<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
<url>
  <loc>https://hackwatch.io/alert/openai-scrapped-the-new-gpt-6-1-astra-model-following-security-concerns</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T13:16:30Z</news:publication_date>
    <news:title>OpenAI Scrapped the New GPT-6.1 Astra Model Following Security Concerns</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/pentagon-personnel-agency-data-breach-impacts-3-million-people</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T12:25:12Z</news:publication_date>
    <news:title>Pentagon Personnel Agency Data Breach Impacts 3 Million People</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/opensupdater-malware-hides-inside-7-zip-installers-to-evade-detection</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T12:16:52Z</news:publication_date>
    <news:title>OpenSUpdater Malware Hides Inside 7-Zip Installers to Evade Detection</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/phishing-exposure-nears-70-across-key-us-industries-what-should-security-teams-do</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T12:12:06Z</news:publication_date>
    <news:title>Phishing Exposure Nears 70% Across Key US Industries. What Should Security Teams Do?</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/malicious-custom-gpt-on-chatgpt-com-lures-users-into-installing-a-rat</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T11:55:25Z</news:publication_date>
    <news:title>Hackers Weaponizing ChatGPT’s Custom GPT Feature to Trick Victims into Installing Malware</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/vietnamese-man-charged-in-16-million-pig-butchering-crypto-scam</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T11:41:53Z</news:publication_date>
    <news:title>Vietnamese man charged in $16 million &apos;pig butchering&apos; crypto scam</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-ai-powered-botnet-x47-c-steals-credentials-and-drains-ai-account-credits</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T11:06:53Z</news:publication_date>
    <news:title>New AI-Powered Botnet x47.c Steals Credentials and Drains AI Account Credits</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/using-device-linking-to-eavesdrop-on-whatsapp-and-signal</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T11:02:19Z</news:publication_date>
    <news:title>Using Device Linking to Eavesdrop on WhatsApp and Signal</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/gauteng-e-panic-button-targeted-in-security-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T10:22:26Z</news:publication_date>
    <news:title>Gauteng e-Panic Button targeted in security breach</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/dprk-linked-hackers-add-hashhiding-to-blockchain-c2-network-for-takedown-resistant-malware</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T10:08:30Z</news:publication_date>
    <news:title>DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-watchguard-ap-flaws-let-unauthenticated-attackers-execute-arbitrary-commands</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T10:03:33Z</news:publication_date>
    <news:title>Critical WatchGuard AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/silverfox-built-fake-software-sites-that-know-when-researchers-are-watching</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T09:46:35Z</news:publication_date>
    <news:title>SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-exploit-sql-injection-flaw-to-steal-patient-data-from-polish-medical-software-prov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T09:17:43Z</news:publication_date>
    <news:title>Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/kiteworks-patches-critical-flaw-brings-customer-systems-online</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T09:04:06Z</news:publication_date>
    <news:title>Kiteworks patches critical flaw, brings customer systems online</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/keio-railway-confirms-ransomware-attack-disrupted-business-systems</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T08:03:42Z</news:publication_date>
    <news:title>Keio Railway Confirms Ransomware Attack Disrupted Business Systems</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-watchguard-api-vulnerabilities-enables-command-execution-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T08:00:44Z</news:publication_date>
    <news:title>Critical WatchGuard API Vulnerabilities Enables Command Execution Attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-tracks-needymantis-malware-targeting-telecoms-and-government-contractors</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T07:54:05Z</news:publication_date>
    <news:title>Microsoft Warns NeedyMantis Malware Enables Persistent Network Access</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/githubs-ai-agent-found-24-android-app-vulnerabilities</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T06:39:42Z</news:publication_date>
    <news:title>GitHub AI Security Agent Finds 24 Android Vulnerabilities Including Account Takeover Flaws</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T06:18:27Z</news:publication_date>
    <news:title>Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/official-mcp-python-sdk-flaw-can-let-malicious-servers-steal-oauth-credentials</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T06:08:25Z</news:publication_date>
    <news:title>Anthropic MCP Python SDK Flaw Enables OAuth Credential Theft and Account Takeover</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/agtabackup-rat-uses-fake-microsoft-store-pages-and-rmm-tools-to-hijack-windows-systems</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T05:47:11Z</news:publication_date>
    <news:title>AgtaBackup RAT Uses Fake Microsoft Store Pages and RMM Tools to Hijack Windows Systems</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hottest-cybersecurity-open-source-tools-of-the-month-september-2026</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T04:30:00Z</news:publication_date>
    <news:title>Hottest cybersecurity open-source tools of the month: September 2026</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cybersecurity-jobs-available-right-now-september-29-2026</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T04:00:33Z</news:publication_date>
    <news:title>Cybersecurity jobs available right now: September 29, 2026</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/autokeuribteu-midieoteg-cibses-cwiyagjeom-balgyeon-cve-2geon-sigbyeol-new-cyber-risk-repor</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T01:00:15Z</news:publication_date>
    <news:title>아우토크립트, 미디어텍 칩셋 보안 취약점 발견해 CVE 등록: new cyber risk reported by dailysecu.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/citrix-patches-actively-exploited-netscaler-zero-days-after-a-weekend-of-unofficial-warnin</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T00:58:15Z</news:publication_date>
    <news:title>Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/malicious-ad-blocking-extensions-exploit-chrome-web-store-trust</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T22:33:00Z</news:publication_date>
    <news:title>Malicious ad-blocking extensions exploit Chrome Web Store trust</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/clop-ransomware-gang-moves-to-new-server-after-grav-cms-vulnerability-exploited</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T22:10:21Z</news:publication_date>
    <news:title>Clop ransomware gang moves to new server after Grav CMS vulnerability exploited</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/exploit-in-data-reveals-enduring-roots-of-cybercrime-in-early-2000s-forum</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T22:00:21Z</news:publication_date>
    <news:title>Exploit.in data reveals enduring roots of cybercrime in early 2000s forum</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/exclusive-shinyhunters-says-fbi-data-wont-be-leaked-when-ultimatum-ends</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T21:45:03Z</news:publication_date>
    <news:title>Exclusive: ShinyHunters Says FBI Data Won’t Be Leaked When Ultimatum Ends</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/one-packet-can-crash-ot-servers-in-industrial-sectors</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T21:13:04Z</news:publication_date>
    <news:title>One Packet Can Crash OT Servers in Industrial Sectors</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/japan-s-keio-confirms-ransomware-attack-disrupted-business-systems</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T20:56:47Z</news:publication_date>
    <news:title>Japan&apos;s Keio confirms ransomware attack disrupted business systems</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/times-car-confirms-data-breach-affecting-6-6-million-user-accounts</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T20:31:16Z</news:publication_date>
    <news:title>Pentagon Data Breach – Hackers Reportedly Accessed 3 Million People’s Sensitive Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/carbonato-botnet-puts-an-ai-agent-on-hacked-docker-hosts</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T20:23:58Z</news:publication_date>
    <news:title>Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/apple-squashes-zero-day-bug-exploited-in-extremely-sophisticated-attack-cve-2026-86950</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T19:18:01Z</news:publication_date>
    <news:title>Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/jadepuffer-usa-ia-para-atacar-azure-e-destruir-recursos</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T19:04:35Z</news:publication_date>
    <news:title>JadePuffer usa IA para atacar Azure e destruir recursos</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/pentagon-data-breach-exposes-military-personnel</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T18:05:00Z</news:publication_date>
    <news:title>Pentagon Data Breach Exposes Military Personnel</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/previously-convicted-dutch-hacker-arrested-in-shinyhunters-odido-probe</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T17:43:56Z</news:publication_date>
    <news:title>Previously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bitget-says-attacker-exploited-third-party-security-product-flaw-to-steal-388m</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T17:42:18Z</news:publication_date>
    <news:title>Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/trojan-usa-wordpress-e-blockchain-para-roubar-credenciais</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T17:40:47Z</news:publication_date>
    <news:title>Trojan usa WordPress e blockchain para roubar credenciais</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/rathat-android-malware-console-uses-gemini-to-identify-higher-value-victims</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T17:38:33Z</news:publication_date>
    <news:title>RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cyberattack-on-welsh-police-force-may-have-exposed-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T17:15:00Z</news:publication_date>
    <news:title>Cyberattack on Welsh Police Force May Have Exposed Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/chrome-store-hosts-poper-blocker-spyware-downloaded-by-millions</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T16:51:25Z</news:publication_date>
    <news:title>Chrome Store Hosts &apos;Poper Blocker&apos; Spyware Downloaded by Millions</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-finds-new-malware-used-by-hackers-to-maintain-secret-access-inside-target-networ</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T16:35:03Z</news:publication_date>
    <news:title>Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/what-security-leaders-need-to-know-about-the-new-ransomware-economics</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T16:11:09Z</news:publication_date>
    <news:title>What Security Leaders Need to Know About the New Ransomware Economics</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/how-cross-account-trust-creates-exploitable-privilege-boundaries</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T16:06:09Z</news:publication_date>
    <news:title>How cross-account trust creates exploitable privilege boundaries</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T15:49:27Z</news:publication_date>
    <news:title>JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/kiteworks-lifts-advisory-after-precautionary-warning-for-customers-to-shut-down-systems</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T15:46:24Z</news:publication_date>
    <news:title>Kiteworks lifts advisory after precautionary warning for customers to shut down systems</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/threat-brief-netscaler-zero-days-cve-2026-88771-and-cve-2026-88772-exploited-in-the-wild</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T15:02:04Z</news:publication_date>
    <news:title>Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T15:00:00Z</news:publication_date>
    <news:title>NeedyMantis: Unpacking a post-compromise malware family used in targeted operations</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bitget-restarts-bitcoin-withdrawals-following-387-5m-wallet-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T15:00:00Z</news:publication_date>
    <news:title>Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/shinyhunters-trades-financial-extortion-for-a-reckless-war-of-ego-with-the-fbi</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:47:10Z</news:publication_date>
    <news:title>ShinyHunters trades financial extortion for a reckless war of ego with the FBI</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/truecaller-scam-checker-launches-in-india-how-it-works</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:41:28Z</news:publication_date>
    <news:title>Truecaller Scam Checker Launches in India: How It Works</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/autonomous-agents-attack-azure-using-compromised-identities-and-destroying-resources</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:22:22Z</news:publication_date>
    <news:title>Autonomous agents attack Azure using compromised identities and destroying resources</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bitget-backend-breach-drains-387-5-million-as-dprk-linked-launderers-expose-themselves</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:07:52Z</news:publication_date>
    <news:title>Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/weekly-recap-387m-crypto-hack-citrix-exploits-ai-agents-go-off-script-and-more-threats</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:00:53Z</news:publication_date>
    <news:title>⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/80000-organizations-had-ai-logins-stolen-from-shadow-ai-to-llmjacking</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:00:10Z</news:publication_date>
    <news:title>80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/28th-september-threat-intelligence-report-new-cyber-risk-reported-by-research-checkpoint-c</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T13:55:26Z</news:publication_date>
    <news:title>28th September – Threat Intelligence Report: new cyber risk reported by research.checkpoint.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/researchers-discover-cybercrime-server-containing-ai-tools-phishing-kits-and-stolen-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T13:22:17Z</news:publication_date>
    <news:title>Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-warns-of-microsoft-sharepoint-code-injection-vulnerability-exploited-in-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T13:21:22Z</news:publication_date>
    <news:title>CISA Warns of Microsoft SharePoint Code Injection Vulnerability Exploited in Attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/anthropic-declines-australian-ai-hearing-as-openai-agent-breach-faces-scrutiny</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T12:41:52Z</news:publication_date>
    <news:title>Anthropic Declines Australian AI Hearing as OpenAI Agent Breach Faces Scrutiny</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/other-users-can-watch-your-browsing-and-time-your-keystrokes-through-os-file-notifications</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T12:14:43Z</news:publication_date>
    <news:title>Other users can watch your browsing and time your keystrokes through OS file notifications</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/carbonato-botnet-compromises-docker-hosts-to-deploy-telegram-controlled-hermes-ai-agent</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T11:46:00Z</news:publication_date>
    <news:title>Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/vulnerability-summary-for-the-week-of-september-21-2026</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T11:32:46Z</news:publication_date>
    <news:title>Vulnerability Summary for the Week of September 21, 2026</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/drunk-ai-is-terrible-at-keeping-secrets-new-cyber-risk-reported-by-helpnetsecurity-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T11:30:22Z</news:publication_date>
    <news:title>“Drunk” AI is terrible at keeping secrets: new cyber risk reported by helpnetsecurity.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T10:56:46Z</news:publication_date>
    <news:title>ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-entra-trustsink-attack-uses-rogue-mfa-provider-to-steal-passwords</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T09:33:31Z</news:publication_date>
    <news:title>Microsoft Entra TrustSink Attack Uses Rogue MFA Provider to Steal Passwords</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fbi-agents-blood-tests-and-doctors-notes-surface-after-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T09:28:31Z</news:publication_date>
    <news:title>FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/guardrisk-distances-itself-from-mip-cyber-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T09:21:44Z</news:publication_date>
    <news:title>Guardrisk distances itself from MIP cyber breach</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/lumma-redline-and-vidar-infostealers-fuel-cloud-credential-theft-campaigns</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T09:12:23Z</news:publication_date>
    <news:title>Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/your-attack-surface-is-bigger-than-you-think-and-hackers-know-that</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T09:00:00Z</news:publication_date>
    <news:title>New File Notification Attack Lets Hackers Track User Activity Across Linux, Windows and macOS</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/python-maas-infostealer-builder-steals-passwords-credit-cards-and-cookies-from-17-browsers</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T08:41:03Z</news:publication_date>
    <news:title>Python MaaS Infostealer Builder Steals Passwords, Credit Cards and Cookies From 17 Browsers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/operation-master-exploits-globalprotect-cve-2026-0257-and-deploys-adaptixc2-across-enterpr</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T08:33:08Z</news:publication_date>
    <news:title>Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Netw</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/citrix-patches-critical-zero-days-under-active-exploitation</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T08:30:00Z</news:publication_date>
    <news:title>Citrix Patches Critical Zero Days Under Active Exploitation</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/stolen-ai-credentials-feed-growing-llm-proxy-economy</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T08:25:00Z</news:publication_date>
    <news:title>Stolen AI credentials feed growing LLM proxy economy</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/top-10-best-adaptive-risk-based-authentication-tools-in-2026-ranked-scored</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T07:02:08Z</news:publication_date>
    <news:title>Top 10 Best Authentication-as-a-Service (AaaS) Providers in 2026 [Ranked &amp; Scored]</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-turn-an-open-source-ai-agent-into-a-tool-for-controlling-compromised-docker-server</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T06:57:50Z</news:publication_date>
    <news:title>Hackers Turn an Open-Source AI Agent Into a Tool for Controlling Compromised Docker Servers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/viewsonic-vcast-vulnerabilities-let-attackers-gain-full-device-control-without-authenticat</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T06:38:20Z</news:publication_date>
    <news:title>Critical ViewSonic vCast Vulnerabilities Allow Attackers to Gain Full Control Over the Device</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/if-you-do-one-security-check-this-quarter-make-it-agent-memory</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T06:00:40Z</news:publication_date>
    <news:title>If you do one security check this quarter, make it agent memory</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/16-year-old-researcher-discovers-microsoft-authentication-bug-exposing-17-3-trillion-recor</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T05:36:42Z</news:publication_date>
    <news:title>16-Year-Old Researcher Discovers Microsoft Authentication Bug Exposing 17.3 Trillion Records</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/macsyncs-new-infection-chain-shows-how-mac-malware-is-becoming-more-sophisticated</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T05:12:21Z</news:publication_date>
    <news:title>MacSync’s New Infection Chain Shows How Mac Malware Is Becoming More Sophisticated</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-warns-of-citrix-netscaler-0-day-rce-vulnerabilities-exploited-in-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T18:04:39Z</news:publication_date>
    <news:title>Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/citrix-urges-immediate-upgrades-of-netscaler-amid-widespread-exploitation-attempts</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T17:56:38Z</news:publication_date>
    <news:title>Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T16:02:37Z</news:publication_date>
    <news:title>Kiteworks Warned Customers to Shut Down Servers Over Potential Zero-Day Attack</news:title>
  </news:news>
</url>
</urlset>