<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  
    <url>
      <loc>https://cyber-osint.io/news/malicious-npm-packages-evade-install-script-defenses-at-runtime</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-20</news:publication_date>
        <news:title>Malicious npm packages evade install-script defenses at runtime</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/researchers-escape-openai-codex-sandbox-to-run-commands-on-host</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-20</news:publication_date>
        <news:title>Researchers escape OpenAI Codex sandbox to run commands on host</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>BragJack attacks hijack AI browser agents through malicious extensions</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/north-korean-waterplum-hackers-infected-30000-devices-worldwide</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>North Korean WaterPlum hackers infected 30,000 devices worldwide</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>ShinyHunters hacks Clop leak site, threatens to extort ransomware gang</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/identity-visibility-in-2026-the-foundation-of-identity-security</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>Identity Visibility in 2026: The Foundation of Identity Security</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/viral-ai-actress-hotline-face-scans-every-caller-watches-their-mood</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>Viral AI actress&apos; hotline face-scans every caller, watches their mood</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/calling-viral-ai-actress-tilly-norwood-agree-to-a-face-scan-first</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>Calling viral AI actress Tilly Norwood? Agree to a face scan first</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/claude-opus-5-helped-researchers-take-over-openai-staff-accounts-via-chained-flaws</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/solarwinds-patches-arm-hard-coded-key-flaw-enabling-unauthenticated-rce</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/critical-pre-auth-rce-in-orkes-conductor-workflow-platform-exploited-in-the-wild</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/google-gemini-broke-into-real-company-systems-after-security-test-domain-mix-up</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up</news:title>
      </news:news>
    </url>
</urlset>