<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/owasp-ai-testing-guide/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-13T10:59:03.000Z</news:publication_date>
      <news:title>OWASP AI Testing Guide (AITG): Complete Guide</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/atomic-agents-stack-dashboard-path-traversal-arbitrary-file-read</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-13T14:28:51.699Z</news:publication_date>
      <news:title>atomic-agents-stack: Dashboard HTTP Server Path Traversal Allows Arbitrary File Read</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-12243-nltk-percent-encoded-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-13T20:49:05.050Z</news:publication_date>
      <news:title>CVE-2026-12243: nltk Arbitrary File Read via Percent-Encoded Path Traversal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-35219-budibase-server-ssrf-automation-steps-blacklist-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T19:36:21.810Z</news:publication_date>
      <news:title>CVE-2026-35219: Budibase Server SSRF via Automation Steps Bypassing IP Blacklist</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-35511-authorizer-oauth-account-takeover-unverified-email-linking</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T15:48:49.798Z</news:publication_date>
      <news:title>CVE-2026-35511: Authorizer Zero-Click Account Takeover via OAuth Identity Linking</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53653-grav-image-resize-dos-unbounded-dimensions</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T19:31:34.572Z</news:publication_date>
      <news:title>CVE-2026-53653: Grav Unauthenticated DoS via Unbounded Image Resize Dimensions</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53657-lima-qemu-guest-agent-socket-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T19:30:13.133Z</news:publication_date>
      <news:title>CVE-2026-53657: Lima QEMU Guest Agent Socket World-Writable Privilege Escalation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53660-openam-sso-cookie-httponly-samesite-missing</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T19:28:53.225Z</news:publication_date>
      <news:title>CVE-2026-53660: OpenAM Insecure SSO Cookie Initialization (Missing HttpOnly and SameSite)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54526-argo-workflows-artifactgc-podspecpatch-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-13T14:30:21.885Z</news:publication_date>
      <news:title>CVE-2026-54526: Argo Workflows ArtifactGC.PodSpecPatch Allow-List Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55072-pimcore-classdefinition-uid-regex-sql-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-13T13:49:11.700Z</news:publication_date>
      <news:title>CVE-2026-55072: Pimcore ClassDefinition UID Regex Missing End Anchor Allows SQL Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55074-ansible-jailexec-symlink-jail-escape-put-file</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-12T23:28:58.207Z</news:publication_date>
      <news:title>CVE-2026-55074: ansible-jailexec Jail Escape via Symlink Following in put_file</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55153-mchange-commons-java-unsafe-reflection-jndi-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T19:35:04.102Z</news:publication_date>
      <news:title>CVE-2026-55153: mchange-commons-java Unsafe Reflection via JavaBeanObjectFactory</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55157-token-optimizer-mcp-smart-user-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T21:48:51.497Z</news:publication_date>
      <news:title>CVE-2026-55157: @ooples/token-optimizer-mcp OS Command Injection via smart_user username</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73654-triggerdev-prototype-pollution-run-metadata</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-13T21:08:54.459Z</news:publication_date>
      <news:title>CVE-2026-73654: @trigger.dev/core Prototype Pollution via Run Metadata Operations</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>