<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/openai-hugging-face-exploitgym-incident-analysis/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T15:35:52.000Z</news:publication_date>
      <news:title>How OpenAI&amp;#8217;s AI Agent Broke Into Hugging Face</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/ai-assisted-penetration-testing/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T07:04:32.000Z</news:publication_date>
      <news:title>AI-Assisted Penetration Testing: Guide &amp;#038; Tools</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-43910-appium-java-client-directconnect-ssrf-network-pivot</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:28:48.099Z</news:publication_date>
      <news:title>CVE-2026-43910: appium/java-client SSRF via Unvalidated directConnect Redirect</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-43983-pocket-id-oidc-refresh-token-authorization-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:30:12.261Z</news:publication_date>
      <news:title>CVE-2026-43983: Pocket ID OIDC Refresh Token Authorization Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-45293-wpcs-eval-injection-enqueued-resource-parameters</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:56:07.367Z</news:publication_date>
      <news:title>CVE-2026-45293: WordPress Coding Standards (WPCS) Eval Injection via EnqueuedResourceParameters Sniff</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-46428-lettre-boring-tls-hostname-verification-disabled</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:51:31.443Z</news:publication_date>
      <news:title>CVE-2026-46428: lettre Inverted Boolean Disables TLS Hostname Verification (boring-tls)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47427-github-mcp-server-nil-pointer-dereference-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:50:08.053Z</news:publication_date>
      <news:title>CVE-2026-47427: github-mcp-server Nil Pointer Dereference DoS in completion/complete Handler</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50570-fission-capability-denylist-bypass-sys-time</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T20:29:29.632Z</news:publication_date>
      <news:title>CVE-2026-50570: Fission Incomplete Capability Denylist Allows CAP_SYS_TIME Privilege Escalation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54545-wakaru-cli-path-traversal-arbitrary-file-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:48:54.542Z</news:publication_date>
      <news:title>CVE-2026-54545: @wakaru/cli Arbitrary File Write via Path Traversal in --unpack</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54588-poweradmin-host-header-injection-oidc-redirect-uri</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T16:48:45.893Z</news:publication_date>
      <news:title>CVE-2026-54588: Poweradmin Host Header Injection in OIDC / SAML / Logout Redirect</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54593-pterodactyl-panel-jwt-scope-bypass-file-upload</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T15:48:46.096Z</news:publication_date>
      <news:title>CVE-2026-54593: Pterodactyl Panel Improper JWT Scope Allows Unauthorized File Upload</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54603-oauth2-protocol-relative-redirect-bearer-token-leak</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T16:51:05.868Z</news:publication_date>
      <news:title>CVE-2026-54603: oauth2 Protocol-Relative Redirect Bearer Token Leak</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54605-ruby-oauth-cross-origin-token-redirect-ssrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T16:28:59.760Z</news:publication_date>
      <news:title>CVE-2026-54605: oauth gem Cross-Origin Token Redirect SSRF and Signed-Request Disclosure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54609-qtineon-neonrelay-reconnect-amplification-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T16:49:53.869Z</news:publication_date>
      <news:title>CVE-2026-54609: QTINeon NeonRelay Unauthenticated Amplification via Unbounded RECONNECT_REQUEST Forwarding</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54632-sipsorcery-rtp-ice-udp-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T17:08:57.683Z</news:publication_date>
      <news:title>CVE-2026-54632: SIPSorcery Remote DoS via Malformed UDP Packet on RTP/ICE Socket</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54635-pytonapi-webhook-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T17:28:44.203Z</news:publication_date>
      <news:title>CVE-2026-54635: pytonapi Webhook Custom Path Authentication Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55771-cedarjava-entityidentifier-equals-inverted-logic</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T14:54:38.130Z</news:publication_date>
      <news:title>CVE-2026-55771: CedarJava EntityIdentifier Incorrect Equality Comparison</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61609-pterodactyl-panel-global-auth-ratelimit-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-28T15:08:50.730Z</news:publication_date>
      <news:title>CVE-2026-61609: Pterodactyl Panel Global Authentication Rate-Limit DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>