<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
<url>
  <loc>https://hackwatch.io/alert/bitget-hacked-via-zero-day-in-third-party-security-products</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T11:11:46Z</news:publication_date>
    <news:title>Bitget hacked via zero-day in third-party security products</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/openinfra-europes-jfrog-artifactory-instance-breached-packages-potentially-compromised</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T10:39:26Z</news:publication_date>
    <news:title>OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/shared-intel-q-a-ai-finds-flaws-faster-defenders-still-need-to-fix-what-attackers-exploit</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T10:02:58Z</news:publication_date>
    <news:title>SHARED INTEL Q&amp;A: AI finds flaws faster — defenders still need to fix what attackers exploit</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T10:00:01Z</news:publication_date>
    <news:title>China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/the-mfa-you-have-isnt-the-mfa-you-think-you-have</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T10:00:00Z</news:publication_date>
    <news:title>The MFA you have isn’t the MFA you think you have</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/waterisac-reckons-with-range-of-threats-after-summer-of-cyberattacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T10:00:00Z</news:publication_date>
    <news:title>WaterISAC reckons with range of threats after summer of cyberattacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-exploit-citrix-netscaler-zero-day-to-gain-root-access-and-deploy-web-shells</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T09:33:11Z</news:publication_date>
    <news:title>Hackers Abuse MSP360 and ScreenConnect RMM Tools for Persistent Access and Credential Theft</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/can-we-jail-a-superintelligence-new-cyber-risk-reported-by-csoonline-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T09:00:00Z</news:publication_date>
    <news:title>Can we jail a superintelligence?: new cyber risk reported by csoonline.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ransomware-gangs-steal-896-terabytes-zscaler-says</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T08:54:00Z</news:publication_date>
    <news:title>Ransomware gangs steal 896 terabytes, Zscaler says</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/emergency-updates-fix-coregraphics-zero-day-linked-to-targeted-zero-click-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T08:45:00Z</news:publication_date>
    <news:title>Emergency updates fix CoreGraphics zero day linked to targeted zero click attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/linux-kernel-cve-2026-72018-flaw-lets-local-attackers-gain-root-access</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T07:46:51Z</news:publication_date>
    <news:title>AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/south-africa-seeks-help-after-cyberattack-targets-air-traffic-control</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T07:00:00Z</news:publication_date>
    <news:title>South Africa Seeks Help After Cyberattack Targets Air Traffic Control</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/high-severity-vulnerabilities-patched-in-openssl-wolfssl</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T06:55:50Z</news:publication_date>
    <news:title>High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/storm-3068-hijacks-azure-devops-pipelines-to-steal-kubernetes-credentials-after-account-ta</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T06:38:15Z</news:publication_date>
    <news:title>Storm-3068 Hijacks Azure DevOps Pipelines to Steal Kubernetes Credentials After Account Takeover</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/android-malware-turns-gemini-ai-into-an-assistant-for-on-device-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T05:58:20Z</news:publication_date>
    <news:title>RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/sectoprat-malware-hides-in-legitimate-software-to-steal-browser-credentials-and-crypto-wal</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T05:33:58Z</news:publication_date>
    <news:title>Fortinet Uncovers SectopRAT Variant Hidden Inside Tampered Legitimate Windows Software</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/citrix-netscaler-cve-2026-88772-exploit-details-show-pre-auth-path-to-shellcode-execution</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T05:30:30Z</news:publication_date>
    <news:title>Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/openssl-fixes-high-severity-flaw-that-can-leak-server-memory-in-plaintext</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T05:14:11Z</news:publication_date>
    <news:title>OpenSSL Fixes High-Severity Flaw That Can Leak Server Memory in Plaintext</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/openai-rolled-out-codex-security-cloud-an-always-on-application-security-service</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T04:36:20Z</news:publication_date>
    <news:title>OpenAI Rolled out Codex Security Cloud, an Always-on Application Security Service</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/octopus-server-flaw-lets-authenticated-users-execute-code-through-insecure-json-deserializ</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T04:11:37Z</news:publication_date>
    <news:title>Unsloth Studio RCE Flaw Lets Malicious Hugging Face Models Execute Code</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/most-open-critical-and-high-flaws-are-over-90-days-old</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T04:00:38Z</news:publication_date>
    <news:title>Most open critical and high flaws are over 90 days old</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/security-news-hkcert-new-cyber-risk-reported-by-hkcert-org-3</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T02:15:26Z</news:publication_date>
    <news:title>Security News | HKCERT: new cyber risk reported by hkcert.org</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/phantomsub-campaign-uses-101-npm-packages-to-add-developers-to-whatsapp-groups</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T00:37:23Z</news:publication_date>
    <news:title>PhantomSub campaign uses 101 npm packages to add developers to WhatsApp groups</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/vietnamese-national-charged-in-16-million-cryptocurrency-pig-butchering-scam</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-30T00:32:23Z</news:publication_date>
    <news:title>Vietnamese national charged in $16 million cryptocurrency pig butchering scam</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/phishing-abuses-rmm-tools-for-persistent-access</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T21:39:27Z</news:publication_date>
    <news:title>Phishing Abuses RMM Tools for Persistent Access</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/apple-zero-day-vulnerability-weaponized-in-targeted-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T21:31:29Z</news:publication_date>
    <news:title>Apple Zero-Day Vulnerability Weaponized in Targeted Attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T20:59:39Z</news:publication_date>
    <news:title>Custom ChatGPTs push ClickFix attacks to deploy RAT malware</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-adds-one-known-exploited-vulnerability-to-catalog-3</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T19:19:28Z</news:publication_date>
    <news:title>CISA Adds One Known Exploited Vulnerability to Catalog</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/llmjacking-can-run-up-your-business-ai-bill-fast-how-to-stop-it</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T19:09:53Z</news:publication_date>
    <news:title>LLMjacking can run up your business’ AI bill fast – how to stop it</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/attackers-exploited-citrix-netscaler-zero-day-for-at-least-three-weeks-undetected</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T18:37:12Z</news:publication_date>
    <news:title>Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/former-us-air-force-members-sent-to-prison-over-bec-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T18:09:39Z</news:publication_date>
    <news:title>Former US Air Force members behind million-dollar BEC scheme head to prison</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/french-tax-data-theft-using-stolen-staff-passwords-went-undetected-for-seven-weeks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T17:47:01Z</news:publication_date>
    <news:title>French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-spectre-v2-btr-attack-leaks-linux-memory-despite-existing-defenses</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T17:00:00Z</news:publication_date>
    <news:title>New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/how-us-socs-and-mssps-can-use-threat-intelligence-to-detect-phishing-infrastructure-earlie</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T16:06:22Z</news:publication_date>
    <news:title>How US SOCs and MSSPs Can Use Threat Intelligence to Detect Phishing Infrastructure Earlier</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T15:39:19Z</news:publication_date>
    <news:title>Automated AI agent used to breach cybersecurity nonprofit DIVD</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/viidure-dashcam-android-application-new-cyber-risk-reported-by-us-cert-gov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T15:18:33Z</news:publication_date>
    <news:title>Viidure Dashcam Android Application: new cyber risk reported by us-cert.gov</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/mikrotik-routeros-new-cyber-risk-reported-by-us-cert-gov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T15:13:22Z</news:publication_date>
    <news:title>MikroTik RouterOS: new cyber risk reported by us-cert.gov</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/anjvision-yssd-rtmp-h5-new-cyber-risk-reported-by-us-cert-gov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T15:07:16Z</news:publication_date>
    <news:title>Anjvision YSSD-RTMP-H5: new cyber risk reported by us-cert.gov</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/baicells-nova-430h-new-cyber-risk-reported-by-us-cert-gov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T15:03:45Z</news:publication_date>
    <news:title>Baicells Nova 430H: new cyber risk reported by us-cert.gov</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/vivotek-camera-firmware-new-cyber-risk-reported-by-us-cert-gov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T15:00:03Z</news:publication_date>
    <news:title>VIVOTEK Camera Firmware: new cyber risk reported by us-cert.gov</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T15:00:00Z</news:publication_date>
    <news:title>Russia&apos;s Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T14:59:06Z</news:publication_date>
    <news:title>NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/toptech-tms7-and-tophat-new-cyber-risk-reported-by-us-cert-gov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T14:53:54Z</news:publication_date>
    <news:title>Toptech TMS7 and TopHAT: new cyber risk reported by us-cert.gov</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/lantronix-g520-series-cellular-gateway-new-cyber-risk-reported-by-us-cert-gov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T14:39:25Z</news:publication_date>
    <news:title>Lantronix G520 Series Cellular Gateway: new cyber risk reported by us-cert.gov</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/rathat-s-evolving-c2-panel-points-to-malware-as-a-service-model</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T14:30:00Z</news:publication_date>
    <news:title>RatHat&apos;s Evolving C2 Panel Points to Malware-as-a-Service Model</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/kiteworks-lifts-shutdown-advisory-after-credible-threat-intelligence-from-federal-authorit</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T14:11:43Z</news:publication_date>
    <news:title>Kiteworks lifts shutdown advisory after ‘credible threat intelligence’ from federal authorities</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/openai-scrapped-the-new-gpt-6-1-astra-model-following-security-concerns</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T13:16:30Z</news:publication_date>
    <news:title>OpenAI Scrapped the New GPT-6.1 Astra Model Following Security Concerns</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/pentagon-personnel-agency-data-breach-impacts-3-million-people</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T12:25:12Z</news:publication_date>
    <news:title>Pentagon Personnel Agency Data Breach Impacts 3 Million People</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/opensupdater-malware-hides-inside-7-zip-installers-to-evade-detection</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T12:16:52Z</news:publication_date>
    <news:title>OpenSUpdater Malware Hides Inside 7-Zip Installers to Evade Detection</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/phishing-exposure-nears-70-across-key-us-industries-what-should-security-teams-do</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T12:12:06Z</news:publication_date>
    <news:title>Phishing Exposure Nears 70% Across Key US Industries. What Should Security Teams Do?</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-turned-ethereum-into-a-secret-messaging-system-for-malware</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T11:55:25Z</news:publication_date>
    <news:title>Hackers Turned Ethereum Into a Secret Messaging System for Malware</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/vietnamese-man-charged-in-16-million-pig-butchering-crypto-scam</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T11:41:53Z</news:publication_date>
    <news:title>Vietnamese man charged in $16 million &apos;pig butchering&apos; crypto scam</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-ai-powered-botnet-x47-c-steals-credentials-and-drains-ai-account-credits</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T11:06:53Z</news:publication_date>
    <news:title>New AI-Powered Botnet x47.c Steals Credentials and Drains AI Account Credits</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/using-device-linking-to-eavesdrop-on-whatsapp-and-signal</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T11:02:19Z</news:publication_date>
    <news:title>Using Device Linking to Eavesdrop on WhatsApp and Signal</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/openai-o-leak-what-we-know-about-chatgpts-always-on-assistant-before-devday</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T10:50:06Z</news:publication_date>
    <news:title>OpenAI ‘o’ Leak: What We Know About ChatGPT’s Always-On Assistant Before DevDay</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/gauteng-e-panic-button-targeted-in-security-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T10:22:26Z</news:publication_date>
    <news:title>Gauteng e-Panic Button targeted in security breach</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/dprk-linked-hackers-add-hashhiding-to-blockchain-c2-network-for-takedown-resistant-malware</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T10:08:30Z</news:publication_date>
    <news:title>DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-watchguard-ap-flaws-let-unauthenticated-attackers-execute-arbitrary-commands</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T10:03:33Z</news:publication_date>
    <news:title>Critical WatchGuard AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-hide-malware-inside-7-zip-installers-using-a-new-evasion-technique</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T09:46:35Z</news:publication_date>
    <news:title>Hackers Hide Malware Inside 7-Zip Installers Using a New Evasion Technique</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-exploit-sql-injection-flaw-to-steal-patient-data-from-polish-medical-software-prov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T09:17:43Z</news:publication_date>
    <news:title>Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/kiteworks-patches-critical-flaw-brings-customer-systems-online</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T09:04:06Z</news:publication_date>
    <news:title>Kiteworks patches critical flaw, brings customer systems online</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/keio-railway-confirms-ransomware-attack-disrupted-business-systems</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T08:03:42Z</news:publication_date>
    <news:title>Keio Railway Confirms Ransomware Attack Disrupted Business Systems</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-watchguard-api-vulnerabilities-enables-command-execution-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T08:00:44Z</news:publication_date>
    <news:title>Critical WatchGuard API Vulnerabilities Enables Command Execution Attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-tracks-needymantis-malware-targeting-telecoms-and-government-contractors</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T07:54:05Z</news:publication_date>
    <news:title>Microsoft Warns NeedyMantis Malware Enables Persistent Network Access</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/githubs-ai-agent-found-24-android-app-vulnerabilities</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T06:39:42Z</news:publication_date>
    <news:title>GitHub AI Security Agent Finds 24 Android Vulnerabilities Including Account Takeover Flaws</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T06:18:27Z</news:publication_date>
    <news:title>Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/official-mcp-python-sdk-flaw-can-let-malicious-servers-steal-oauth-credentials</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T06:08:25Z</news:publication_date>
    <news:title>Anthropic MCP Python SDK Flaw Enables OAuth Credential Theft and Account Takeover</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/agtabackup-rat-uses-fake-microsoft-store-pages-and-rmm-tools-to-hijack-windows-systems</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T05:47:11Z</news:publication_date>
    <news:title>AgtaBackup RAT Uses Fake Microsoft Store Pages and RMM Tools to Hijack Windows Systems</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hottest-cybersecurity-open-source-tools-of-the-month-september-2026</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T04:30:00Z</news:publication_date>
    <news:title>Hottest cybersecurity open-source tools of the month: September 2026</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cybersecurity-jobs-available-right-now-september-29-2026</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T04:00:33Z</news:publication_date>
    <news:title>Cybersecurity jobs available right now: September 29, 2026</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/autokeuribteu-midieoteg-cibses-cwiyagjeom-balgyeon-cve-2geon-sigbyeol-new-cyber-risk-repor</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T01:00:15Z</news:publication_date>
    <news:title>아우토크립트, 미디어텍 칩셋 보안 취약점 발견해 CVE 등록: new cyber risk reported by dailysecu.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/citrix-patches-actively-exploited-netscaler-zero-days-after-a-weekend-of-unofficial-warnin</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-29T00:58:15Z</news:publication_date>
    <news:title>Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/malicious-ad-blocking-extensions-exploit-chrome-web-store-trust</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T22:33:00Z</news:publication_date>
    <news:title>Malicious ad-blocking extensions exploit Chrome Web Store trust</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/clop-ransomware-gang-moves-to-new-server-after-grav-cms-vulnerability-exploited</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T22:10:21Z</news:publication_date>
    <news:title>Clop ransomware gang moves to new server after Grav CMS vulnerability exploited</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/exploit-in-data-reveals-enduring-roots-of-cybercrime-in-early-2000s-forum</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T22:00:21Z</news:publication_date>
    <news:title>Exploit.in data reveals enduring roots of cybercrime in early 2000s forum</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/exclusive-shinyhunters-says-fbi-data-wont-be-leaked-when-ultimatum-ends</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T21:45:03Z</news:publication_date>
    <news:title>Exclusive: ShinyHunters Says FBI Data Won’t Be Leaked When Ultimatum Ends</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/dual-netscaler-zero-days-trigger-chaos-for-citrix-customers</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T21:19:43Z</news:publication_date>
    <news:title>Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/one-packet-can-crash-ot-servers-in-industrial-sectors</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T21:13:04Z</news:publication_date>
    <news:title>One Packet Can Crash OT Servers in Industrial Sectors</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/japan-s-keio-confirms-ransomware-attack-disrupted-business-systems</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T20:56:47Z</news:publication_date>
    <news:title>Japan&apos;s Keio confirms ransomware attack disrupted business systems</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/times-car-confirms-data-breach-affecting-6-6-million-user-accounts</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T20:31:16Z</news:publication_date>
    <news:title>Pentagon Data Breach – Hackers Reportedly Accessed 3 Million People’s Sensitive Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/carbonato-botnet-puts-an-ai-agent-on-hacked-docker-hosts</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T20:23:58Z</news:publication_date>
    <news:title>Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/apple-squashes-zero-day-bug-exploited-in-extremely-sophisticated-attack-cve-2026-86950</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T19:18:01Z</news:publication_date>
    <news:title>Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/jadepuffer-usa-ia-para-atacar-azure-e-destruir-recursos</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T19:04:35Z</news:publication_date>
    <news:title>JadePuffer usa IA para atacar Azure e destruir recursos</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/pentagon-data-breach-exposes-military-personnel</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T18:05:00Z</news:publication_date>
    <news:title>Pentagon Data Breach Exposes Military Personnel</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/previously-convicted-dutch-hacker-arrested-in-shinyhunters-odido-probe</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T17:43:56Z</news:publication_date>
    <news:title>Previously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bitget-says-attacker-exploited-third-party-security-product-flaw-to-steal-388m</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T17:42:18Z</news:publication_date>
    <news:title>Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/trojan-usa-wordpress-e-blockchain-para-roubar-credenciais</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T17:40:47Z</news:publication_date>
    <news:title>Trojan usa WordPress e blockchain para roubar credenciais</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/rathat-android-malware-console-uses-gemini-to-identify-higher-value-victims</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T17:38:33Z</news:publication_date>
    <news:title>RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cyberattack-on-welsh-police-force-may-have-exposed-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T17:15:00Z</news:publication_date>
    <news:title>Cyberattack on Welsh Police Force May Have Exposed Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/chrome-store-hosts-poper-blocker-spyware-downloaded-by-millions</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T16:51:25Z</news:publication_date>
    <news:title>Chrome Store Hosts &apos;Poper Blocker&apos; Spyware Downloaded by Millions</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-finds-new-malware-used-by-hackers-to-maintain-secret-access-inside-target-networ</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T16:35:03Z</news:publication_date>
    <news:title>Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/what-security-leaders-need-to-know-about-the-new-ransomware-economics</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T16:11:09Z</news:publication_date>
    <news:title>What Security Leaders Need to Know About the New Ransomware Economics</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/how-cross-account-trust-creates-exploitable-privilege-boundaries</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T16:06:09Z</news:publication_date>
    <news:title>How cross-account trust creates exploitable privilege boundaries</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T15:49:27Z</news:publication_date>
    <news:title>JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/kiteworks-lifts-advisory-after-precautionary-warning-for-customers-to-shut-down-systems</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T15:46:24Z</news:publication_date>
    <news:title>Kiteworks lifts advisory after precautionary warning for customers to shut down systems</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/threat-brief-netscaler-zero-days-cve-2026-88771-and-cve-2026-88772-exploited-in-the-wild</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T15:02:04Z</news:publication_date>
    <news:title>Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bitget-restarts-bitcoin-withdrawals-following-387-5m-wallet-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T15:00:00Z</news:publication_date>
    <news:title>Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T15:00:00Z</news:publication_date>
    <news:title>NeedyMantis: Unpacking a post-compromise malware family used in targeted operations</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/shinyhunters-trades-financial-extortion-for-a-reckless-war-of-ego-with-the-fbi</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:47:10Z</news:publication_date>
    <news:title>ShinyHunters trades financial extortion for a reckless war of ego with the FBI</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/truecaller-scam-checker-launches-in-india-how-it-works</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:41:28Z</news:publication_date>
    <news:title>Truecaller Scam Checker Launches in India: How It Works</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/autonomous-agents-attack-azure-using-compromised-identities-and-destroying-resources</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:22:22Z</news:publication_date>
    <news:title>Autonomous agents attack Azure using compromised identities and destroying resources</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bitget-backend-breach-drains-387-5-million-as-dprk-linked-launderers-expose-themselves</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:07:52Z</news:publication_date>
    <news:title>Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/weekly-recap-387m-crypto-hack-citrix-exploits-ai-agents-go-off-script-and-more-threats</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:00:53Z</news:publication_date>
    <news:title>⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/80000-organizations-had-ai-logins-stolen-from-shadow-ai-to-llmjacking</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T14:00:10Z</news:publication_date>
    <news:title>80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/28th-september-threat-intelligence-report-new-cyber-risk-reported-by-research-checkpoint-c</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T13:55:26Z</news:publication_date>
    <news:title>28th September – Threat Intelligence Report: new cyber risk reported by research.checkpoint.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/researchers-discover-cybercrime-server-containing-ai-tools-phishing-kits-and-stolen-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T13:22:17Z</news:publication_date>
    <news:title>Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-warns-of-microsoft-sharepoint-code-injection-vulnerability-exploited-in-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T13:21:22Z</news:publication_date>
    <news:title>CISA Warns of Microsoft SharePoint Code Injection Vulnerability Exploited in Attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/anthropic-declines-australian-ai-hearing-as-openai-agent-breach-faces-scrutiny</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T12:41:52Z</news:publication_date>
    <news:title>Anthropic Declines Australian AI Hearing as OpenAI Agent Breach Faces Scrutiny</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/other-users-can-watch-your-browsing-and-time-your-keystrokes-through-os-file-notifications</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T12:14:43Z</news:publication_date>
    <news:title>Other users can watch your browsing and time your keystrokes through OS file notifications</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/carbonato-botnet-compromises-docker-hosts-to-deploy-telegram-controlled-hermes-ai-agent</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T11:46:00Z</news:publication_date>
    <news:title>Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/vulnerability-summary-for-the-week-of-september-21-2026</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T11:32:46Z</news:publication_date>
    <news:title>Vulnerability Summary for the Week of September 21, 2026</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/drunk-ai-is-terrible-at-keeping-secrets-new-cyber-risk-reported-by-helpnetsecurity-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T11:30:22Z</news:publication_date>
    <news:title>“Drunk” AI is terrible at keeping secrets: new cyber risk reported by helpnetsecurity.com</news:title>
  </news:news>
</url>
</urlset>