<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/ai-agent-red-teaming-obfuscated-prompt-injection/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T19:15:05.000Z</news:publication_date>
      <news:title>We Red-Teamed an AI Agent: 54% of Prompt-Injection Probes Got Past Its Defenses</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47683-vm2-buffer-concat-alloclimit-bypass-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T18:08:54.360Z</news:publication_date>
      <news:title>CVE-2026-47683: vm2 bufferAllocLimit DoS Bypass via Buffer.concat and Buffer.from</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47686-vm2-error-cause-sandbox-escape-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T18:04:34.818Z</news:publication_date>
      <news:title>CVE-2026-47686: vm2 Missing Error.cause Sanitization Sandbox Escape to RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47698-vm2-sandbox-breakout-indirect-call-proto-mutation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:52:05.204Z</news:publication_date>
      <news:title>CVE-2026-47698: vm2 Sandbox Breakout via Indirect Call Proto Mutation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53728-medplum-external-auth-open-redirect-code-leak</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T13:49:12.059Z</news:publication_date>
      <news:title>CVE-2026-53728: @medplum/core Open Redirect via Prefix-Matched Redirect URI in External Auth Callback</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54284-sqlparse-tokenlist-quadratic-cpu-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T18:01:39.597Z</news:publication_date>
      <news:title>CVE-2026-54284: sqlparse TokenList O(n*depth) CPU Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55090-etherpad-stored-xss-html-export-attribute-pool</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T18:03:06.805Z</news:publication_date>
      <news:title>CVE-2026-55090: Etherpad Stored XSS via Unescaped HTML Export Attribute Values</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55158-conflibot-command-injection-branch-name-pull-request-target</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T13:50:52.266Z</news:publication_date>
      <news:title>CVE-2026-55158: conflibot OS Command Injection via Pull Request Branch Name</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59893-sqlparse-redos-dollar-quote-multiline-comment</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:57:53.140Z</news:publication_date>
      <news:title>CVE-2026-59893: sqlparse ReDoS via Dollar-Quoted and Multiline-Comment Regexes</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59902-netty-sctp-memory-exhaustion-oom</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:55:09.824Z</news:publication_date>
      <news:title>CVE-2026-59902: netty-transport-sctp SctpMessageCompletionHandler Memory Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64859-new-api-user-list-access-token-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T16:55:04.359Z</news:publication_date>
      <news:title>CVE-2026-64859: new-api User List API Leaks Root Access Token</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64868-new-api-webhook-dos-unbounded-body</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T16:52:06.431Z</news:publication_date>
      <news:title>CVE-2026-64868: new-api Unauthenticated Webhook DoS via Unbounded Body Read</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68518-glances-action-template-sanitizer-bypass-cross-field-command-inje</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T16:49:22.549Z</news:publication_date>
      <news:title>CVE-2026-68518: glances Action-Template Sanitizer Bypass via Cross-Field Shell-Operator Reconstruction</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68519-glances-disable-config-exec-bypass-alert-action-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:30:37.651Z</news:publication_date>
      <news:title>CVE-2026-68519: Glances --disable-config-exec Bypass via On-Alert Action OS Command Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71479-new-api-integer-overflow-quota-billing-self-credit</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T16:50:43.760Z</news:publication_date>
      <news:title>CVE-2026-71479: new-api Integer Overflow in Quota Billing Yields Negative Charges</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71491-sqlparse-quadratic-dos-group-comments</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:29:06.190Z</news:publication_date>
      <news:title>CVE-2026-71491: sqlparse Quadratic DoS in group_comments</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/uniget-cli-inverted-signature-guard-metadata-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:56:25.494Z</news:publication_date>
      <news:title>uniget CLI: Inverted Signature-Guard Condition Allows Unsigned Metadata RCE</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/vm2-arraybuffer-bufferalloclimit-bypass-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:49:12.890Z</news:publication_date>
      <news:title>vm2 Memory Exhaustion DoS via ArrayBuffer bufferAllocLimit Bypass</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/vm2-nodejs-sandbox-os-dns-host-process-escape</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:50:39.644Z</news:publication_date>
      <news:title>vm2: NodeVM builtin wildcard exposes os and dns host-process read/write primitives</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>