<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/exploit-validated-pentesting/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T19:24:52.000Z</news:publication_date>
      <news:title>Exploit-Validated Pentesting: Stop Paying for CVE Lists</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/ai-agent-red-teaming-obfuscated-prompt-injection/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T19:15:05.000Z</news:publication_date>
      <news:title>We Red-Teamed an AI Agent: 54% of Prompt-Injection Probes Got Past Its Defenses</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/atomic-agents-stack-http-mcp-catalog-mitm-rce-cleartext-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T22:18:00.239Z</news:publication_date>
      <news:title>atomic-agents-stack: HTTP MCP Catalog MITM to RCE via Cleartext Command Injection</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-17106-moby-go-archive-symlink-tar-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T21:22:07.463Z</news:publication_date>
      <news:title>CVE-2026-17106: moby/go-archive Symlink-Following Path Traversal in Tar Extraction</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47683-vm2-buffer-concat-alloclimit-bypass-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T18:08:54.360Z</news:publication_date>
      <news:title>CVE-2026-47683: vm2 bufferAllocLimit DoS Bypass via Buffer.concat and Buffer.from</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47686-vm2-error-cause-sandbox-escape-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T18:04:34.818Z</news:publication_date>
      <news:title>CVE-2026-47686: vm2 Missing Error.cause Sanitization Sandbox Escape to RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47698-vm2-sandbox-breakout-indirect-call-proto-mutation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:52:05.204Z</news:publication_date>
      <news:title>CVE-2026-47698: vm2 Sandbox Breakout via Indirect Call Proto Mutation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53659-http4k-gzip-decompression-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T22:16:20.536Z</news:publication_date>
      <news:title>CVE-2026-53659: http4k-core Unbounded Gzip Decompression DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54133-jmespath-php-compiler-runtime-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T20:36:17.844Z</news:publication_date>
      <news:title>CVE-2026-54133: jmespath.php CompilerRuntime Code Injection via Unescaped Function Names</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54284-sqlparse-tokenlist-quadratic-cpu-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T18:01:39.597Z</news:publication_date>
      <news:title>CVE-2026-54284: sqlparse TokenList O(n*depth) CPU Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54347-froxlor-stored-xss-dns-txt-admin-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T21:30:08.023Z</news:publication_date>
      <news:title>CVE-2026-54347: Froxlor Stored XSS in DNS TXT Record Leads to Admin Account Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54348-froxlor-second-order-sql-injection-admins-ipaddress</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T21:28:49.148Z</news:publication_date>
      <news:title>CVE-2026-54348: Froxlor Second-Order SQL Injection via Admins.add ipaddress Parameter</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55090-etherpad-stored-xss-html-export-attribute-pool</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T18:03:06.805Z</news:publication_date>
      <news:title>CVE-2026-55090: Etherpad Stored XSS via Unescaped HTML Export Attribute Values</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55107-kobako-sandbox-escape-public-send-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T20:42:46.316Z</news:publication_date>
      <news:title>CVE-2026-55107: kobako Sandbox Escape via Unguarded public_send Dispatcher</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55178-geolens-cross-dataset-authorization-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T18:09:16.825Z</news:publication_date>
      <news:title>CVE-2026-55178: GeoLens Cross-Dataset Authorization Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55211-surfio-irap-out-of-bounds-read</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T20:37:43.246Z</news:publication_date>
      <news:title>CVE-2026-55211: surfio Out-of-Bounds Read in IRAP Binary Parser</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55224-mineadmin-plugin-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T20:48:48.168Z</news:publication_date>
      <news:title>CVE-2026-55224: MineAdmin Path Traversal in Plugin Install/Uninstall</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55839-kestra-stored-xss-markdown-link-attribute-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T16:56:32.599Z</news:publication_date>
      <news:title>CVE-2026-55839: Kestra Stored XSS via Custom Markdown [[link]] Attribute Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56677-9router-unauthenticated-ssrf-oidc-issuerurl</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T22:11:28.723Z</news:publication_date>
      <news:title>CVE-2026-56677: 9router Unauthenticated SSRF via OIDC Test Endpoint</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59893-sqlparse-redos-dollar-quote-multiline-comment</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:57:53.140Z</news:publication_date>
      <news:title>CVE-2026-59893: sqlparse ReDoS via Dollar-Quoted and Multiline-Comment Regexes</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59902-netty-sctp-memory-exhaustion-oom</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:55:09.824Z</news:publication_date>
      <news:title>CVE-2026-59902: netty-transport-sctp SctpMessageCompletionHandler Memory Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62988-froxlor-api-credential-2fa-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T21:24:36.348Z</news:publication_date>
      <news:title>CVE-2026-62988: Froxlor API Credential and 2FA Secret Disclosure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63337-rabbitmq-amqp-client-unsafe-reflection-jsonrpc</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T16:49:07.442Z</news:publication_date>
      <news:title>CVE-2026-63337: RabbitMQ amqp-client Unsafe Reflection via JSON-RPC javaReturnType</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64849-mlflow-webhook-ssrf-redirect-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T22:10:15.142Z</news:publication_date>
      <news:title>CVE-2026-64849: MLflow Unauthenticated Full-Read SSRF via Webhook HTTP Redirect</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64859-new-api-user-list-access-token-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T16:55:04.359Z</news:publication_date>
      <news:title>CVE-2026-64859: new-api User List API Leaks Root Access Token</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64868-new-api-webhook-dos-unbounded-body</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T16:52:06.431Z</news:publication_date>
      <news:title>CVE-2026-64868: new-api Unauthenticated Webhook DoS via Unbounded Body Read</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68518-glances-action-template-sanitizer-bypass-cross-field-command-inje</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T16:49:22.549Z</news:publication_date>
      <news:title>CVE-2026-68518: glances Action-Template Sanitizer Bypass via Cross-Field Shell-Operator Reconstruction</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68519-glances-disable-config-exec-bypass-alert-action-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:30:37.651Z</news:publication_date>
      <news:title>CVE-2026-68519: Glances --disable-config-exec Bypass via On-Alert Action OS Command Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69148-mlflow-create-model-version-missing-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T22:08:47.988Z</news:publication_date>
      <news:title>CVE-2026-69148: MLflow Missing Authorization on CreateModelVersion run_id</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69219-rabbitmq-java-client-longstring-oom-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T16:50:29.820Z</news:publication_date>
      <news:title>CVE-2026-69219: RabbitMQ Java Client Unchecked LongString Allocation DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69220-rabbitmq-java-client-valuereader-uncontrolled-recursion-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T16:55:23.024Z</news:publication_date>
      <news:title>CVE-2026-69220: RabbitMQ Java Client Uncontrolled Recursion DoS via Nested AMQP Tables</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70666-lemur-acme-ssrf-server-controlled-urls</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T21:16:21.692Z</news:publication_date>
      <news:title>CVE-2026-70666: Lemur ACME Client Server-Side Request Forgery via Server-Controlled URLs</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71303-lemur-acme-authority-update-ssrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T21:14:51.232Z</news:publication_date>
      <news:title>CVE-2026-71303: Lemur ACME Authority Update SSRF (Incomplete Fix)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71307-lemur-destination-credentials-missing-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T21:11:40.379Z</news:publication_date>
      <news:title>CVE-2026-71307: Lemur Authenticated Plaintext Destination Credential Exposure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71308-lemur-replaces-authorization-bypass-certificate-hijack</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T21:10:22.677Z</news:publication_date>
      <news:title>CVE-2026-71308: Lemur Unauthorized Certificate Hijack via Unchecked replaces Field</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71417-lemur-authorization-bypass-arbitrary-certificate-revocation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T21:08:53.742Z</news:publication_date>
      <news:title>CVE-2026-71417: Lemur Authorization Bypass via Duplicate Certificate Upload Enables Arbitrary CA Revocation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71479-new-api-integer-overflow-quota-billing-self-credit</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T16:50:43.760Z</news:publication_date>
      <news:title>CVE-2026-71479: new-api Integer Overflow in Quota Billing Yields Negative Charges</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71491-sqlparse-quadratic-dos-group-comments</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:29:06.190Z</news:publication_date>
      <news:title>CVE-2026-71491: sqlparse Quadratic DoS in group_comments</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/librenms-oxidized-ssrf-stored-xss-showconfig</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T21:23:21.211Z</news:publication_date>
      <news:title>LibreNMS SSRF-Driven Stored XSS via Oxidized API Response Fields</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/meshcentral-stored-xss-agent-osdesc-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T20:43:58.849Z</news:publication_date>
      <news:title>MeshCentral Stored XSS via Unsanitized Agent Fields</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/monai-algo-from-pickle-pickle-deserialization-rce-incomplete-fix</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T20:31:08.298Z</news:publication_date>
      <news:title>MONAI algo_from_pickle() Unsafe Pickle Deserialization RCE (Incomplete Fix)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/monai-nnunetv2runner-os-command-injection-dataset-name</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T20:34:51.710Z</news:publication_date>
      <news:title>MONAI nnUNetV2Runner OS Command Injection via dataset_name_or_id</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/monai-numpyreader-unsafe-deserialization-allow-pickle-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18T20:28:55.373Z</news:publication_date>
      <news:title>MONAI NumpyReader Unsafe Deserialization via allow_pickle=True</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/uniget-cli-inverted-signature-guard-metadata-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:56:25.494Z</news:publication_date>
      <news:title>uniget CLI: Inverted Signature-Guard Condition Allows Unsigned Metadata RCE</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/vm2-arraybuffer-bufferalloclimit-bypass-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:49:12.890Z</news:publication_date>
      <news:title>vm2 Memory Exhaustion DoS via ArrayBuffer bufferAllocLimit Bypass</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/vm2-nodejs-sandbox-os-dns-host-process-escape</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:50:39.644Z</news:publication_date>
      <news:title>vm2: NodeVM builtin wildcard exposes os and dns host-process read/write primitives</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>