<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"><url><loc>https://malwarebrief.com/section/vulnerabilities/unreviewed-ai-bug-reports-go-straight-to-opted-in/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T14:33:14Z</news:publication_date><news:title>Unreviewed AI bug reports go straight to opted-in OSS maintainers to speed patching</news:title></news:news></url><url><loc>https://malwarebrief.com/section/data-breaches/shinyhunters-suspect-jailed-following-fbi/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T14:32:59Z</news:publication_date><news:title>ShinyHunters Suspect Jailed Following FBI Recruitment Portal Breach and Agent Data Theft</news:title></news:news></url><url><loc>https://malwarebrief.com/section/cyber-attacks/malicious-github-workflows-infect-340/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T14:32:59Z</news:publication_date><news:title>Malicious GitHub Workflows Infect 340 Repositories via Hijacked Maintainer Accounts</news:title></news:news></url><url><loc>https://malwarebrief.com/section/vulnerabilities/orgs-with-falkordb-bolt-endpoint-exposed-face/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T14:32:35Z</news:publication_date><news:title>Orgs with FalkorDB Bolt Endpoint Exposed Face Critical Auth Bypass CVE-2026-107910</news:title></news:news></url><url><loc>https://malwarebrief.com/section/vulnerabilities/eduadmin-booking-sql-injection-risk-threatens/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T14:32:35Z</news:publication_date><news:title>EduAdmin Booking SQL Injection Risk Threatens Data Integrity for Institutions</news:title></news:news></url><url><loc>https://malwarebrief.com/section/vulnerabilities/organizations-urged-to-patch-themerex-lets-play/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T14:32:35Z</news:publication_date><news:title>Organizations Urged to Patch ThemeREX Let&#x27;s Play v1.1.15 to Mitigate Critical 9.8 CVSS Deserialization Risk</news:title></news:news></url><url><loc>https://malwarebrief.com/section/vulnerabilities/organisations-risk-remote-code-execution-via/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-09T18:42:29Z</news:publication_date><news:title>Organisations Risk Remote Code Execution via Critical Command Injection in @enmaso/node-convert Library</news:title></news:news></url><url><loc>https://malwarebrief.com/section/vulnerabilities/skyeye-tts-vulnerability-enables-unauth/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-09T18:42:21Z</news:publication_date><news:title>Skyeye TTS Vulnerability Enables Unauth PowerShell Execution on Windows Servers</news:title></news:news></url><url><loc>https://malwarebrief.com/section/cyber-attacks/organizations-urged-to-check-ssl-certs-after/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-09T18:40:54Z</news:publication_date><news:title>Organizations urged to check SSL certs after hackers hijacked .gh, .sl, .as to forge Google HTTPS</news:title></news:news></url><url><loc>https://malwarebrief.com/section/vulnerabilities/open-source-maintainers-receive-automated-ai/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-09T18:20:38Z</news:publication_date><news:title>Open-source maintainers receive automated AI vulnerability reports from Anthropic&#x27;s new free scanner</news:title></news:news></url><url><loc>https://malwarebrief.com/section/vulnerabilities/critical-unauth-sqli-in-phpnuxbill-freeradius/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-09T18:20:38Z</news:publication_date><news:title>Critical Unauth SQLi in PHPNuxBill FreeRADIUS Puts Orgs at Risk, Enabling Credential Theft via Blind Injection</news:title></news:news></url><url><loc>https://malwarebrief.com/section/vulnerabilities/organisations-urged-to-patch-ibm-guardium-12-1/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-09T15:03:09Z</news:publication_date><news:title>Organisations urged to patch IBM Guardium 12.1/12.2.2 to stop unauthenticated container hijack and cluster takeover</news:title></news:news></url><url><loc>https://malwarebrief.com/section/vulnerabilities/organisations-urged-to-patch-ibm-guardium-12-0/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-09T14:41:36Z</news:publication_date><news:title>Organisations urged to patch IBM Guardium 12.0-12.2 after critical unauthenticated RCE flaw exposed</news:title></news:news></url><url><loc>https://malwarebrief.com/section/vulnerabilities/ibm-access-software-flaw-lets-attackers-run-code/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-09T14:29:55Z</news:publication_date><news:title>IBM access software flaw lets attackers run code without credentials, hitting versions up to 10.0.9.2 and 11.0.3</news:title></news:news></url><url><loc>https://malwarebrief.com/section/vulnerabilities/service-outages-loom-as-cisa-orders-federal-bind/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-09T13:08:14Z</news:publication_date><news:title>Service Outages Loom as CISA Orders Federal BIND TKEY Fixes by Oct 11</news:title></news:news></url><url><loc>https://malwarebrief.com/section/cyber-attacks/asos-customers-face-data-exposure-after-hackers/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-08T18:22:19Z</news:publication_date><news:title>Asos customers face data exposure after hackers claim full cloud compromise</news:title></news:news></url><url><loc>https://malwarebrief.com/section/cloud-security/cloudflare-radar-redesign-helps-orgs-access-real/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-08T18:05:42Z</news:publication_date><news:title>Cloudflare Radar Redesign Helps Orgs Access Real-Time Traffic Data Without Technical Skills</news:title></news:news></url><url><loc>https://malwarebrief.com/section/vulnerabilities/handlebars-rce-flaw-allows-server-compromise-via/</loc><news:news><news:publication><news:name>Malware Brief</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-08T18:05:42Z</news:publication_date><news:title>Handlebars RCE flaw allows server compromise via prototype bypass</news:title></news:news></url></urlset>