<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
<url>
  <loc>https://hackwatch.io/alert/staying-ahead-of-the-ransomware-industry-new-cyber-risk-reported-by-securitymagazine-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T16:00:00Z</news:publication_date>
    <news:title>Staying Ahead of the Ransomware Industry: new cyber risk reported by securitymagazine.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/why-ransomware-is-so-dangerous-for-healthcare-new-cyber-risk-reported-by-scmagazine-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T15:42:14Z</news:publication_date>
    <news:title>Why ransomware is so dangerous for healthcare: new cyber risk reported by scmagazine.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T15:35:08Z</news:publication_date>
    <news:title>Storm-3168: Agentic-driven cloud attacks using compromised service principals</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/how-to-prove-ransomware-recovery-works-clean-room-restoration-and-recovery-assurance</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T15:05:09Z</news:publication_date>
    <news:title>How to prove ransomware recovery works: clean-room restoration and recovery assurance</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-russian-infostealer-targeting-ukrainian-users</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T15:00:00Z</news:publication_date>
    <news:title>New Russian Infostealer Targeting Ukrainian Users</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T14:51:10Z</news:publication_date>
    <news:title>With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/stopping-it-worker-scams-requires-revamped-hr-process</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T14:46:13Z</news:publication_date>
    <news:title>Stopping IT Worker Scams Requires Revamped HR Process</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/researchers-found-a-botnet-that-uses-an-ai-agent-to-operate-inside-compromised-servers</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T14:17:54Z</news:publication_date>
    <news:title>Researchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/sauron-loader-malware-uses-dll-side-loading-and-in-memory-decryption-to-evade-detection</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T13:47:28Z</news:publication_date>
    <news:title>Kothamine malware uses Tailscale’s tailcat to evade network detection</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/zero-click-vulnerabilities-in-salesforce-agentforce-expose-wider-ai-agent-risk</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T13:30:00Z</news:publication_date>
    <news:title>Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/14-year-old-linux-kernel-vulnerability-enables-root-access-and-docker-escape</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T12:48:13Z</news:publication_date>
    <news:title>14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/google-chrome-154-fixes-108-security-flaws-11-are-rated-critical</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T12:30:09Z</news:publication_date>
    <news:title>Google Chrome 154 Fixes 108 Security Flaws: 11 Are Rated Critical</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-servicenow-vulnerabilities-let-attackers-bypass-authorization-update-now</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T12:18:09Z</news:publication_date>
    <news:title>Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization – Update Now!</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/attackers-are-turning-everyday-business-emails-into-malware-delivery-machines</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T12:01:17Z</news:publication_date>
    <news:title>Attackers Are Turning Everyday Business Emails Into Malware Delivery Machines</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T11:35:14Z</news:publication_date>
    <news:title>Rydox marketplace admin pleads guilty, faces 22 years in prison</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/on-anthropics-ai-misuse-report-new-cyber-risk-reported-by-schneier-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T11:07:22Z</news:publication_date>
    <news:title>On Anthropic’s AI Misuse Report: new cyber risk reported by schneier.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/party-invite-phishing-scams-are-the-new-missed-connections</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T11:00:00Z</news:publication_date>
    <news:title>Party Invite Phishing Scams Are the New Missed Connections</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/servicenow-security-flaws-allow-attackers-to-execute-sql-and-modify-instance-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T10:58:04Z</news:publication_date>
    <news:title>ServiceNow Security Flaws Allow Attackers to Execute SQL and Modify Instance Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bitget-says-suspected-north-korean-hackers-stole-351-6m-after-backend-compromise</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T10:35:55Z</news:publication_date>
    <news:title>Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-flags-wso2-security-flaw-under-active-exploitation</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T10:14:50Z</news:publication_date>
    <news:title>CISA Flags WSO2 Security Flaw Under Active Exploitation</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/roundcube-pre-auth-sql-injection-flaw-actively-exploited-in-the-wild</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T10:14:02Z</news:publication_date>
    <news:title>Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-finds-ransomware-group-using-same-attack-blueprint-across-multiple-malware-famil</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T10:11:25Z</news:publication_date>
    <news:title>Microsoft Finds Ransomware Group Using Same Attack Blueprint Across Multiple Malware Families</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-password-reset-portal-could-reveal-users-and-mfa-protection-details</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T09:53:32Z</news:publication_date>
    <news:title>Microsoft Password Reset Portal Could Reveal Users and MFA Protection Details</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/wordpress-flaw-under-active-attack-hackers-target-cve-2026-87902-for-code-execution</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T09:51:07Z</news:publication_date>
    <news:title>WordPress Flaw Under Active Attack: Hackers Target CVE-2026-87902 for Code Execution</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/remcontrol-banking-trojan-gives-attackers-remote-control-of-android-devices</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T09:30:00Z</news:publication_date>
    <news:title>RemControl Banking Trojan Gives Attackers Remote Control of Android Devices</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/macsync-info-stealing-malware-hides-malicious-commands-in-an-icloud-calendar</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T09:22:45Z</news:publication_date>
    <news:title>MacSync info-stealing malware hides malicious commands in an iCloud calendar</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/researchers-identify-aliexpress-phishing-domains-before-registration</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T08:30:00Z</news:publication_date>
    <news:title>Researchers Identify AliExpress Phishing Domains Before Registration</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/salesforce-agentforce-flaw-enables-0-click-data-exfiltration-via-prompt-injection</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T07:47:45Z</news:publication_date>
    <news:title>Salesforce Indirect Prompt Injection Vulnerability Enables 0-click Data Exfiltration</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/sudo-vulnerability-lets-attackers-bypass-time-based-authorization-controls</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T07:26:40Z</news:publication_date>
    <news:title>Sudo Security Vulnerability Lets Attackers Escalate Privileges</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/roundcube-webmail-vulnerability-in-attackers-crosshairs</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T06:57:40Z</news:publication_date>
    <news:title>Roundcube Webmail Vulnerability in Attackers’ Crosshairs</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/duelbits-confirms-7-million-hot-wallet-hack-forcing-systems-offline</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T05:41:52Z</news:publication_date>
    <news:title>Duelbits Confirms $7 Million Hot-Wallet Hack, forcing Systems offline</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-exploited-ethereum-bridge-contract-to-drain-full-balance-from-payy-network</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T05:18:27Z</news:publication_date>
    <news:title>Hackers Exploited Ethereum Bridge Contract to Drain Full Balance from Payy Network</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bbc-technology-technology-health-environment-ai-3</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T05:17:35Z</news:publication_date>
    <news:title>BBC Technology | Technology, Health, Environment, AI</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/only-26-of-detected-cisa-known-exploited-vulnerabilities-were-fully-remediated</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T04:46:34Z</news:publication_date>
    <news:title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bitget-hot-wallet-hacked-attackers-stole-351-6-million-from-hot-wallets</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T03:34:38Z</news:publication_date>
    <news:title>Bitget Hot Wallet Hacked – Attackers Stole $351.6 Million From Hot Wallets</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cloudflare-containers-vulnerability-could-leak-data-between-customer-workloads</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T03:13:12Z</news:publication_date>
    <news:title>Cloudflare Containers Vulnerability Could Leak Data Between Customer Workloads</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/security-news-hkcert-new-cyber-risk-reported-by-hkcert-org-2</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T02:00:26Z</news:publication_date>
    <news:title>Security News | HKCERT: new cyber risk reported by hkcert.org</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-ransomware-group-n0n-escalates-threats-by-targeting-backups</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T00:22:44Z</news:publication_date>
    <news:title>New ransomware group n0n escalates threats by targeting backups</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/scammers-impersonating-police-and-government-officials-have-stolen-1-6-billion</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T23:50:26Z</news:publication_date>
    <news:title>Scammers impersonating police and government officials have stolen $1.6 billion</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/f5-patches-critical-zero-day-flaw-exploited-in-big-ip-apm</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T23:45:26Z</news:publication_date>
    <news:title>F5 patches critical zero-day flaw exploited in BIG-IP APM</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-windows-botnet-offers-ai-credit-draining-and-other-attack-methods</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T23:13:08Z</news:publication_date>
    <news:title>New Windows botnet offers AI credit draining and other attack methods</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/botnet-carbonato-ataca-docker-e-instala-agente-de-ia-hermes</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T23:01:30Z</news:publication_date>
    <news:title>Botnet Carbonato ataca Docker e instala agente de IA Hermes</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/sectoprat-returns-hiding-inside-a-legitimate-application</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T20:32:50Z</news:publication_date>
    <news:title>SectopRAT Returns, Hiding Inside a Legitimate Application</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/wordpress-patches-a-critical-severity-security-vulnerability</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T20:26:22Z</news:publication_date>
    <news:title>WordPress patches a critical severity security vulnerability</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-macsync-malware-turns-macos-apps-into-tools-for-crypto-and-password-theft</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T20:10:48Z</news:publication_date>
    <news:title>TWEAKOS Malware Turns Telegram Into a Stealer, C2 Platform and Stolen Account Marketplace</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/falha-no-wordpress-escala-para-comprometimentos-ativos</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T20:08:58Z</news:publication_date>
    <news:title>Falha no WordPress escala para comprometimentos ativos</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/i-think-i-found-an-ai-agent-worth-the-risk-new-cyber-risk-reported-by-wired-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T19:36:35Z</news:publication_date>
    <news:title>I Think I Found an AI Agent Worth the Risk: new cyber risk reported by wired.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-9-8-jetbrains-teamcity-rce-exploited-by-ransomware-says-cisa</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T19:25:35Z</news:publication_date>
    <news:title>Critical 9.8 JetBrains TeamCity RCE exploited by ransomware, says CISA</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cyber-recovery-plans-lag-behind-ai-ransomware-threats</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T18:20:56Z</news:publication_date>
    <news:title>Cyber recovery plans lag behind AI, ransomware threats</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-adds-two-known-exploited-vulnerabilities-to-catalog</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T18:16:27Z</news:publication_date>
    <news:title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/burger-king-russia-customer-data-leaked-online-after-2024-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T17:53:42Z</news:publication_date>
    <news:title>Burger King Russia customer data leaked online after 2024 breach</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/threatsday-ai-search-poisoning-ai-coding-tool-leaking-repos-one-click-code-execution-and-1</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T17:52:43Z</news:publication_date>
    <news:title>Zero-click flaw enables remote code execution in four mainstream AI coding agents: report</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/exposed-gitlab-project-email-addresses-let-attackers-push-code</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T17:47:44Z</news:publication_date>
    <news:title>Private GitLab email addresses exposed in public documentation</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-trustsink-attack-steals-passwords-via-rogue-mfa-provider</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T16:44:06Z</news:publication_date>
    <news:title>New TrustSink attack steals passwords via rogue MFA provider</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/beyond-the-ransomware-tracking-storm-2570s-consistent-tradecraft-across-deployments</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T16:00:00Z</news:publication_date>
    <news:title>Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/eufy-omni-c20-omni-x10-pro-new-cyber-risk-reported-by-cisa-gov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T15:16:09Z</news:publication_date>
    <news:title>Eufy Omni C20, Omni X10 Pro: new cyber risk reported by cisa.gov</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/wiz-uses-ai-to-find-vulnerabilities-in-railroads-hospitals-and-other-critical-infrastructu</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T15:11:00Z</news:publication_date>
    <news:title>Wiz uses AI to find vulnerabilities in railroads, hospitals and other critical infrastructure</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/emerging-ransomware-gang-uses-backup-destruction-threats-to-pressure-victims</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T15:00:00Z</news:publication_date>
    <news:title>Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/botslab-g980h-dashcams-new-cyber-risk-reported-by-cisa-gov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T14:45:03Z</news:publication_date>
    <news:title>Botslab G980H Dashcams: new cyber risk reported by cisa.gov</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/3-cyber-threats-that-defined-the-summer-of-2026</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T14:44:12Z</news:publication_date>
    <news:title>3 Cyber Threats That Defined the Summer of 2026</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bbc-technology-technology-health-environment-ai-2</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T14:43:45Z</news:publication_date>
    <news:title>BBC Technology | Technology, Health, Environment, AI</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/android-malware-gebruikt-vaker-vpn-voor-blokkeren-van-google-play-protect</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T14:15:00Z</news:publication_date>
    <news:title>&apos;Android-malware gebruikt vaker vpn voor blokkeren van Google Play Protect&apos;</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fake-pdf-files-hide-konni-malware-campaign-targeting-ukraine-organizations</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T13:39:18Z</news:publication_date>
    <news:title>Fake PDF Files Hide Konni Malware Campaign Targeting Ukraine Organizations</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/on-prem-velocloud-orchestrator-under-attack-only-some-versions-patched</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T13:35:04Z</news:publication_date>
    <news:title>On-prem VeloCloud Orchestrator under attack, only some versions patched</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fortiguard-labs-threat-research-new-cyber-risk-reported-by-fortinet-com-2</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T13:23:27Z</news:publication_date>
    <news:title>FortiGuard Labs Threat Research: new cyber risk reported by fortinet.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/verdachte-achter-ransomware-aanvallen-moet-12-miljoen-dollar-betalen</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T13:12:00Z</news:publication_date>
    <news:title>Verdachte achter ransomware-aanvallen moet 1,2 miljoen dollar betalen</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ai-powered-campaign-targets-hundreds-of-online-retailers</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T12:48:14Z</news:publication_date>
    <news:title>AI-Powered Campaign Targets Hundreds of Online Retailers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/secrets-sprawl-is-an-identity-problem-that-ai-just-made-impossible-to-ignore</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T11:00:00Z</news:publication_date>
    <news:title>Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T10:42:37Z</news:publication_date>
    <news:title>CISA: Ransomware gangs now exploiting critical TeamCity flaw</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/solarwinds-patches-critical-rce-flaws-in-observability-self-hosted</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T10:40:40Z</news:publication_date>
    <news:title>SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/how-tax-policy-can-stop-threat-actors-from-breaching-us-water-systems</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T10:00:00Z</news:publication_date>
    <news:title>How tax policy can stop threat actors from breaching US water systems</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/astrana-health-data-breach-impacts-private-confidential-information</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T09:56:04Z</news:publication_date>
    <news:title>Astrana Health Data Breach Impacts Private, Confidential Information</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/operation-conflict-compass-deploys-velvetcake-powershell-malware-through-malicious-lnk-fil</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T09:34:36Z</news:publication_date>
    <news:title>Operation Conflict Compass Deploys VelvetCake PowerShell Malware Through Malicious LNK Files</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/17000-urls-reveal-how-clickfix-turns-trusted-websites-into-malware-traps-report-by-ctm360</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T09:14:21Z</news:publication_date>
    <news:title>17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/aviation-solved-the-vigilance-problem-ai-just-gave-security-a-worse-one</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T09:00:00Z</news:publication_date>
    <news:title>Aviation solved the vigilance problem. AI just gave security a worse one</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/us-court-sentences-armenian-man-to-prison-for-ryuk-ransomware-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T08:38:29Z</news:publication_date>
    <news:title>US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-windows-malware-built-to-survive-takedowns-with-a-hidden-p2p-command-network</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T08:36:41Z</news:publication_date>
    <news:title>AvisLoader Windows Malware That Learned to Survive Even After Its Servers Are Taken Down</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/58-hardware-vulnerabilities-a-guide-to-the-threats</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T08:25:00Z</news:publication_date>
    <news:title>58 hardware vulnerabilities: A guide to the threats</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/gnome-50-5-security-fixes-patch-a-gvfs-cve-and-epiphany-code-injection</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T08:17:04Z</news:publication_date>
    <news:title>GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/apples-new-ios-27-feature-looks-for-signs-youre-being-scammed</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T08:02:31Z</news:publication_date>
    <news:title>Apple’s new iOS 27 feature looks for signs you’re being scammed</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/openai-agent-hacked-australian-government-medicare-portal-in-worlds-first-rogue-ai-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T08:01:49Z</news:publication_date>
    <news:title>OpenAI agent breached Medicare statistics site, then took months to report it</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/roundcube-webmail-sql-injection-vulnerability-exploited-in-the-wild</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T07:37:03Z</news:publication_date>
    <news:title>Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-wordpress-vulnerability-exploited-immediately-after-disclosure</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T07:12:26Z</news:publication_date>
    <news:title>Critical WordPress Vulnerability Exploited Immediately After Disclosure</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cpanel-permissions-flaw-allows-local-users-to-read-other-accounts-calendar-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T07:08:28Z</news:publication_date>
    <news:title>cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/druva-enhances-identity-resilience-with-ransomware-detection</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T06:13:24Z</news:publication_date>
    <news:title>Druva Enhances Identity Resilience with Ransomware Detection</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-galago-ransomware-operation-emerges-with-links-to-panzer-extortion-group</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T06:06:25Z</news:publication_date>
    <news:title>New Galago Ransomware Operation Emerges With Links to Panzer Group</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/attackers-exploit-wordpress-cve-2026-87902-within-hours-of-disclosure</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T05:36:18Z</news:publication_date>
    <news:title>Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fake-firefox-extension-hijacks-google-accounts-without-stealing-passwords-first</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T05:15:38Z</news:publication_date>
    <news:title>Fake Firefox Extension Hijacks Google Accounts Without Stealing Passwords First</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bbc-technology-technology-health-environment-ai</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T04:20:59Z</news:publication_date>
    <news:title>BBC Technology | Technology, Health, Environment, AI</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/apache-tomcat-update-fixes-websocket-and-http-2-flaws-affecting-server-security</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T04:04:20Z</news:publication_date>
    <news:title>Apache Tomcat Update Fixes WebSocket and HTTP/2 Flaws Affecting Server Security</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/europes-technology-backbone-is-becoming-a-cyber-target</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T04:00:02Z</news:publication_date>
    <news:title>Europe’s technology backbone is becoming a cyber target</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/check-point-hacked-the-security-software-protecting-your-network-has-become-a-prime-attack</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T02:05:30Z</news:publication_date>
    <news:title>Check Point hacked: The security software protecting your network has become a prime attack target</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ransomware-group-payload-weaponizes-microsoft-active-directory-for-disruption</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T00:07:27Z</news:publication_date>
    <news:title>Ransomware group PAYLOAD weaponizes Microsoft Active Directory for disruption</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/d-link-warns-of-critical-vulnerabilities-in-legacy-dir-822a-routers-with-public-exploit-co</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T00:02:26Z</news:publication_date>
    <news:title>D-Link warns of critical vulnerabilities in legacy DIR-822A routers with public exploit code</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/zte-smartlife-platform-vulnerabilities-allow-account-takeover</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T22:57:23Z</news:publication_date>
    <news:title>ZTE SmartLife platform vulnerabilities allow account takeover</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T21:25:13Z</news:publication_date>
    <news:title>New Android Banking Trojan Uses AI-Built Overlays to Steal Users’ Banking PINs</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/f5-fixes-actively-exploited-zero-day-flaw-in-big-ip-apm</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T20:44:25Z</news:publication_date>
    <news:title>F5 fixes actively exploited zero-day flaw in BIG-IP APM</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/how-device-code-phishing-gives-scammers-access-to-your-account</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T18:59:38Z</news:publication_date>
    <news:title>How device code phishing gives scammers access to your account</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-now-exploit-critical-roundcube-flaw-in-code-injection-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T18:31:22Z</news:publication_date>
    <news:title>Hackers now exploit critical Roundcube flaw in code injection attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fbi-probes-cyberattack-tied-to-third-party-jobs-portal</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T18:28:00Z</news:publication_date>
    <news:title>FBI probes cyberattack tied to third-party jobs portal</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/attackers-use-malicious-terraform-providers-to-deliver-go-malware-via-hashicorp-registry</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T18:06:30Z</news:publication_date>
    <news:title>Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry</news:title>
  </news:news>
</url>
</urlset>