<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
<url>
  <loc>https://hackwatch.io/alert/metas-muse-ai-assistant-rolled-out-with-a-serious-security-flaw</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T12:54:58Z</news:publication_date>
    <news:title>Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fake-crypto-wallet-app-spreads-pamstealer-malware-to-steal-mac-passwords</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T12:44:40Z</news:publication_date>
    <news:title>Fake Crypto Wallet App Spreads PamStealer Malware to Steal Mac Passwords</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/exvicy-clickfix-malware-as-a-service-copies-errtraffic-to-hijack-wordpress-sites</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T12:29:44Z</news:publication_date>
    <news:title>Exvicy ClickFix Malware-as-a-Service Copies ErrTraffic to Hijack WordPress Sites</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ransomware-attacks-reach-record-high-for-2026-new-cyber-risk-reported-by-infosecurity-maga</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T12:00:00Z</news:publication_date>
    <news:title>Ransomware Attacks Reach Record High for 2026: new cyber risk reported by infosecurity-magazine.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/adobe-patches-critical-flaws-in-connect-aem-forms</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T11:40:59Z</news:publication_date>
    <news:title>Adobe Patches Critical Flaws in Connect, AEM Forms</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cybercriminals-abandon-domains-but-keep-the-hosting-networks-behind-malware-campaigns</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T11:40:52Z</news:publication_date>
    <news:title>The Domains Keep Disappearing, but the Malware Infrastructure Behind Them Never Moves</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/exploit-released-for-unpatched-ubuntu-linux-flaw-enabling-host-root-container-escape</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T11:12:18Z</news:publication_date>
    <news:title>Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/the-malware-hiding-in-developer-tools-that-turned-terraform-providers-into-attack-paths</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T09:22:31Z</news:publication_date>
    <news:title>The Phishing Kit That Turned Microsoft’s Login Flow Into an AI-Powered Fraud Machine</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/wordpress-7-1-2-fixes-critical-unauthenticated-path-traversal-vulnerability-cve-2026-87902</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T09:01:45Z</news:publication_date>
    <news:title>WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/chatgpt-computer-history-feature-creates-new-data-theft-risk-for-macos-infostealers</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T08:52:18Z</news:publication_date>
    <news:title>ChatGPT Computer History Feature Creates New Data Theft Risk for macOS Infostealers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-disrupts-eviltokens-phishing-service-that-gave-criminals-access-to-12000-inboxes</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T08:34:15Z</news:publication_date>
    <news:title>Microsoft Warns of EvilTokens AI Phishing Service Hijacking Thousands of Accounts</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/arista-patches-actively-exploited-velocloud-orchestrator-zero-day</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T08:33:06Z</news:publication_date>
    <news:title>Arista patches actively exploited VeloCloud Orchestrator zero-day</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/chinese-hackers-exploit-chrome-windows-zero-day-chain-to-deploy-cleangulp-malware</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T08:29:24Z</news:publication_date>
    <news:title>Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ryuk-ransomware-member-sentenced-to-24-months-in-prison</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T08:20:05Z</news:publication_date>
    <news:title>Ryuk ransomware member sentenced to 24 months in prison</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-etuue-nch-ngohw-cve-2026-65660-ain-sharepoint-aacchnmaaaipsuukaarrankhmaasangbne</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T08:02:00Z</news:publication_date>
    <news:title>Microsoft เตือนช่องโหว่ CVE-2026-65660 ใน SharePoint อาจนำไปสู่การรันคำสั่งบนเซิร์ฟเวอร์</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-manageengine-flaw-lets-attackers-gain-system-access-through-windows-login-screen</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:53:01Z</news:publication_date>
    <news:title>ManageEngine RCE Flaw Enables SYSTEM Code Execution From Windows Login Screen</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/chrome-patches-108-vulnerabilities-including-crticial-flaws-that-enable-code-execution-att</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:46:37Z</news:publication_date>
    <news:title>Chrome 154 Patches 108 Vulnerabilities: new cyber risk reported by securityweek.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisco-talos-launches-cairn-tool-to-hunt-and-track-ai-integrated-malware</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:39:43Z</news:publication_date>
    <news:title>Cisco Talos Launches CAIRN Tool to Hunt and Track AI-Integrated Malware</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ai-powered-threats-exploit-digital-trust-through-autonomous-breach-techniques</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:31:46Z</news:publication_date>
    <news:title>AI-Driven Cyberattacks Enter New Phase With Autonomous Fraud and Digital Trust Abuse</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/this-malware-doesnt-wait-for-hackers-it-asks-ai-models-what-to-do-next</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:20:40Z</news:publication_date>
    <news:title>This Malware Doesn’t Wait for Hackers—It Asks AI Models What to Do Next</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/weekly-cybersecurity-newsletter-top-50-biggest-cybersecurity-stories-of-the-week</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:10:26Z</news:publication_date>
    <news:title>Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hpe-networking-analytics-engine-flaws-let-attackers-gain-root-access</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:05:59Z</news:publication_date>
    <news:title>SolarWinds Observability Flaws Let Unauthenticated Attackers Execute Remote Code</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fake-tv-streaming-ads-deliver-streamrat-malware-for-remote-android-device-hijacking</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T06:47:11Z</news:publication_date>
    <news:title>A Fake Streaming App Turned Android Phones Into Remote-Controlled Devices</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/prismor-open-source-runtime-control-plane-for-ai-agents</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T05:30:31Z</news:publication_date>
    <news:title>Prismor: Open-source runtime control plane for AI agents</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/product-showcase-scamwise-checks-the-red-flags-before-you-take-the-bait</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T05:00:48Z</news:publication_date>
    <news:title>Product showcase: Scamwise checks the red flags before you take the bait</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-exploiting-f5-big-ip-oauth-server-0-day-flaw-to-gain-remote-code-execution</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T03:24:27Z</news:publication_date>
    <news:title>Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ai-malware-just-removed-the-human-from-the-attack-loop</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T00:39:51Z</news:publication_date>
    <news:title>AI malware just removed the human from the attack loop</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bigcommerce-merchants-impacted-by-third-party-app-data-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T23:24:58Z</news:publication_date>
    <news:title>BigCommerce merchants impacted by third-party app data breach</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-exvicy-malware-as-a-service-framework-copies-rival-s-code</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T22:57:39Z</news:publication_date>
    <news:title>New Exvicy malware-as-a-service framework copies rival&apos;s code</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/task-stomp-campaign-uses-powershell-backdoor-for-data-theft</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T22:52:39Z</news:publication_date>
    <news:title>Stealthy WordPress Malware Uses Must-Use Plugin and Ethereum EtherHiding for Persistent Backdoor A</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T20:35:24Z</news:publication_date>
    <news:title>Chinese hackers exploit WordPress, Zyxel flaws to steal govt data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T19:13:29Z</news:publication_date>
    <news:title>ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/volexity-spots-another-china-aligned-threat-group-exploiting-chrome-and-microsoft-defects</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T18:47:07Z</news:publication_date>
    <news:title>Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-adds-four-known-exploited-vulnerabilities-to-catalog</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T18:44:46Z</news:publication_date>
    <news:title>CISA Adds Four Known Exploited Vulnerabilities to Catalog</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-closedquorum-windows-malware-uses-ai-for-attack-decisions</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T18:04:39Z</news:publication_date>
    <news:title>New ClosedQuorum Windows malware uses AI for attack decisions</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/malicious-npm-package-poses-as-twilio-bug-bounty-probe-can-exfiltrate-credentials</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T17:58:15Z</news:publication_date>
    <news:title>Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bigcommerce-data-stolen-via-ribon-apps-hack-new-cyber-risk-reported-by-securityweek-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T17:58:00Z</news:publication_date>
    <news:title>BigCommerce Data Stolen via Ribon Apps Hack: new cyber risk reported by securityweek.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/shai-hulud-attack-nips-cyber-firm-crowdsec-s-github-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T17:32:49Z</news:publication_date>
    <news:title>Shai-Hulud Attack Nips Cyber-Firm CrowdSec&apos;s GitHub Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/rathat-android-malware-uses-ai-to-target-banking-credentials-in-real-time</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T17:02:05Z</news:publication_date>
    <news:title>RatHat Android Malware Uses AI to Target Banking Credentials in Real Time</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/gemini-ai-autonomously-hacked-3-companies-google-confirms</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T17:00:00Z</news:publication_date>
    <news:title>Gemini AI Autonomously Hacked 3 Companies, Google Confirms</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/scaling-soc-capabilities-how-threat-intelligence-cuts-triage-time-and-burnout</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T16:46:05Z</news:publication_date>
    <news:title>Scaling SOC Capabilities: How Threat Intelligence Cuts Triage Time and Burnout</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-bifrost-ai-gateway-flaw-lets-attackers-run-commands-without-credentials</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T16:41:12Z</news:publication_date>
    <news:title>Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/attackers-hit-check-point-management-servers-and-spark-firewalls-f5-big-ip-apm-instances</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T16:32:47Z</news:publication_date>
    <news:title>Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/researcher-drops-bigdiskbuster-zero-day-poc-that-blocks-microsoft-defender-updates</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T16:14:04Z</news:publication_date>
    <news:title>Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/moviereaper-malware-uses-the-odyssey-torrents-to-infect-users-worldwide</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T15:44:09Z</news:publication_date>
    <news:title>MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ferramentas-de-acesso-remoto-porta-de-entrada-para-ataques</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T15:42:55Z</news:publication_date>
    <news:title>Ferramentas de acesso remoto: porta de entrada para ataques</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cairn-a-new-tool-to-track-ai-malware-that-operates-without-human-control</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T15:27:12Z</news:publication_date>
    <news:title>CAIRN – A New Tool to Track AI Malware That Operates Without Human Control</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-and-partners-disrupt-eviltokens-a-comprehensive-cybercrime-service-for-financial</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T15:00:00Z</news:publication_date>
    <news:title>Microsoft Disrupts EvilTokens Device Code Phishing Service</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T15:00:00Z</news:publication_date>
    <news:title>Unmasking EvilTokens: Getting to the root of device code phishing</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload-risk</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T14:56:08Z</news:publication_date>
    <news:title>Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/payload-il-ransomware-che-trasforma-active-directory-in-strumento-dattacco</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T14:15:36Z</news:publication_date>
    <news:title>PAYLOAD, il ransomware che trasforma Active Directory in strumento d’attacco</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/autonomous-ai-agents-hack-retailers-for-25-and-steal-600000-credit-cards</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T14:00:00Z</news:publication_date>
    <news:title>Autonomous AI Agents Hack Retailers for $25 and Steal 600,000 Credit Cards</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/researchers-uncover-malware-that-uses-ai-to-choose-its-next-move</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T13:56:55Z</news:publication_date>
    <news:title>Researchers uncover malware that uses AI to choose its next move</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/nightmare-eclipse-drops-new-microsoft-defender-exploit-after-revealing-identity</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T13:26:51Z</news:publication_date>
    <news:title>Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/webinar-tomorrow-inside-real-world-google-workspace-breaches</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T12:57:07Z</news:publication_date>
    <news:title>Webinar tomorrow: Inside real-world Google Workspace breaches</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T12:48:06Z</news:publication_date>
    <news:title>D-Link warns of max severity zero-day bug in DIR-822A routers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/amazon-blocks-metas-muse-ai-agent-from-shopping-on-amazon-com-over-bot-access</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T12:08:57Z</news:publication_date>
    <news:title>Amazon Blocks Meta’s Muse AI Agent From Shopping on Amazon.com Over Bot Access</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/the-latest-deepfake-numbers-give-cisos-plenty-to-worry-about</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T12:05:36Z</news:publication_date>
    <news:title>The latest deepfake numbers give CISOs plenty to worry about</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/the-next-intellectual-property-thief-may-sound-like-your-ceo</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T12:00:05Z</news:publication_date>
    <news:title>The next intellectual property thief may sound like your CEO</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/recent-zyxel-switch-vulnerability-exploited-by-chinese-hackers</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T11:55:20Z</news:publication_date>
    <news:title>Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-linux-kernel-flaw-gives-arm64-kvm-guests-read-write-access-to-host-memory</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T11:38:40Z</news:publication_date>
    <news:title>New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-cvss-10-0-velocloud-orchestrator-flaw-actively-exploited-in-certificate-based-setups</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T11:22:39Z</news:publication_date>
    <news:title>New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/sharepoint-flaw-initially-listed-as-spoofing-by-microsoft-enables-authenticated-rce</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T11:17:41Z</news:publication_date>
    <news:title>SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bambootoken-linux-backdoor-uses-mqtt-c2-to-execute-shell-commands-and-exfiltrate-files</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T11:17:04Z</news:publication_date>
    <news:title>New TASK#STOMP Backdoor Uses PowerShell to Steal Documents and Wi-Fi Passwords</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/linux-kvm-arm64-vulnerability-lets-attackers-escape-virtual-machines-and-gain-host-access</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T11:10:07Z</news:publication_date>
    <news:title>Linux KVM/arm64 Vulnerability Lets Attackers Escape Virtual Machines and Gain Host Access</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/attacker-compromised-nearly-1000-zyxel-switches-since-august-cve-2026-7273</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T10:42:54Z</news:publication_date>
    <news:title>Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/wordpress-patches-click2shell-vulnerability-new-cyber-risk-reported-by-securityweek-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T10:22:27Z</news:publication_date>
    <news:title>WordPress Patches ‘Click2Shell’ Vulnerability: new cyber risk reported by securityweek.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/introducing-cairn-frontier-tracking-for-ai-integrated-malware</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T10:00:25Z</news:publication_date>
    <news:title>Introducing CAIRN: Frontier tracking for AI-integrated malware</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/a-new-tool-found-malware-thats-guided-by-an-ai-hive-mind-no-humans-in-sight</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T10:00:00Z</news:publication_date>
    <news:title>A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T09:55:11Z</news:publication_date>
    <news:title>New Windows Defender zero-day blocks Microsoft antivirus updates</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/windows-com-flaw-lets-attackers-gain-system-privileges-with-a-malicious-dll</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T09:45:30Z</news:publication_date>
    <news:title>Critical MaxKB AI Agent Flaw Lets Prompt Injection Execute System Commands</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-abuse-stolen-bigcommerce-app-key-to-steal-master-of-malt-customer-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T09:11:59Z</news:publication_date>
    <news:title>Hackers Abuse Stolen BigCommerce App Key to Steal Master of Malt Customer Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/chinese-apt-clones-legitimate-websites-to-deliver-chrome-and-windows-zero-day-exploits</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T09:01:14Z</news:publication_date>
    <news:title>Hackers Clone Legitimate Websites to Silently Trigger Chrome and Windows Zero-Day Exploits</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/the-cyber-ai-parity-window-now-has-a-deadline-new-cyber-risk-reported-by-csoonline-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T09:00:00Z</news:publication_date>
    <news:title>The cyber AI parity window now has a deadline: new cyber risk reported by csoonline.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/looking-for-free-robux-heres-whats-real-and-whats-a-scam</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T09:00:00Z</news:publication_date>
    <news:title>Looking for free Robux? Here’s what’s real, and what’s a scam</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/d-link-router-hit-by-cvss-10-0-flaw-exploitable-remotely-without-authentication</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T08:58:31Z</news:publication_date>
    <news:title>D-Link Router Hit by CVSS 10.0 Flaw Exploitable Remotely Without Authentication</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/scammers-use-genuine-google-sign-ins-to-sell-costly-unverified-ai-subscriptions</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T08:54:30Z</news:publication_date>
    <news:title>Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/vidar-malware-rewrites-its-obfuscation-with-every-build-to-make-detection-harder</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T08:40:13Z</news:publication_date>
    <news:title>Vidar Malware Rewrites Its Obfuscation With Every Build to Make Detection Harder</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/top-10-best-identity-threat-detection-response-itdr-tools-in-2026-ranked-scored</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T07:59:29Z</news:publication_date>
    <news:title>Top 10 Best Customer Identity &amp; Access Management (CIAM) Solutions in 2026 [Ranked &amp; Scored]</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/sidecopy-broadens-india-targeting-to-academia-with-reverserat-spear-phishing</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T07:52:03Z</news:publication_date>
    <news:title>SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-warns-of-zyxel-gs1900-switches-flaw-actively-exploited-in-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T07:42:44Z</news:publication_date>
    <news:title>CISA orders feds to patch Zyxel flaw exploited for data theft</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/zte-smartlife-flaws-let-attackers-hijack-accounts-by-resetting-passwords-without-verificat</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T07:39:59Z</news:publication_date>
    <news:title>ZTE SmartLife Flaws Let Attackers Hijack Accounts by Resetting Passwords Without Verification</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-exploit-wordpress-cve-2026-63030-and-cve-2026-60137-to-steal-government-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T06:40:37Z</news:publication_date>
    <news:title>Hackers Exploit WordPress Flaws to Steal 18,566 Government Records and Plaintext Passwords</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-to-disable-sms-as-primary-entra-id-sign-in-method-in-2027</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T06:31:19Z</news:publication_date>
    <news:title>Microsoft to Disable SMS as Primary Entra ID Sign-In Method in 2027</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/wordpress-comment2shell-flaw-can-turn-anonymous-comment-xss-into-rce-via-admin-session</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T06:03:14Z</news:publication_date>
    <news:title>WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/vidar-uses-custom-bytecode-interpreter-and-arx-stream-ciphers-for-per-build-string-obfusca</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T05:46:53Z</news:publication_date>
    <news:title>Linux BambooToken Malware Uses MQTT C2 for Remote Shell Access and File Exfiltration</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/zyxel-and-veeam-flaws-under-active-exploitation-with-command-and-system-access</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T05:31:59Z</news:publication_date>
    <news:title>Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-impersonate-it-help-desk-on-microsoft-teams-to-steal-windows-passwords</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T04:46:11Z</news:publication_date>
    <news:title>Hackers Impersonate IT Help Desk on Microsoft Teams to Steal Windows Passwords</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cybersecurity-jobs-available-right-now-september-22-2026</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T04:00:23Z</news:publication_date>
    <news:title>Cybersecurity jobs available right now: September 22, 2026</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/metas-muse-ai-agent-0-day-vulnerability-allows-attackers-to-hijack-the-tool-and-inject-mal</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T03:13:18Z</news:publication_date>
    <news:title>One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/more-budget-more-breaches-the-roi-problem-asia-pacific-can-no-longer-ignore</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T01:00:00Z</news:publication_date>
    <news:title>More budget, more breaches: The ROI problem Asia Pacific can no longer ignore</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/transparent-tribe-targets-india-afghanistan-with-new-malware-in-operation-rapidrust</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T23:40:34Z</news:publication_date>
    <news:title>Transparent Tribe targets India, Afghanistan with new malware in Operation RapidRust</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/shinyhunters-defaces-clop-ransomware-data-leak-site-claims-data-theft</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T23:35:34Z</news:publication_date>
    <news:title>ShinyHunters เจาะและเปลี่ยนหน้า Leak Site ของ Clop Ransomware บน Dark Web</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/google-had-undercover-analyst-inside-teampcp-hacking-group</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T23:25:34Z</news:publication_date>
    <news:title>Google had undercover analyst inside TeamPCP hacking group</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/21st-september-threat-intelligence-report-new-cyber-risk-reported-by-research-checkpoint-c</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T23:13:07Z</news:publication_date>
    <news:title>21st September – Threat Intelligence Report: new cyber risk reported by research.checkpoint.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/openplc-runtime-v3-new-cyber-risk-reported-by-cisa-gov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T23:04:43Z</news:publication_date>
    <news:title>OpenPLC Runtime v3: new cyber risk reported by cisa.gov</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/lwip-lightweight-ip-new-cyber-risk-reported-by-cisa-gov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T22:17:11Z</news:publication_date>
    <news:title>lwIP (Lightweight IP): new cyber risk reported by cisa.gov</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T21:18:49Z</news:publication_date>
    <news:title>BigCommerce alerts merchants of data breach linked to Ribon apps</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-alerts-of-active-exploitation-of-three-linux-kernel-flaws</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T20:12:17Z</news:publication_date>
    <news:title>CISA adds Linux kernel flaws to exploited vulnerabilities catalog</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T18:23:11Z</news:publication_date>
    <news:title>WordPress Click2Shell flaw lets hackers execute PHP on the server</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-adds-one-known-exploited-vulnerability-to-catalog-2</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T18:11:39Z</news:publication_date>
    <news:title>CISA Adds One Known Exploited Vulnerability to Catalog</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/windows-exploitation-techniques-dangling-com-object-registrations</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T17:42:43Z</news:publication_date>
    <news:title>Windows Exploitation Techniques: Dangling COM Object Registrations</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/iran-linked-handala-hack-group-utilizes-heavygram-and-crudeexclude-malware</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T17:37:43Z</news:publication_date>
    <news:title>Iran-linked Handala Hack group utilizes HEAVYGRAM and CRUDEEXCLUDE malware</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/phantomraven-malware-distributed-via-npm-package-registry</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T17:32:43Z</news:publication_date>
    <news:title>PhantomRaven malware distributed via npm package registry</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/google-fined-eur403-million-for-gdpr-violations-over-users-location-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T17:19:53Z</news:publication_date>
    <news:title>Google Fined €403 Million for GDPR Violations Over Location Data Processing</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/after-spending-billions-openai-still-has-gaps-in-its-cybersecurity</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T16:24:03Z</news:publication_date>
    <news:title>After spending billions, OpenAI still has gaps in its cybersecurity</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-compromise-65-github-repositories-and-poison-npm-package-with-hidden-backdoor</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T16:19:59Z</news:publication_date>
    <news:title>GHAPPIER Supply Chain Attack Compromises 65 GitHub Repositories and Poisons npm Package</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fake-lastpass-installers-push-kernel-level-edr-killer-rapuncel-stealer</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T15:46:58Z</news:publication_date>
    <news:title>Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-npm-malware-finds-a-way-around-install-script-defenses</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T14:27:49Z</news:publication_date>
    <news:title>New npm malware finds a way around install script defenses</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/weekly-recap-cisco-0-day-ai-agent-rce-clickfix-attacks-clickfix-surge-and-browser-hijacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T14:24:13Z</news:publication_date>
    <news:title>⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-investigating-teams-calling-issue-blocking-users-from-making-or-receiving-calls</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T14:18:59Z</news:publication_date>
    <news:title>Microsoft Investigating Teams Calling Issue Blocking Users From Making or Receiving Calls</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/the-task-stomp-windows-backdoor-takes-wi-fi-passwords-screenshots-and-business-files</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-21T14:00:18Z</news:publication_date>
    <news:title>The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files</news:title>
  </news:news>
</url>
</urlset>