<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
<url>
  <loc>https://hackwatch.io/alert/microsoft-entra-trustsink-attack-uses-rogue-mfa-provider-to-steal-passwords</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T09:33:31Z</news:publication_date>
    <news:title>Microsoft Entra TrustSink Attack Uses Rogue MFA Provider to Steal Passwords</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/lumma-redline-and-vidar-infostealers-fuel-cloud-credential-theft-campaigns</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T09:12:23Z</news:publication_date>
    <news:title>Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/your-attack-surface-is-bigger-than-you-think-and-hackers-know-that</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T09:00:00Z</news:publication_date>
    <news:title>Your attack surface is bigger than you think… and hackers know that</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/python-maas-infostealer-builder-steals-passwords-credit-cards-and-cookies-from-17-browsers</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T08:41:03Z</news:publication_date>
    <news:title>Python MaaS Infostealer Builder Steals Passwords, Credit Cards and Cookies From 17 Browsers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/operation-master-exploits-globalprotect-cve-2026-0257-and-deploys-adaptixc2-across-enterpr</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T08:33:08Z</news:publication_date>
    <news:title>Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Netw</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/citrix-patches-critical-zero-days-under-active-exploitation</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T08:30:00Z</news:publication_date>
    <news:title>Citrix Patches Critical Zero Days Under Active Exploitation</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/stolen-ai-credentials-feed-growing-llm-proxy-economy</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T08:25:00Z</news:publication_date>
    <news:title>Stolen AI credentials feed growing LLM proxy economy</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/top-10-best-adaptive-risk-based-authentication-tools-in-2026-ranked-scored</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T07:02:08Z</news:publication_date>
    <news:title>Top 10 Best Authentication-as-a-Service (AaaS) Providers in 2026 [Ranked &amp; Scored]</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-turn-an-open-source-ai-agent-into-a-tool-for-controlling-compromised-docker-server</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T06:57:50Z</news:publication_date>
    <news:title>Hackers Turn an Open-Source AI Agent Into a Tool for Controlling Compromised Docker Servers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/if-you-do-one-security-check-this-quarter-make-it-agent-memory</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T06:00:40Z</news:publication_date>
    <news:title>If you do one security check this quarter, make it agent memory</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/16-year-old-researcher-discovers-microsoft-authentication-bug-exposing-17-3-trillion-recor</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T05:36:42Z</news:publication_date>
    <news:title>16-Year-Old Researcher Discovers Microsoft Authentication Bug Exposing 17.3 Trillion Records</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/macsyncs-new-infection-chain-shows-how-mac-malware-is-becoming-more-sophisticated</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-28T05:12:21Z</news:publication_date>
    <news:title>MacSync’s New Infection Chain Shows How Mac Malware Is Becoming More Sophisticated</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-adds-two-known-exploited-vulnerabilities-to-catalog-2</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T18:04:39Z</news:publication_date>
    <news:title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/citrix-confirms-netscaler-0-day-rce-vulnerabilities-actively-exploited-in-attack</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T17:56:38Z</news:publication_date>
    <news:title>Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T16:02:37Z</news:publication_date>
    <news:title>Kiteworks Urges Customers to Shut Down Servers Over Potential Zero-Day Threat</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/sicherheitsforscher-warnen-neue-zero-day-exploits-in-citrix-netscaler</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T11:47:35Z</news:publication_date>
    <news:title>Sicherheitsforscher warnen: Neue Zero-Day-Exploits in Citrix Netscaler?</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-sharepoint-flaw-cve-2026-65660-now-exploited-in-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T09:23:09Z</news:publication_date>
    <news:title>Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/week-in-review-gyazo-breach-exposes-23-6m-user-data-task-stomp-steals-documents</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T08:00:49Z</news:publication_date>
    <news:title>Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/which-platforms-to-use-for-enterprise-threat-intelligence</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-27T03:59:32Z</news:publication_date>
    <news:title>Which Platforms to Use for Enterprise Threat Intelligence</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/lunex-stealer-abuses-amd-driver-to-disable-security-monitoring-and-steal-browser-credentia</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-26T18:22:52Z</news:publication_date>
    <news:title>Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/shinyhunters-bypass-waf-rules-to-resume-oracle-peoplesoft-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-26T13:36:11Z</news:publication_date>
    <news:title>ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/old-school-credit-card-scams-are-far-from-dead</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-26T12:00:00Z</news:publication_date>
    <news:title>Old-School Credit Card Scams Are Far From Dead</news:title>
  </news:news>
</url>
</urlset>