<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/runtime-application-self-protection-rasp/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T08:56:31.000Z</news:publication_date>
      <news:title>Runtime Application Self-Protection (RASP) Explained</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/openai-hugging-face-exploitgym-incident-analysis/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T15:35:52.000Z</news:publication_date>
      <news:title>How OpenAI&amp;#8217;s AI Agent Broke Into Hugging Face</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/ai-assisted-penetration-testing/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T07:04:32.000Z</news:publication_date>
      <news:title>AI-Assisted Penetration Testing: Guide &amp;#038; Tools</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-32203-encryptedxml-nested-xml-stack-overflow-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T21:08:55.611Z</news:publication_date>
      <news:title>CVE-2026-32203: System.Security.Cryptography.Xml EncryptedXml Stack Overflow via Deeply Nested XML</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-43910-appium-java-client-directconnect-ssrf-network-pivot</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:28:48.099Z</news:publication_date>
      <news:title>CVE-2026-43910: appium/java-client SSRF via Unvalidated directConnect Redirect</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-43983-pocket-id-oidc-refresh-token-authorization-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:30:12.261Z</news:publication_date>
      <news:title>CVE-2026-43983: Pocket ID OIDC Refresh Token Authorization Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-45293-wpcs-eval-injection-enqueued-resource-parameters</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:56:07.367Z</news:publication_date>
      <news:title>CVE-2026-45293: WordPress Coding Standards (WPCS) Eval Injection via EnqueuedResourceParameters Sniff</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-46428-lettre-boring-tls-hostname-verification-disabled</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:51:31.443Z</news:publication_date>
      <news:title>CVE-2026-46428: lettre Inverted Boolean Disables TLS Hostname Verification (boring-tls)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47427-github-mcp-server-nil-pointer-dereference-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:50:08.053Z</news:publication_date>
      <news:title>CVE-2026-47427: github-mcp-server Nil Pointer Dereference DoS in completion/complete Handler</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50570-fission-capability-denylist-bypass-sys-time</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T20:29:29.632Z</news:publication_date>
      <news:title>CVE-2026-50570: Fission Incomplete Capability Denylist Allows CAP_SYS_TIME Privilege Escalation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54545-wakaru-cli-path-traversal-arbitrary-file-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:48:54.542Z</news:publication_date>
      <news:title>CVE-2026-54545: @wakaru/cli Arbitrary File Write via Path Traversal in --unpack</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54588-poweradmin-host-header-injection-oidc-redirect-uri</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T16:48:45.893Z</news:publication_date>
      <news:title>CVE-2026-54588: Poweradmin Host Header Injection in OIDC / SAML / Logout Redirect</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54593-pterodactyl-panel-jwt-scope-bypass-file-upload</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T15:48:46.096Z</news:publication_date>
      <news:title>CVE-2026-54593: Pterodactyl Panel Improper JWT Scope Allows Unauthorized File Upload</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54603-oauth2-protocol-relative-redirect-bearer-token-leak</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T16:51:05.868Z</news:publication_date>
      <news:title>CVE-2026-54603: oauth2 Protocol-Relative Redirect Bearer Token Leak</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54605-ruby-oauth-cross-origin-token-redirect-ssrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T16:28:59.760Z</news:publication_date>
      <news:title>CVE-2026-54605: oauth gem Cross-Origin Token Redirect SSRF and Signed-Request Disclosure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54609-qtineon-neonrelay-reconnect-amplification-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T16:49:53.869Z</news:publication_date>
      <news:title>CVE-2026-54609: QTINeon NeonRelay Unauthenticated Amplification via Unbounded RECONNECT_REQUEST Forwarding</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54632-sipsorcery-rtp-ice-udp-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T17:08:57.683Z</news:publication_date>
      <news:title>CVE-2026-54632: SIPSorcery Remote DoS via Malformed UDP Packet on RTP/ICE Socket</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54635-pytonapi-webhook-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T17:28:44.203Z</news:publication_date>
      <news:title>CVE-2026-54635: pytonapi Webhook Custom Path Authentication Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54638-gotd-td-unencrypted-message-dos-memory-allocation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T22:22:42.969Z</news:publication_date>
      <news:title>CVE-2026-54638: gotd/td Pre-Auth Denial of Service via Unbounded Memory Allocation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54650-openhole-server-path-traversal-percent-encoded</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T22:29:09.347Z</news:publication_date>
      <news:title>CVE-2026-54650: openhole-server Path Traversal via Percent-Encoded URL Segments</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54653-datamodel-code-generator-default-factory-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T22:04:38.664Z</news:publication_date>
      <news:title>CVE-2026-54653: datamodel-code-generator Code Injection via default_factory Schema Field</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54654-datamodel-code-generator-extra-template-data-comment-code-injecti</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T22:30:27.178Z</news:publication_date>
      <news:title>CVE-2026-54654: datamodel-code-generator Code Injection via Carriage Return in --extra-template-data comment</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54655-datamodel-code-generator-x-python-type-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T22:17:36.306Z</news:publication_date>
      <news:title>CVE-2026-54655: datamodel-code-generator Code Injection via x-python-type</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54658-hypequery-clickhouse-sql-injection-backslash-escape-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T22:21:34.046Z</news:publication_date>
      <news:title>CVE-2026-54658: @hypequery/clickhouse SQL Injection via Backslash Escape Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54690-datamodel-code-generator-ssrf-json-schema-ref</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T21:50:42.222Z</news:publication_date>
      <news:title>CVE-2026-54690: datamodel-code-generator SSRF via JSON Schema $ref HTTP URL</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54691-datamodel-code-generator-ssrf-url</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T22:36:56.996Z</news:publication_date>
      <news:title>CVE-2026-54691: datamodel-code-generator SSRF via --url</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54719-goshs-bulk-download-acl-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T22:01:34.532Z</news:publication_date>
      <news:title>CVE-2026-54719: goshs .goshs ACL Bypass via ?bulk Zip-Download Route</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55389-datamodel-code-generator-file-ref-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T21:55:33.059Z</news:publication_date>
      <news:title>CVE-2026-55389: datamodel-code-generator Arbitrary File Read via JSON-Schema $ref</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55390-datamodel-code-generator-xsd-schemalocation-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T21:28:37.918Z</news:publication_date>
      <news:title>CVE-2026-55390: datamodel-code-generator XSD schemaLocation Path Traversal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55391-datamodel-code-generator-ssrf-dns-rebinding</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T22:10:20.897Z</news:publication_date>
      <news:title>CVE-2026-55391: datamodel-code-generator SSRF Protection Bypass via DNS Rebinding</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55415-datamodel-code-generator-import-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T21:52:08.418Z</news:publication_date>
      <news:title>CVE-2026-55415: datamodel-code-generator Code Injection via x-python-import and customTypePath</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55771-cedarjava-entityidentifier-equals-inverted-logic</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:54:38.130Z</news:publication_date>
      <news:title>CVE-2026-55771: CedarJava EntityIdentifier Incorrect Equality Comparison</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61609-pterodactyl-panel-global-auth-ratelimit-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T15:08:50.730Z</news:publication_date>
      <news:title>CVE-2026-61609: Pterodactyl Panel Global Authentication Rate-Limit DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62325-goshs-sftp-empty-password-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T22:02:39.974Z</news:publication_date>
      <news:title>CVE-2026-62325: goshs SFTP Authentication Bypass via Empty Password</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64863-goshs-webdav-move-no-delete-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T22:23:57.335Z</news:publication_date>
      <news:title>CVE-2026-64863: goshs WebDAV MOVE Bypasses --no-delete</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>