<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/huggingface-ai-agent-intrusion-technical-anatomy/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:03:53.000Z</news:publication_date>
      <news:title>Inside the HuggingFace AI Agent Intrusion (Part 2)</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/runtime-application-self-protection-rasp/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T08:56:31.000Z</news:publication_date>
      <news:title>Runtime Application Self-Protection (RASP) Explained</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2025-4318-aws-amplify-codegen-ui-react-eval-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T21:08:48.783Z</news:publication_date>
      <news:title>CVE-2025-4318: @aws-amplify/codegen-ui-react Eval Injection (RCE)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-11393-agentcore-cli-triple-quote-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T16:29:35.546Z</news:publication_date>
      <news:title>CVE-2026-11393: @aws/agentcore Code Injection via Triple-Quote Escape Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-49755-req-decompression-bomb-decode-body</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T15:29:06.721Z</news:publication_date>
      <news:title>CVE-2026-49755: Req Decompression Bomb via Auto-Decoded Response Bodies</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50559-quarkus-vertx-http-auth-bypass-encoded-path</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T15:48:59.079Z</news:publication_date>
      <news:title>CVE-2026-50559: quarkus-vertx-http Authentication Bypass via Encoded Path Characters</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54078-verapdf-validation-model-xxe-rich-text</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T15:30:23.075Z</news:publication_date>
      <news:title>CVE-2026-54078: veraPDF validation-model XXE via Rich Text</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54079-verapdf-validation-model-xxe-xfa-stream</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T15:31:48.078Z</news:publication_date>
      <news:title>CVE-2026-54079: veraPDF validation-model XML External Entity Injection via XFA Stream</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54574-proot-distro-symlink-escape-tar-arbitrary-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T16:50:04.239Z</news:publication_date>
      <news:title>CVE-2026-54574: proot-distro Symlink Escape via Malicious Tar Archive</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54660-swagger-typescript-api-auth-token-exfiltration-cross-origin-ref</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T14:30:18.123Z</news:publication_date>
      <news:title>CVE-2026-54660: swagger-typescript-api Authorization Token Exfiltration via Cross-Origin $ref</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54661-swagger-typescript-api-axios-servers-url-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T14:50:56.912Z</news:publication_date>
      <news:title>CVE-2026-54661: swagger-typescript-api Axios HTTP Client Code Injection via servers[0].url</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54662-swagger-typescript-api-fetch-baseurl-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T14:28:53.121Z</news:publication_date>
      <news:title>CVE-2026-54662: swagger-typescript-api Code Injection via Unescaped servers[0].url in Fetch Client Template</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54664-swagger-typescript-api-enum-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T14:49:45.154Z</news:publication_date>
      <news:title>CVE-2026-54664: swagger-typescript-api Code Injection via Unescaped Enum Values</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54680-kube-logging-operator-fluentd-config-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T17:10:14.173Z</news:publication_date>
      <news:title>CVE-2026-54680: kube-logging/logging-operator Fluentd Configuration Injection RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54722-dssrf-ssrf-userinfo-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T16:28:51.243Z</news:publication_date>
      <news:title>CVE-2026-54722: dssrf SSRF Bypass via Userinfo Stripping</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54727-proot-distro-hardlink-cross-container-isolation-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T16:48:49.110Z</news:publication_date>
      <news:title>CVE-2026-54727: proot-distro Container Isolation Bypass via Crafted Restore Archive</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54735-prebid-server-bidder-adapter-ssrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T16:08:56.283Z</news:publication_date>
      <news:title>CVE-2026-54735: prebid-server Bidder Adapter Server-Side Request Forgery</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-66066-activestorage-libvips-unfuzzed-arbitrary-file-read</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T18:29:11.090Z</news:publication_date>
      <news:title>CVE-2026-66066: Active Storage Arbitrary File Read via libvips Unfuzzed Loaders</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67424-flyto-core-ssrf-redirect-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:08:45.660Z</news:publication_date>
      <news:title>CVE-2026-67424: flyto-core SSRF via Unvalidated HTTP Redirect</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67425-flyto-core-llm-api-key-exfiltration-base-url</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:14:58.158Z</news:publication_date>
      <news:title>CVE-2026-67425: flyto-core LLM API Key Exfiltration via Caller-Controlled base_url</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67426-flyto-core-unauthenticated-ssrf-runner-secret</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:11:27.665Z</news:publication_date>
      <news:title>CVE-2026-67426: flyto-core Unauthenticated SSRF and Runner Secret Exfiltration</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67428-flyto-core-ssrf-unguarded-http-modules</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T15:09:57.996Z</news:publication_date>
      <news:title>CVE-2026-67428: flyto-core Missing SSRF Guard on HTTP Modules</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67429-flyto-core-arbitrary-file-write-image-download</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T14:49:47.052Z</news:publication_date>
      <news:title>CVE-2026-67429: flyto-core Arbitrary File Write via image.download</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67432-mcp-ruby-sdk-unbounded-body-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-30T14:51:48.356Z</news:publication_date>
      <news:title>CVE-2026-67432: mcp (Ruby SDK) Unbounded Request Body Memory Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/netfoil-block-response-0000-localhost-traffic</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-29T17:08:53.037Z</news:publication_date>
      <news:title>netfoil: Incorrect Block Response Sends Traffic to Localhost</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>