<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
<url>
  <loc>https://hackwatch.io/alert/payload-ransomware-abuses-active-directory-group-policy-to-disrupt-entire-windows-domain</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T11:54:18Z</news:publication_date>
    <news:title>PAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-rapuncel-infostealer-abuses-microsoft-signed-driver-to-disable-145-security-tools</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T11:36:46Z</news:publication_date>
    <news:title>Hackers Use Microsoft-Signed Driver to Disable 145 Security Tools and Steal Passwords</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/claude-opus-5-helps-researchers-weaponize-heif-image-flaw-into-remote-code-execution</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T11:34:03Z</news:publication_date>
    <news:title>Claude Opus 5 Helps Researchers Weaponize HEIF Image Flaw Into Remote Code Execution</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/crowdsec-confirms-source-code-stolen-in-supply-chain-attack</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T10:55:46Z</news:publication_date>
    <news:title>CrowdSec Confirms Source Code Stolen in Supply Chain Attack</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/scammers-impersonate-cops-use-arrest-threats-to-extort-victims</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T10:53:24Z</news:publication_date>
    <news:title>Scammers impersonate cops, use arrest threats to extort victims</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/group-policy-hijacked-payload-ransomware-weaponizes-active-directory-gpo</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T10:00:40Z</news:publication_date>
    <news:title>Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/organizations-warned-of-3-exploited-linux-kernel-vulnerabilities</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T09:31:12Z</news:publication_date>
    <news:title>Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/msnightmare-has-released-a-windows-defender-update-dos-vulnerability-called-bigdiskbuster</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T09:12:39Z</news:publication_date>
    <news:title>BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-abuse-microsoft-teams-to-pose-as-it-support-and-steal-employee-passwords</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T09:09:24Z</news:publication_date>
    <news:title>Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/revoking-the-token-didnt-kill-the-backdoor-new-cyber-risk-reported-by-csoonline-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T09:00:00Z</news:publication_date>
    <news:title>Revoking the token didn’t kill the backdoor: new cyber risk reported by csoonline.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/revolut-customers-targeted-with-new-wave-of-phishing-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T09:00:00Z</news:publication_date>
    <news:title>Revolut Customers Targeted with New Wave of Phishing Attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/more-cves-than-ever-the-same-old-ones-keep-getting-exploited</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T09:00:00Z</news:publication_date>
    <news:title>More CVEs than ever. The same old ones keep getting exploited</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-weaponize-terraform-lock-files-to-infect-devops-engineers-with-macos-backdoors</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T08:53:58Z</news:publication_date>
    <news:title>Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/clickfix-lures-deploy-chainscript-rat-using-polygon-to-rotate-c2-infrastructure</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T08:39:38Z</news:publication_date>
    <news:title>ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/heif-heist-image-flaws-let-attackers-gain-rce-across-meta-slack-and-github-enterprise</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T08:17:05Z</news:publication_date>
    <news:title>HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/openai-codex-sandbox-flaws-let-malicious-repositories-execute-commands-on-host-systems</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T08:08:23Z</news:publication_date>
    <news:title>OpenAI Codex Sandbox Flaws Let Malicious Repositories Execute Commands on Host Systems</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/top-10-best-identity-governance-administration-iga-tools-in-2026</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T08:07:16Z</news:publication_date>
    <news:title>Top 10 Best Identity Governance &amp; Administration (IGA) Tools in 2026</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-hide-xmrig-miner-in-windows-registry-png-and-wav-files-to-evade-detection</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T07:52:49Z</news:publication_date>
    <news:title>Hackers Hide XMRig Miner in Windows Registry, PNG and WAV Files to Evade Detection</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/google-confirms-gemini-ai-breached-three-firms</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T07:20:46Z</news:publication_date>
    <news:title>Google Confirms Gemini AI Breached Three Firms</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-remus-infostealer-steals-openai-and-anthropic-api-tokens-passwords-and-crypto-wallets</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T07:19:52Z</news:publication_date>
    <news:title>Remus Infostealer Removes Syscall Hooks to Evade EDR and Steal Sensitive Credentials</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/exim-mail-server-hit-by-4-security-flaws-enabling-smtp-smuggling-and-heap-corruption</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T06:48:53Z</news:publication_date>
    <news:title>Exim Mail Server 4.100.1 Fixes 4 Security Flaws Including SMTP Smuggling and Heap Corruption</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/etherhiding-malware-abuses-polygon-blockchain-to-hide-c2-and-steal-banking-credentials</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T05:51:05Z</news:publication_date>
    <news:title>New Android Malware Uses AI to Steal Bank Logins and Reconstruct Your PIN</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-abuse-critical-cpanel-authentication-bypass-to-compromise-hosting-servers</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T05:06:37Z</news:publication_date>
    <news:title>Hackers Exploit cPanel CVE-2026-41940 Auth Bypass to Deploy Mirai Malware</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/gopass-open-source-command-line-password-manager-for-teams</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T05:00:32Z</news:publication_date>
    <news:title>Gopass: Open-source command-line password manager for teams</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/click2shell-wordpress-flaw-lets-hackers-execute-php-code-and-take-over-websites</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T04:54:06Z</news:publication_date>
    <news:title>Click2Shell WordPress Flaw Lets Hackers Execute PHP Code and Take Over Websites</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/weekly-cybersecurity-newsletter-bulletin-cisco-and-android-0-day-bragjack-attack-claude-op</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T02:32:05Z</news:publication_date>
    <news:title>Weekly Cybersecurity Newsletter Bulletin – Cisco and Android 0-Day, BragJack Attack, Claude Opus 5</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ransomware-group-alleges-attack-and-exfiltration-of-data-linked-to-major-payment-provider</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T02:01:23Z</news:publication_date>
    <news:title>Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/malicious-npm-packages-evade-install-script-defenses-at-runtime</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-20T14:11:21Z</news:publication_date>
    <news:title>Malicious npm packages evade install-script defenses at runtime</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/week-in-review-cisco-patches-exploited-email-gateway-0-day-revolut-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-20T08:00:21Z</news:publication_date>
    <news:title>Week in review: Cisco patches exploited email gateway 0-day, Revolut breach</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/when-ransomware-targets-ai-models-defending-the-ai-ml-recovery-chain</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-20T04:42:15Z</news:publication_date>
    <news:title>When Ransomware Targets AI Models: Defending the AI/ML Recovery Chain</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-warns-of-linux-kernel-vulnerabilities-actively-exploited-in-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-19T15:09:43Z</news:publication_date>
    <news:title>CISA Warns of Linux Kernel Vulnerabilities Actively Exploited in Attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/north-korean-waterplum-hackers-infected-30000-devices-worldwide</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-19T14:05:15Z</news:publication_date>
    <news:title>North Korean WaterPlum hackers infected 30,000 devices worldwide</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-19T13:48:32Z</news:publication_date>
    <news:title>ShinyHunters hacks Clop leak site, threatens to extort ransomware gang</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/identity-visibility-in-2026-the-foundation-of-identity-security</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-19T13:28:41Z</news:publication_date>
    <news:title>Identity Visibility in 2026: The Foundation of Identity Security</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/spear-phishing-how-the-attack-works-and-how-to-stop-it</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-19T13:24:59Z</news:publication_date>
    <news:title>Spear Phishing: How the attack works and how to stop it</news:title>
  </news:news>
</url>
</urlset>