<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/penetration-testing-report/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T16:55:57.000Z</news:publication_date>
      <news:title>Penetration Testing Report: Key Sections And How to Use</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/penetration-testing-execution-standard/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T11:13:18.000Z</news:publication_date>
      <news:title>Penetration Testing Execution Standard (PTES): A Complete Guide</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/huggingface-ai-agent-intrusion-technical-anatomy/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:03:53.000Z</news:publication_date>
      <news:title>Inside the HuggingFace AI Agent Intrusion (Part 2)</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2025-4318-aws-amplify-codegen-ui-react-eval-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T21:08:48.783Z</news:publication_date>
      <news:title>CVE-2025-4318: @aws-amplify/codegen-ui-react Eval Injection (RCE)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-12061-nltk-reviews-corpus-reader-redos-features-regex</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T17:16:55.415Z</news:publication_date>
      <news:title>CVE-2026-12061: NLTK ReviewsCorpusReader Quadratic ReDoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-12072-nltk-nkjpcorpusreader-path-traversal-arbitrary-file-read</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T17:18:13.909Z</news:publication_date>
      <news:title>CVE-2026-12072: NLTK NKJPCorpusReader Path Traversal Arbitrary File Read</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-12075-nltk-dns-rebinding-ssrf-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T17:15:45.623Z</news:publication_date>
      <news:title>CVE-2026-12075: nltk DNS-Rebinding SSRF Filter Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-41695-spring-data-commons-property-path-cache-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T16:48:44.938Z</news:publication_date>
      <news:title>CVE-2026-41695: Spring Data Commons Unbounded Property-Path Cache DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53500-thumbor-allowed-sources-ssrf-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T18:48:45.898Z</news:publication_date>
      <news:title>CVE-2026-53500: thumbor ALLOWED_SOURCES Regex Wildcard SSRF Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53501-thumbor-hmac-signature-bypass-replace</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:30:06.179Z</news:publication_date>
      <news:title>CVE-2026-53501: thumbor HMAC Signature Validation Bypass via Repeated URL Segments</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53502-thumbor-file-loader-path-traversal-unquote-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:08:37.984Z</news:publication_date>
      <news:title>CVE-2026-53502: thumbor Path Traversal via Post-Validation URL Decode in file_loader</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53503-thumbor-convolution-divide-by-zero-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:12:10.260Z</news:publication_date>
      <news:title>CVE-2026-53503: thumbor convolution filter remote divide-by-zero DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53504-thumbor-redos-convolution-filter</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:11:02.892Z</news:publication_date>
      <news:title>CVE-2026-53504: thumbor ReDoS in convolution Filter</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53505-thumbor-proportion-filter-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:09:48.256Z</news:publication_date>
      <news:title>CVE-2026-53505: thumbor proportion filter Remote Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54722-dssrf-ssrf-userinfo-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T16:28:51.243Z</news:publication_date>
      <news:title>CVE-2026-54722: dssrf SSRF Bypass via Userinfo Stripping</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54725-vault-secrets-webhook-annotation-ssrf-sa-token-theft</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T17:48:54.314Z</news:publication_date>
      <news:title>CVE-2026-54725: vault-secrets-webhook Annotation SSRF and ServiceAccount Token Theft</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54729-dssrf-ssrf-dns-nxdomain-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T17:10:06.172Z</news:publication_date>
      <news:title>CVE-2026-54729: dssrf SSRF Bypass via DNS NXDOMAIN on 1.1.1.1</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54737-phun-ky-defaults-deep-prototype-pollution</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T18:08:40.162Z</news:publication_date>
      <news:title>CVE-2026-54737: @phun-ky/defaults-deep Prototype Pollution via Unsafe Recursive Merge</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55100-hashi-vault-js-path-traversal-query-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T17:08:45.015Z</news:publication_date>
      <news:title>CVE-2026-55100: hashi-vault-js Path Traversal and Query Parameter Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56819-netty-http2-decompression-bytebuf-refcount-leak-oom-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T17:12:02.386Z</news:publication_date>
      <news:title>CVE-2026-56819: netty-codec-http2 HTTP/2 Decompression ByteBuf Reference-Count Leak (OOM DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58263-jodit-mathml-mutation-xss-clean-html-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:28:59.566Z</news:publication_date>
      <news:title>CVE-2026-58263: Jodit Editor Mutation XSS via MathML/style Rawtext Carrier</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-66066-activestorage-libvips-unfuzzed-arbitrary-file-read</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T18:29:11.090Z</news:publication_date>
      <news:title>CVE-2026-66066: Active Storage Arbitrary File Read via libvips Unfuzzed Loaders</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67424-flyto-core-ssrf-redirect-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:08:45.660Z</news:publication_date>
      <news:title>CVE-2026-67424: flyto-core SSRF via Unvalidated HTTP Redirect</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67425-flyto-core-llm-api-key-exfiltration-base-url</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:14:58.158Z</news:publication_date>
      <news:title>CVE-2026-67425: flyto-core LLM API Key Exfiltration via Caller-Controlled base_url</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67426-flyto-core-unauthenticated-ssrf-runner-secret</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:11:27.665Z</news:publication_date>
      <news:title>CVE-2026-67426: flyto-core Unauthenticated SSRF and Runner Secret Exfiltration</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67428-flyto-core-ssrf-unguarded-http-modules</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:09:57.996Z</news:publication_date>
      <news:title>CVE-2026-67428: flyto-core Missing SSRF Guard on HTTP Modules</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67429-flyto-core-arbitrary-file-write-image-download</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T14:49:47.052Z</news:publication_date>
      <news:title>CVE-2026-67429: flyto-core Arbitrary File Write via image.download</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67432-mcp-ruby-sdk-unbounded-body-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T14:51:48.356Z</news:publication_date>
      <news:title>CVE-2026-67432: mcp (Ruby SDK) Unbounded Request Body Memory Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/dynatrace-mcp-server-unauthenticated-http-mcp-tool-invocation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T16:08:41.298Z</news:publication_date>
      <news:title>dynatrace-mcp-server Unauthenticated HTTP MCP Tool Invocation</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>