<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/black-hat-usa-2026-parties-events-guide/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T18:33:09.000Z</news:publication_date>
      <news:title>Black Hat USA 2026 Parties &amp;#038; Events: The Complete Guide (with DEF CON 34)</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2025-67725-tornado-httpheaders-quadratic-dos-repeated-headers</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T19:08:39.101Z</news:publication_date>
      <news:title>CVE-2025-67725: Tornado HTTPHeaders Quadratic DoS via Repeated Header Coalescing</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2025-67726-tornado-multipart-parseparam-quadratic-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T19:08:00.383Z</news:publication_date>
      <news:title>CVE-2025-67726: Tornado Quadratic DoS via Crafted Multipart Parameters</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53515-better-auth-sso-bola-register-provider</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:08:02.302Z</news:publication_date>
      <news:title>CVE-2026-53515: @better-auth/sso Broken Object-Level Authorization on SSO Provider Registration</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54560-cloudreve-oauth-scope-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:29:48.976Z</news:publication_date>
      <news:title>CVE-2026-54560: Cloudreve OAuth Access Token Scope Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55380-pillow-gdimagefile-decompression-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:51:06.544Z</news:publication_date>
      <news:title>CVE-2026-55380: Pillow GdImageFile Decompression Bomb (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55514-vllm-mrope-prompt-embeds-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T19:28:51.145Z</news:publication_date>
      <news:title>CVE-2026-55514: vLLM Denial of Service via Prompt Embeds on M-RoPE Models</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55667-filebrowser-scopedfs-removeall-symlink-deletion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:29:15.182Z</news:publication_date>
      <news:title>CVE-2026-55667: File Browser Out-of-Scope File Deletion via Symlink-Following RemoveAll</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59731-astro-middleware-authorization-bypass-decode-iteration</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:08:00.647Z</news:publication_date>
      <news:title>CVE-2026-59731: Astro Middleware Authorization Bypass via URL Decode Iteration Limit</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59869-js-yaml-merge-key-quadratic-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:28:34.464Z</news:publication_date>
      <news:title>CVE-2026-59869: js-yaml Merge-Key Chain Quadratic CPU DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59922-mistune-quadratic-dos-formatting-plugins</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:49:33.963Z</news:publication_date>
      <news:title>CVE-2026-59922: mistune Quadratic Parsing DoS in Formatting Plugins</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59928-mistune-quadratic-reflink-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:28:01.632Z</news:publication_date>
      <news:title>CVE-2026-59928: mistune Quadratic-Time ReDoS via Reference-Link Definitions</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61736-lightrag-cors-wildcard-credentials</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:48:51.361Z</news:publication_date>
      <news:title>CVE-2026-61736: lightrag-hku CORS Wildcard + Credentials Any-Origin Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61740-lightrag-hardcoded-jwt-secret-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:48:13.747Z</news:publication_date>
      <news:title>CVE-2026-61740: LightRAG Authentication Bypass via Hardcoded JWT Secret and Guest Token Short-Circuit</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>