<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/penetration-testing-execution-standard/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T11:13:18.000Z</news:publication_date>
      <news:title>Penetration Testing Execution Standard (PTES): A Complete Guide</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/huggingface-ai-agent-intrusion-technical-anatomy/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:03:53.000Z</news:publication_date>
      <news:title>Inside the HuggingFace AI Agent Intrusion (Part 2)</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2025-4318-aws-amplify-codegen-ui-react-eval-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T21:08:48.783Z</news:publication_date>
      <news:title>CVE-2025-4318: @aws-amplify/codegen-ui-react Eval Injection (RCE)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-11393-agentcore-cli-triple-quote-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T16:29:35.546Z</news:publication_date>
      <news:title>CVE-2026-11393: @aws/agentcore Code Injection via Triple-Quote Escape Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54574-proot-distro-symlink-escape-tar-arbitrary-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T16:50:04.239Z</news:publication_date>
      <news:title>CVE-2026-54574: proot-distro Symlink Escape via Malicious Tar Archive</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54680-kube-logging-operator-fluentd-config-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T17:10:14.173Z</news:publication_date>
      <news:title>CVE-2026-54680: kube-logging/logging-operator Fluentd Configuration Injection RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54722-dssrf-ssrf-userinfo-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T16:28:51.243Z</news:publication_date>
      <news:title>CVE-2026-54722: dssrf SSRF Bypass via Userinfo Stripping</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54727-proot-distro-hardlink-cross-container-isolation-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T16:48:49.110Z</news:publication_date>
      <news:title>CVE-2026-54727: proot-distro Container Isolation Bypass via Crafted Restore Archive</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54735-prebid-server-bidder-adapter-ssrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T16:08:56.283Z</news:publication_date>
      <news:title>CVE-2026-54735: prebid-server Bidder Adapter Server-Side Request Forgery</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-66066-activestorage-libvips-unfuzzed-arbitrary-file-read</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T18:29:11.090Z</news:publication_date>
      <news:title>CVE-2026-66066: Active Storage Arbitrary File Read via libvips Unfuzzed Loaders</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67424-flyto-core-ssrf-redirect-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:08:45.660Z</news:publication_date>
      <news:title>CVE-2026-67424: flyto-core SSRF via Unvalidated HTTP Redirect</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67425-flyto-core-llm-api-key-exfiltration-base-url</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:14:58.158Z</news:publication_date>
      <news:title>CVE-2026-67425: flyto-core LLM API Key Exfiltration via Caller-Controlled base_url</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67426-flyto-core-unauthenticated-ssrf-runner-secret</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:11:27.665Z</news:publication_date>
      <news:title>CVE-2026-67426: flyto-core Unauthenticated SSRF and Runner Secret Exfiltration</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67428-flyto-core-ssrf-unguarded-http-modules</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:09:57.996Z</news:publication_date>
      <news:title>CVE-2026-67428: flyto-core Missing SSRF Guard on HTTP Modules</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67429-flyto-core-arbitrary-file-write-image-download</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T14:49:47.052Z</news:publication_date>
      <news:title>CVE-2026-67429: flyto-core Arbitrary File Write via image.download</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67432-mcp-ruby-sdk-unbounded-body-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T14:51:48.356Z</news:publication_date>
      <news:title>CVE-2026-67432: mcp (Ruby SDK) Unbounded Request Body Memory Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/netfoil-block-response-0000-localhost-traffic</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T17:08:53.037Z</news:publication_date>
      <news:title>netfoil: Incorrect Block Response Sends Traffic to Localhost</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>