<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
<url>
  <loc>https://hackwatch.io/alert/bitget-backend-breach-drains-387-5-million-as-dprk-linked-launderers-expose-themselves</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:07:52Z</news:publication_date>
    <news:title>Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/80000-organizations-had-ai-logins-stolen-from-shadow-ai-to-llmjacking</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:00:10Z</news:publication_date>
    <news:title>80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/researchers-discover-cybercrime-server-containing-ai-tools-phishing-kits-and-stolen-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T13:22:17Z</news:publication_date>
    <news:title>Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-warns-of-microsoft-sharepoint-code-injection-vulnerability-exploited-in-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T13:21:22Z</news:publication_date>
    <news:title>CISA Warns of Microsoft SharePoint Code Injection Vulnerability Exploited in Attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/other-users-can-watch-your-browsing-and-time-your-keystrokes-through-os-file-notifications</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T12:14:43Z</news:publication_date>
    <news:title>Other users can watch your browsing and time your keystrokes through OS file notifications</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/carbonato-botnet-compromises-docker-hosts-to-deploy-telegram-controlled-hermes-ai-agent</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T11:46:00Z</news:publication_date>
    <news:title>Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/drunk-ai-is-terrible-at-keeping-secrets-new-cyber-risk-reported-by-helpnetsecurity-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T11:30:22Z</news:publication_date>
    <news:title>“Drunk” AI is terrible at keeping secrets: new cyber risk reported by helpnetsecurity.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T10:56:46Z</news:publication_date>
    <news:title>Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-entra-trustsink-attack-uses-rogue-mfa-provider-to-steal-passwords</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T09:33:31Z</news:publication_date>
    <news:title>Microsoft Entra TrustSink Attack Uses Rogue MFA Provider to Steal Passwords</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fbi-agents-blood-tests-and-doctors-notes-surface-after-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T09:28:31Z</news:publication_date>
    <news:title>FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/guardrisk-distances-itself-from-mip-cyber-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T09:21:44Z</news:publication_date>
    <news:title>Guardrisk distances itself from MIP cyber breach</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/lumma-redline-and-vidar-infostealers-fuel-cloud-credential-theft-campaigns</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T09:12:23Z</news:publication_date>
    <news:title>Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/your-attack-surface-is-bigger-than-you-think-and-hackers-know-that</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T09:00:00Z</news:publication_date>
    <news:title>Your attack surface is bigger than you think… and hackers know that</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/python-maas-infostealer-builder-steals-passwords-credit-cards-and-cookies-from-17-browsers</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T08:41:03Z</news:publication_date>
    <news:title>Python MaaS Infostealer Builder Steals Passwords, Credit Cards and Cookies From 17 Browsers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/operation-master-exploits-globalprotect-cve-2026-0257-and-deploys-adaptixc2-across-enterpr</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T08:33:08Z</news:publication_date>
    <news:title>Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Netw</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/citrix-patches-critical-zero-days-under-active-exploitation</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T08:30:00Z</news:publication_date>
    <news:title>Citrix Patches Critical Zero Days Under Active Exploitation</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/stolen-ai-credentials-feed-growing-llm-proxy-economy</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T08:25:00Z</news:publication_date>
    <news:title>Stolen AI credentials feed growing LLM proxy economy</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/top-10-best-adaptive-risk-based-authentication-tools-in-2026-ranked-scored</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T07:02:08Z</news:publication_date>
    <news:title>Top 10 Best Authentication-as-a-Service (AaaS) Providers in 2026 [Ranked &amp; Scored]</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-turn-an-open-source-ai-agent-into-a-tool-for-controlling-compromised-docker-server</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T06:57:50Z</news:publication_date>
    <news:title>Hackers Turn an Open-Source AI Agent Into a Tool for Controlling Compromised Docker Servers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/viewsonic-vcast-vulnerabilities-let-attackers-gain-full-device-control-without-authenticat</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T06:38:20Z</news:publication_date>
    <news:title>Critical ViewSonic vCast Vulnerabilities Allow Attackers to Gain Full Control Over the Device</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/if-you-do-one-security-check-this-quarter-make-it-agent-memory</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T06:00:40Z</news:publication_date>
    <news:title>If you do one security check this quarter, make it agent memory</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/16-year-old-researcher-discovers-microsoft-authentication-bug-exposing-17-3-trillion-recor</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T05:36:42Z</news:publication_date>
    <news:title>16-Year-Old Researcher Discovers Microsoft Authentication Bug Exposing 17.3 Trillion Records</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/macsyncs-new-infection-chain-shows-how-mac-malware-is-becoming-more-sophisticated</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T05:12:21Z</news:publication_date>
    <news:title>MacSync’s New Infection Chain Shows How Mac Malware Is Becoming More Sophisticated</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-warns-of-citrix-netscaler-0-day-rce-vulnerabilities-exploited-in-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T18:04:39Z</news:publication_date>
    <news:title>Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/netscaler-admins-told-to-patch-critical-zero-days-in-adc-and-gateway-now</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T17:56:38Z</news:publication_date>
    <news:title>NetScaler admins told to patch critical zero-days in ADC and Gateway now</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T16:02:37Z</news:publication_date>
    <news:title>Kiteworks Warned Customers to Shut Down Servers Over Potential Zero-Day Attack</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/sicherheitsforscher-warnen-neue-zero-day-exploits-in-citrix-netscaler</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T11:47:35Z</news:publication_date>
    <news:title>Sicherheitsforscher warnen: Neue Zero-Day-Exploits in Citrix Netscaler?</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-sharepoint-flaw-cve-2026-65660-now-exploited-in-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T09:23:09Z</news:publication_date>
    <news:title>Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/week-in-review-gyazo-breach-exposes-23-6m-user-data-task-stomp-steals-documents</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T08:00:49Z</news:publication_date>
    <news:title>Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/which-platforms-to-use-for-enterprise-threat-intelligence</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T03:59:32Z</news:publication_date>
    <news:title>Which Platforms to Use for Enterprise Threat Intelligence</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/lunex-stealer-abuses-amd-driver-to-disable-security-monitoring-and-steal-browser-credentia</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-26T18:22:52Z</news:publication_date>
    <news:title>Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials</news:title>
  </news:news>
</url>
</urlset>