<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/owasp-top-10-proactive-controls/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T11:09:24.000Z</news:publication_date>
      <news:title>A Guide to OWASP Top 10 Proactive Controls</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/apache-dubbo-remote-003-path-traversal/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T14:38:03.000Z</news:publication_date>
      <news:title>REMOTE-003 Path Traversal in Configuration Subsystem of Apache Dubbo 3.3.x</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/ai-security/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T11:13:15.000Z</news:publication_date>
      <news:title>AI Security: A Complete Guide to Securing Enterprise AI Systems</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/craftcms-arbitrary-password-reset-elements-save-authorization-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T21:08:51.438Z</news:publication_date>
      <news:title>Craft CMS Improper Authorization: Arbitrary Password Reset via Element Save</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53950-tryghost-activitypub-stored-xss</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T22:09:37.437Z</news:publication_date>
      <news:title>CVE-2026-53950: @tryghost/activitypub Stored XSS via Federated Post Content</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54572-rclone-links-symlink-escape-arbitrary-file-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T20:29:14.281Z</news:publication_date>
      <news:title>CVE-2026-54572: rclone Symlink Target Escape via --links (Arbitrary File Write)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54763-traefik-underscore-header-identity-spoofing</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T17:09:04.206Z</news:publication_date>
      <news:title>CVE-2026-54763: Traefik BasicAuth/DigestAuth/ForwardAuth Underscore Header Identity Spoofing</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59733-rclone-restic-private-repos-path-traversal-authz-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T20:48:57.512Z</news:publication_date>
      <news:title>CVE-2026-59733: rclone serve restic --private-repos Authorization Bypass via Path Traversal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59870-js-yaml-omap-quadratic-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T21:05:01.900Z</news:publication_date>
      <news:title>CVE-2026-59870: js-yaml Quadratic CPU Denial of Service via !!omap</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64665-statamic-oauth-account-takeover-unverified-email</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T19:28:54.862Z</news:publication_date>
      <news:title>CVE-2026-64665: Statamic CMS OAuth Account Takeover via Unverified Email Matching</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65600-traefik-replacepathregex-auth-bypass-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T17:10:21.964Z</news:publication_date>
      <news:title>CVE-2026-65600: Traefik ReplacePathRegex Authentication Bypass via Path Traversal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67309-traefik-ingressnginx-rewritetarget-path-traversal-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T16:49:01.930Z</news:publication_date>
      <news:title>CVE-2026-67309: Traefik Kubernetes Ingress NGINX RewriteTarget Path Traversal Authentication Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70601-electron-contextbridge-bind-hijack-context-isolation-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T15:49:56.860Z</news:publication_date>
      <news:title>CVE-2026-70601: Electron Context Isolation Bypass via Function.prototype.bind Hijack</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70608-electron-sandboxed-iframe-allow-popups-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T17:48:54.554Z</news:publication_date>
      <news:title>CVE-2026-70608: Electron Sandboxed iframe allow-popups Restriction Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71309-rclone-serve-restic-path-traversal-root-escape</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T20:30:34.412Z</news:publication_date>
      <news:title>CVE-2026-71309: rclone serve restic Path Traversal Backend Root Escape</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71312-rclone-sftp-powershell-smartquote-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T20:50:14.348Z</news:publication_date>
      <news:title>CVE-2026-71312: rclone SFTP PowerShell Smart-Quote Filename OS Command Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71314-nuxt-island-vfor-oom-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T21:10:14.928Z</news:publication_date>
      <news:title>CVE-2026-71314: Nuxt Unauthenticated DoS via Unbounded v-for Expansion in Island Rendering</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71315-nuxt-approute-rules-mixedcase-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T21:08:47.270Z</news:publication_date>
      <news:title>CVE-2026-71315: Nuxt appMiddleware Auth Bypass via Mixed-Case Route Rule Keys</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71316-nuxt-payload-cache-cross-user-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T21:28:54.256Z</news:publication_date>
      <news:title>CVE-2026-71316: Nuxt SSR Payload Cache Cross-User Information Disclosure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71321-nuxt-island-cpu-exhaustion-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T21:48:52.115Z</news:publication_date>
      <news:title>CVE-2026-71321: Nuxt Island Endpoint Unauthenticated CPU Exhaustion (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71324-traefik-h2-connect-pool-poisoning-response-smuggling</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T16:09:05.929Z</news:publication_date>
      <news:title>CVE-2026-71324: Traefik HTTP/2 CONNECT Pool Poisoning Cross-User Response Smuggling</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71327-traefik-gateway-api-route-identity-collision</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T16:50:29.405Z</news:publication_date>
      <news:title>CVE-2026-71327: Traefik Gateway API Route Identity Collision Allows Cross-Namespace Backend Hijacking</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/league-commonmark-footnote-duplicate-definition-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T20:57:22.152Z</news:publication_date>
      <news:title>league/commonmark Footnote Extension Quadratic Complexity DoS</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/league-commonmark-heading-slug-dos-quadratic-complexity</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T20:56:06.741Z</news:publication_date>
      <news:title>league/commonmark Denial of Service via Colliding Heading Slugs</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>