<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  
    <url>
      <loc>https://cyber-osint.io/news/calling-viral-ai-actress-tilly-norwood-agree-to-a-face-scan-first</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>Calling viral AI actress Tilly Norwood? Agree to a face scan first</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/claude-opus-5-helped-researchers-take-over-openai-staff-accounts-via-chained-flaws</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/solarwinds-patches-arm-hard-coded-key-flaw-enabling-unauthenticated-rce</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/critical-pre-auth-rce-in-orkes-conductor-workflow-platform-exploited-in-the-wild</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/google-gemini-broke-into-real-company-systems-after-security-test-domain-mix-up</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/crowdsec-says-tanstack-npm-attack-led-to-copy-of-170-private-github-repositories</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/cisa-flags-three-linux-kernel-vulnerabilities-exploited-in-the-wild</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-19</news:publication_date>
        <news:title>CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/vectra-ai-launches-ascent-to-help-address-new-era-of-ai-driven-attacks</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/cisco-zero-day-highlights-api-endpoint-authentication-issues</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Cisco Zero-Day Highlights API Endpoint Authentication Issues</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/ey-survey-finds-autonomous-ai-implementation-outpaces-oversight</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>EY Survey Finds Autonomous AI Implementation Outpaces Oversight</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/mfa-wont-save-you-from-oauth-consent-abuse</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>MFA Won&apos;t Save You From OAuth Consent Abuse</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/public-exploits-released-for-four-linux-kernel-flaws-that-enable-local-root</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/new-wordpress-click2shell-flaw-forces-theme-installs-can-chain-to-code-execution</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/why-less-is-more-in-symantec-pam-clustering</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Why &quot;Less Is More&quot; in Symantec PAM Clustering</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/gyazo-server-flaw-exploited-to-steal-236-million-user-records</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Gyazo server flaw exploited to steal 23.6 million user records</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/new-android-malware-uses-ai-to-steal-bank-logins-and-pins</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>New Android malware uses AI to steal bank logins and PINs</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/transparent-tribe-deploys-new-rust-backdoor-using-private-github-repositories-for-c2</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/prime-detect-roi-validated-savings-from-detection-at-the-pipeline-layer</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Prime Detect ROI: Validated Savings from Detection at the Pipeline Layer</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/nations-take-action-on-north-korean-it-workers-after-un-report</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Nations take action on North Korean IT workers after UN report</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/did-an-ai-really-try-to-break-free-from-human-control</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Did an AI really try to break free from human control?</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/secure-enterprise-sharing-with-access-reviews-for-microsoft-365</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Secure enterprise sharing with access reviews for Microsoft 365</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/microsoft-teams-will-let-admins-block-custom-file-extensions</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Microsoft Teams will let admins block custom file extensions</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/hacking-group-nighteagle-targeting-chinas-high-tech-sector-expands-operations-to-russia</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/webinar-which-google-workspace-security-controls-actually-matter</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Webinar: Which Google Workspace security controls actually matter?</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/microsoft-patches-cvss-100-azure-ai-foundry-flaw-enabling-unauthorized-privilege-escalation</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/microsoft-fixes-bug-behind-defender-antivirus-is-turned-off-alerts</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/an-abandoned-cdn-domain-was-re-registered-thousands-of-sites-still-call-it</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/plugin4shell-lets-repository-owners-swap-pinned-plugin-code-across-four-ai-coding-agents</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/weaselbiscuit-stealer-spreads-via-13-npm-packages-to-harvest-chrome-extension-storage</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/a-vault-with-a-heap-view-the-uncomfortable-space-between-agentcore-harness-and-identity</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/virtual-event-cybersecurity-outlook-2027</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>[Virtual Event] Cybersecurity Outlook 2027</news:title>
      </news:news>
    </url>
    <url>
      <loc>https://cyber-osint.io/news/new-check-point-flaw-lets-hackers-execute-code-with-root-privileges</loc>
      <news:news>
        <news:publication>
          <news:name>CyberOSINT</news:name>
          <news:language>en</news:language>
        </news:publication>
        <news:publication_date>2026-09-18</news:publication_date>
        <news:title>New Check Point flaw lets hackers execute code with root privileges</news:title>
      </news:news>
    </url>
</urlset>