheditor-terminal-allowlist-bypass-argument-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:51:46.049Z</news:publication_date>
      <news:title>Pheditor Terminal Command-Allowlist Bypass via Argument Injection (RCE)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/poweradmin-api-broken-access-control-password-reset-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:04:02.811Z</news:publication_date>
      <news:title>Poweradmin: API Broken Access Control Allows Non-Admin to Reset Any User&apos;s Password</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/poweradmin-idor-broken-access-control-dns-record-edit</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:02:53.716Z</news:publication_date>
      <news:title>Poweradmin: IDOR Broken Access Control in DNS Record Edit</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/poweradmin-oidc-sub-collation-bypass-account-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:01:47.188Z</news:publication_date>
      <news:title>Poweradmin OIDC sub Collation Bypass Account Takeover</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/py-libp2p-yamux-oversized-data-frame-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:55:23.169Z</news:publication_date>
      <news:title>py-libp2p yamux connection DoS via oversized DATA frame</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/shescape-quadratic-dos-flag-protection-redos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:58:13.970Z</news:publication_date>
      <news:title>Shescape: Quadratic-Time Denial of Service in Flag Protection</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/shescape-shell-injection-windows-cmd-parentheses</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T23:04:38.011Z</news:publication_date>
      <news:title>shescape: Shell Injection via Unescaped Parentheses on Windows CMD</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/sm-crypto-predictable-sm2-key-generation-weak-prng-nodejs</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T21:55:56.303Z</news:publication_date>
      <news:title>sm-crypto: Predictable SM2 Key Generation via Weak PRNG in Node.js</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/vantage6-algorithm-store-incorrect-authorization-edit-endpoint</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T22:08:35.239Z</news:publication_date>
      <news:title>vantage6 Algorithm Store: Incorrect Authorization on Algorithm Edit Endpoint</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>