<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://www.hackerposts.org/en/blog/github-543699-live-credentials-trufflesecurity</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T00:00:00.000Z</news:publication_date>
      <news:title>Truffle: 543,699 live credentials sitting in public GitHub repos</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/en/blog/metamask-staking-incident-lido-validator-exit</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T00:00:00.000Z</news:publication_date>
      <news:title>MetaMask exits Lido validators after staking-infrastructure incident</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/en/blog/zammad-cve-2026-102489-102490-divd-ai-breach</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T00:00:00.000Z</news:publication_date>
      <news:title>Zammad zero-days (CVE-2026-102489/102490) chained to root; patch now</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/fr/blog/ffrandonnee-fuite-1-43-million-fiches-adherents</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>fr</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T00:00:00.000Z</news:publication_date>
      <news:title>FFRandonnée : 1,43 million de fiches d&apos;adhérents mises en vente</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/en/blog/bitget-crypto-hack-387m-zero-day-security-appliance</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>Bitget blames $387M crypto theft on zero-days in security appliances</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/en/blog/chatgpt-custom-gpt-clickfix-rat-huntress</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>Malicious custom GPT &apos;Plus 5.6&apos; funnels users into ClickFix RAT</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/en/blog/cisco-catalyst-sd-wan-manager-cve-2026-76504-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>Cisco patches exploited SD-WAN Manager auth bypass (CVE-2026-76504)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/en/blog/dgfip-impots-data-theft-350000-anssi</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>France&apos;s DGFiP breach: 350k+ people hit via stolen passwords</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/en/blog/kiteworks-advanced-forms-critical-flaw-9-5-1</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>Kiteworks patches critical Advanced Forms flaw in release 9.5.1</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/en/blog/microsoft-entra-id-csp-block-script-injection</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>Microsoft Entra ID to enforce CSP, blocking sign-in script injection</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/en/blog/mikrotik-routeros-cve-2026-84411-preauth-rce</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>CISA flags pre-auth root RCE in MikroTik RouterOS (CVE-2026-84411)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/en/blog/openssl-cve-2026-84782-dtls-heap-leak</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>OpenSSL patches DTLS heap-disclosure flaw CVE-2026-84782</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/en/blog/star-blizzard-redflick-cosmicpulse-100-orgs</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>Star Blizzard hits 100+ orgs with RedFlick, CosmicPulse backdoor</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/en/blog/teamviewer-cve-2026-92370-full-client-rce</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>TeamViewer patches CVE-2026-92370 access-control bypass (CVSS 8.8)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/en/blog/watchguard-fireware-cve-2026-86131-bovpn-rce</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>WatchGuard patches critical Fireware OS RCE (CVE-2026-86131)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/fr/blog/chrome-154-certfr-2026-avi-1237-32-failles</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>fr</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>Chrome 154 : Google corrige 32 failles, dont une critique dans ANGLE</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/fr/blog/dgfip-impots-data-theft-350000-anssi</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>fr</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>Fuite DGFiP : 350 000 particuliers exposés via mots de passe volés</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/fr/blog/firefox-157-esr-mfsa-2026-097-100</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>fr</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>Firefox 157 et ESR : Mozilla corrige des dizaines de failles</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/fr/blog/hpe-aruba-instant-on-cve-2026-76721-rce</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>fr</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>HPE Aruba Instant On : RCE critique non authentifiée (CVE-2026-76721)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/fr/blog/mongodb-certfr-2026-avi-1234-cinq-cve</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>fr</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>MongoDB : cinq CVE corrigées, l&apos;ANSSI publie CERTFR-2026-AVI-1234</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/fr/blog/openssl-cve-2026-84782-dtls-heap-leak</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>fr</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>OpenSSL corrige une faille DTLS qui fuit la mémoire (CVE-2026-84782)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://www.hackerposts.org/fr/blog/oracle-peoplesoft-cve-2026-35273-waf-bypass-shinyhunters</loc>
    <news:news>
      <news:publication>
        <news:name>Hacker Posts</news:name>
        <news:language>fr</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>ShinyHunters contourne le WAF PeopleSoft (CVE-2026-35273) : reprise</news:title>
    </news:news>
  </url>
</urlset>
