<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
<url>
  <loc>https://hackwatch.io/alert/fortiguard-labs-threat-research-new-cyber-risk-reported-by-fortinet-com-2</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T13:23:27Z</news:publication_date>
    <news:title>FortiGuard Labs Threat Research: new cyber risk reported by fortinet.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ai-powered-campaign-targets-hundreds-of-online-retailers</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T12:48:14Z</news:publication_date>
    <news:title>AI-Powered Campaign Targets Hundreds of Online Retailers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/secrets-sprawl-is-an-identity-problem-that-ai-just-made-impossible-to-ignore</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T11:00:00Z</news:publication_date>
    <news:title>Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T10:42:37Z</news:publication_date>
    <news:title>CISA: Ransomware gangs now exploiting critical TeamCity flaw</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/solarwinds-patches-critical-rce-flaws-in-observability-self-hosted</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T10:40:40Z</news:publication_date>
    <news:title>SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/how-tax-policy-can-stop-threat-actors-from-breaching-us-water-systems</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T10:00:00Z</news:publication_date>
    <news:title>How tax policy can stop threat actors from breaching US water systems</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/astrana-health-data-breach-impacts-private-confidential-information</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T09:56:04Z</news:publication_date>
    <news:title>Astrana Health Data Breach Impacts Private, Confidential Information</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/operation-conflict-compass-deploys-velvetcake-powershell-malware-through-malicious-lnk-fil</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T09:34:36Z</news:publication_date>
    <news:title>Operation Conflict Compass Deploys VelvetCake PowerShell Malware Through Malicious LNK Files</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/17000-urls-reveal-how-clickfix-turns-trusted-websites-into-malware-traps-report-by-ctm360</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T09:14:21Z</news:publication_date>
    <news:title>17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/aviation-solved-the-vigilance-problem-ai-just-gave-security-a-worse-one</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T09:00:00Z</news:publication_date>
    <news:title>Aviation solved the vigilance problem. AI just gave security a worse one</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/us-court-sentences-armenian-man-to-prison-for-ryuk-ransomware-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T08:38:29Z</news:publication_date>
    <news:title>US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-windows-malware-built-to-survive-takedowns-with-a-hidden-p2p-command-network</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T08:36:41Z</news:publication_date>
    <news:title>AvisLoader Windows Malware That Learned to Survive Even After Its Servers Are Taken Down</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/58-hardware-vulnerabilities-a-guide-to-the-threats</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T08:25:00Z</news:publication_date>
    <news:title>58 hardware vulnerabilities: A guide to the threats</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/gnome-50-5-security-fixes-patch-a-gvfs-cve-and-epiphany-code-injection</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T08:17:04Z</news:publication_date>
    <news:title>GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/apples-new-ios-27-feature-looks-for-signs-youre-being-scammed</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T08:02:31Z</news:publication_date>
    <news:title>Apple’s new iOS 27 feature looks for signs you’re being scammed</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/openai-agent-hacked-australian-government-medicare-portal-in-worlds-first-rogue-ai-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T08:01:49Z</news:publication_date>
    <news:title>OpenAI Agent Hacked Australian Government Medicare Portal in World’s First Rogue AI Breach</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/roundcube-webmail-sql-injection-vulnerability-exploited-in-the-wild</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T07:37:03Z</news:publication_date>
    <news:title>Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-wordpress-vulnerability-exploited-immediately-after-disclosure</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T07:12:26Z</news:publication_date>
    <news:title>Critical WordPress Vulnerability Exploited Immediately After Disclosure</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cpanel-permissions-flaw-allows-local-users-to-read-other-accounts-calendar-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T07:08:28Z</news:publication_date>
    <news:title>cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-galago-ransomware-operation-emerges-with-links-to-panzer-extortion-group</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T06:06:25Z</news:publication_date>
    <news:title>New Galago Ransomware Operation Emerges With Links to Panzer Group</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/attackers-exploit-wordpress-cve-2026-87902-within-hours-of-disclosure</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T05:36:18Z</news:publication_date>
    <news:title>Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fake-firefox-extension-hijacks-google-accounts-without-stealing-passwords-first</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T05:15:38Z</news:publication_date>
    <news:title>Fake Firefox Extension Hijacks Google Accounts Without Stealing Passwords First</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bbc-technology-technology-health-environment-ai</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T04:20:59Z</news:publication_date>
    <news:title>BBC Technology | Technology, Health, Environment, AI</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/apache-tomcat-update-fixes-websocket-and-http-2-flaws-affecting-server-security</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T04:04:20Z</news:publication_date>
    <news:title>Apache Tomcat Update Fixes WebSocket and HTTP/2 Flaws Affecting Server Security</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/europes-technology-backbone-is-becoming-a-cyber-target</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T04:00:02Z</news:publication_date>
    <news:title>Europe’s technology backbone is becoming a cyber target</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/check-point-hacked-the-security-software-protecting-your-network-has-become-a-prime-attack</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T02:05:30Z</news:publication_date>
    <news:title>Check Point hacked: The security software protecting your network has become a prime attack target</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ransomware-group-payload-weaponizes-microsoft-active-directory-for-disruption</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T00:07:27Z</news:publication_date>
    <news:title>Ransomware group PAYLOAD weaponizes Microsoft Active Directory for disruption</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/d-link-warns-of-critical-vulnerabilities-in-legacy-dir-822a-routers-with-public-exploit-co</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T00:02:26Z</news:publication_date>
    <news:title>D-Link warns of critical vulnerabilities in legacy DIR-822A routers with public exploit code</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/zte-smartlife-platform-vulnerabilities-allow-account-takeover</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T22:57:23Z</news:publication_date>
    <news:title>ZTE SmartLife platform vulnerabilities allow account takeover</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T21:25:13Z</news:publication_date>
    <news:title>New Android Banking Trojan Uses AI-Built Overlays to Steal Users’ Banking PINs</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/f5-fixes-actively-exploited-zero-day-flaw-in-big-ip-apm</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T20:44:25Z</news:publication_date>
    <news:title>F5 fixes actively exploited zero-day flaw in BIG-IP APM</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/how-device-code-phishing-gives-scammers-access-to-your-account</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T18:59:38Z</news:publication_date>
    <news:title>How device code phishing gives scammers access to your account</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-now-exploit-critical-roundcube-flaw-in-code-injection-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T18:31:22Z</news:publication_date>
    <news:title>Hackers now exploit critical Roundcube flaw in code injection attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fbi-probes-cyberattack-tied-to-third-party-jobs-portal</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T18:28:00Z</news:publication_date>
    <news:title>FBI probes cyberattack tied to third-party jobs portal</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/attackers-use-malicious-terraform-providers-to-deliver-go-malware-via-hashicorp-registry</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T18:06:30Z</news:publication_date>
    <news:title>Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/open-source-ai-agents-breach-27-companies-steal-600000-credit-card-records</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T17:19:17Z</news:publication_date>
    <news:title>Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/mikrotrick-chain-let-attackers-take-over-mikrotik-routers-without-a-password-or-ssh-key</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T16:06:41Z</news:publication_date>
    <news:title>MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/email-makes-up-nearly-1-in-3-mssp-analyses-how-tier-1-can-triage-phishing-faster</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T15:58:30Z</news:publication_date>
    <news:title>Email Makes Up Nearly 1 in 3 MSSP Analyses: How Tier 1 Can Triage Phishing Faster</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/gitlab-email-feature-vulnerability-lets-attackers-push-code-into-private-repositories</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T15:40:39Z</news:publication_date>
    <news:title>A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/the-visibility-gap-in-phishing-detection-where-sandboxing-makes-a-difference</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T15:40:01Z</news:publication_date>
    <news:title>The Visibility Gap in Phishing Detection: Where Sandboxing Makes a Difference</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-cpanel-vulnerability-allows-attackers-to-access-other-users-accounts</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T15:18:34Z</news:publication_date>
    <news:title>New Cpanel Vulnerability Allows Attackers to Access Other Users’ Accounts</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hundreds-of-leaked-github-app-keys-still-authenticate</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T15:00:00Z</news:publication_date>
    <news:title>GitHub App keys can still enable takeovers long after they are forgotten</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/infratrust-report-warns-network-management-systems-under-attack</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T14:35:26Z</news:publication_date>
    <news:title>InfraTrust report warns network management systems under attack</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ryuk-ransomware-operator-sentenced-for-deploying-malware-and-extorting-victim-networks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T14:28:35Z</news:publication_date>
    <news:title>Ryuk ransomware operator sentenced to 2 years in prison</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/aws-lambda-flaw-lets-attackers-bypass-iam-permissions-and-access-cloud-services</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T14:23:53Z</news:publication_date>
    <news:title>AWS Lambda Flaw Lets Attackers Bypass IAM Permissions and Access Cloud Services</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/this-windows-malware-is-built-to-let-up-to-four-ai-models-vote-on-its-next-move</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T14:17:58Z</news:publication_date>
    <news:title>This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cofense-measures-employee-readiness-against-real-world-phishing-threats</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T14:01:12Z</news:publication_date>
    <news:title>Cofense measures employee readiness against real-world phishing threats</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/windows-botnet-x47-c-offers-ai-api-draining-18-attack-methods</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T14:00:00Z</news:publication_date>
    <news:title>Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/darkme-rat-trades-zero-days-for-plain-phishing-emails</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T13:24:17Z</news:publication_date>
    <news:title>DarkMe RAT trades zero-days for plain phishing emails</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/metas-muse-ai-assistant-rolled-out-with-a-serious-security-flaw</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T12:54:58Z</news:publication_date>
    <news:title>Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fake-claude-max-giveaway-hides-a-google-account-phishing-trap</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T12:45:00Z</news:publication_date>
    <news:title>Fake Claude Max giveaway tricks users into handing over their Google account credentials</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fake-crypto-wallet-app-spreads-pamstealer-malware-to-steal-mac-passwords</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T12:44:40Z</news:publication_date>
    <news:title>Fake Crypto Wallet App Delivers PamStealer Malware That Hijacks Mac Credentials</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/exvicy-clickfix-malware-as-a-service-copies-errtraffic-to-hijack-wordpress-sites</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T12:29:44Z</news:publication_date>
    <news:title>Exvicy ClickFix Malware-as-a-Service Copies ErrTraffic to Hijack WordPress Sites</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ransomware-attacks-reach-record-high-for-2026-new-cyber-risk-reported-by-infosecurity-maga</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T12:00:00Z</news:publication_date>
    <news:title>Ransomware Attacks Reach Record High for 2026: new cyber risk reported by infosecurity-magazine.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/adobe-patches-critical-flaws-in-connect-aem-forms</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T11:40:59Z</news:publication_date>
    <news:title>Adobe Patches Critical Flaws in Connect, AEM Forms</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cybercriminals-abandon-domains-but-keep-the-hosting-networks-behind-malware-campaigns</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T11:40:52Z</news:publication_date>
    <news:title>The Domains Keep Disappearing, but the Malware Infrastructure Behind Them Never Moves</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cloudflare-joins-global-operation-to-take-down-eviltokens</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T11:26:06Z</news:publication_date>
    <news:title>Cloudflare Joins Global Operation to Take Down EvilTokens</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/exploit-released-for-unpatched-ubuntu-linux-flaw-enabling-host-root-container-escape</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T11:12:18Z</news:publication_date>
    <news:title>Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/the-malware-hiding-in-developer-tools-that-turned-terraform-providers-into-attack-paths</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T09:22:31Z</news:publication_date>
    <news:title>The Phishing Kit That Turned Microsoft’s Login Flow Into an AI-Powered Fraud Machine</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/wordpress-7-1-2-fixes-critical-unauthenticated-path-traversal-vulnerability-cve-2026-87902</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T09:01:45Z</news:publication_date>
    <news:title>WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/chatgpt-computer-history-feature-creates-new-data-theft-risk-for-macos-infostealers</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T08:52:18Z</news:publication_date>
    <news:title>ChatGPT Computer History Feature Creates New Data Theft Risk for macOS Infostealers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-disrupts-eviltokens-phishing-service-that-gave-criminals-access-to-12000-inboxes</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T08:34:15Z</news:publication_date>
    <news:title>Microsoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/arista-patches-actively-exploited-velocloud-orchestrator-zero-day</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T08:33:06Z</news:publication_date>
    <news:title>Arista patches actively exploited VeloCloud Orchestrator zero-day</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/chinese-hackers-exploit-chrome-windows-zero-day-chain-to-deploy-cleangulp-malware</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T08:29:24Z</news:publication_date>
    <news:title>Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ryuk-ransomware-member-sentenced-to-24-months-in-prison</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T08:20:05Z</news:publication_date>
    <news:title>Ryuk ransomware member sentenced to 24 months in prison</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-etuue-nch-ngohw-cve-2026-65660-ain-sharepoint-aacchnmaaaipsuukaarrankhmaasangbne</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T08:02:00Z</news:publication_date>
    <news:title>Microsoft เตือนช่องโหว่ CVE-2026-65660 ใน SharePoint อาจนำไปสู่การรันคำสั่งบนเซิร์ฟเวอร์</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-next-js-flaw-enables-rce-attacks-via-weaponized-svg-file</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:53:01Z</news:publication_date>
    <news:title>Critical NEXT.JS Flaw Enables RCE Attacks Via Weaponized SVG File</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/chrome-patches-108-vulnerabilities-including-crticial-flaws-that-enable-code-execution-att</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:46:37Z</news:publication_date>
    <news:title>Chrome 154 Patches 108 Vulnerabilities: new cyber risk reported by securityweek.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisco-talos-launches-cairn-tool-to-hunt-and-track-ai-integrated-malware</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:39:43Z</news:publication_date>
    <news:title>Cisco Talos Launches CAIRN Tool to Hunt and Track AI-Integrated Malware</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ai-powered-threats-exploit-digital-trust-through-autonomous-breach-techniques</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:31:46Z</news:publication_date>
    <news:title>AI-Driven Cyberattacks Enter New Phase With Autonomous Fraud and Digital Trust Abuse</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/this-malware-doesnt-wait-for-hackers-it-asks-ai-models-what-to-do-next</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:20:40Z</news:publication_date>
    <news:title>This Malware Doesn’t Wait for Hackers—It Asks AI Models What to Do Next</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/weekly-cybersecurity-newsletter-top-50-biggest-cybersecurity-stories-of-the-week</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:10:26Z</news:publication_date>
    <news:title>Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hpe-networking-analytics-engine-flaws-let-attackers-gain-root-access</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T07:05:59Z</news:publication_date>
    <news:title>SolarWinds Observability Flaws Let Unauthenticated Attackers Execute Remote Code</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/fake-tv-streaming-ads-deliver-streamrat-malware-for-remote-android-device-hijacking</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T06:47:11Z</news:publication_date>
    <news:title>A Fake Streaming App Turned Android Phones Into Remote-Controlled Devices</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/china-aligned-famoussparrow-targets-governments-with-new-backdoor</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T05:38:09Z</news:publication_date>
    <news:title>China-aligned FamousSparrow Targets Governments with New Backdoor</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/prismor-open-source-runtime-control-plane-for-ai-agents</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T05:30:31Z</news:publication_date>
    <news:title>Prismor: Open-source runtime control plane for AI agents</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/product-showcase-scamwise-checks-the-red-flags-before-you-take-the-bait</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T05:00:48Z</news:publication_date>
    <news:title>Product showcase: Scamwise checks the red flags before you take the bait</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-exploiting-f5-big-ip-oauth-server-0-day-flaw-to-gain-remote-code-execution</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T03:24:27Z</news:publication_date>
    <news:title>Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ai-malware-just-removed-the-human-from-the-attack-loop</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-23T00:39:51Z</news:publication_date>
    <news:title>AI malware just removed the human from the attack loop</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bigcommerce-merchants-impacted-by-third-party-app-data-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T23:24:58Z</news:publication_date>
    <news:title>BigCommerce merchants impacted by third-party app data breach</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-exvicy-malware-as-a-service-framework-copies-rival-s-code</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T22:57:39Z</news:publication_date>
    <news:title>New Exvicy malware-as-a-service framework copies rival&apos;s code</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/task-stomp-campaign-uses-powershell-backdoor-for-data-theft</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T22:52:39Z</news:publication_date>
    <news:title>Stealthy WordPress Malware Uses Must-Use Plugin and Ethereum EtherHiding for Persistent Backdoor A</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T20:35:24Z</news:publication_date>
    <news:title>Chinese hackers exploit WordPress, Zyxel flaws to steal govt data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T19:13:29Z</news:publication_date>
    <news:title>ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/volexity-spots-another-china-aligned-threat-group-exploiting-chrome-and-microsoft-defects</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T18:47:07Z</news:publication_date>
    <news:title>Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-adds-four-known-exploited-vulnerabilities-to-catalog</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T18:44:46Z</news:publication_date>
    <news:title>CISA Adds Four Known Exploited Vulnerabilities to Catalog</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-closedquorum-windows-malware-uses-ai-for-attack-decisions</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T18:04:39Z</news:publication_date>
    <news:title>New ClosedQuorum Windows malware uses AI for attack decisions</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/malicious-npm-package-poses-as-twilio-bug-bounty-probe-can-exfiltrate-credentials</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T17:58:15Z</news:publication_date>
    <news:title>Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bigcommerce-data-stolen-via-ribon-apps-hack-new-cyber-risk-reported-by-securityweek-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T17:58:00Z</news:publication_date>
    <news:title>BigCommerce Data Stolen via Ribon Apps Hack: new cyber risk reported by securityweek.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/shai-hulud-attack-nips-cyber-firm-crowdsec-s-github-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T17:32:49Z</news:publication_date>
    <news:title>Shai-Hulud Attack Nips Cyber-Firm CrowdSec&apos;s GitHub Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/rathat-android-malware-uses-ai-to-target-banking-credentials-in-real-time</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T17:02:05Z</news:publication_date>
    <news:title>RatHat Android Malware Uses AI to Target Banking Credentials in Real Time</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/gemini-ai-autonomously-hacked-3-companies-google-confirms</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T17:00:00Z</news:publication_date>
    <news:title>Gemini AI Autonomously Hacked 3 Companies, Google Confirms</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/scaling-soc-capabilities-how-threat-intelligence-cuts-triage-time-and-burnout</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T16:46:05Z</news:publication_date>
    <news:title>Scaling SOC Capabilities: How Threat Intelligence Cuts Triage Time and Burnout</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-bifrost-ai-gateway-flaw-lets-attackers-run-commands-without-credentials</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T16:41:12Z</news:publication_date>
    <news:title>Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/attackers-hit-check-point-management-servers-and-spark-firewalls-f5-big-ip-apm-instances</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T16:32:47Z</news:publication_date>
    <news:title>Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/researcher-drops-bigdiskbuster-zero-day-poc-that-blocks-microsoft-defender-updates</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T16:14:04Z</news:publication_date>
    <news:title>Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/moviereaper-malware-uses-the-odyssey-torrents-to-infect-users-worldwide</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T15:44:09Z</news:publication_date>
    <news:title>MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ferramentas-de-acesso-remoto-porta-de-entrada-para-ataques</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T15:42:55Z</news:publication_date>
    <news:title>Ferramentas de acesso remoto: porta de entrada para ataques</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cairn-a-new-tool-to-track-ai-malware-that-operates-without-human-control</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T15:27:12Z</news:publication_date>
    <news:title>CAIRN – A New Tool to Track AI Malware That Operates Without Human Control</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-and-partners-disrupt-eviltokens-a-comprehensive-cybercrime-service-for-financial</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T15:00:00Z</news:publication_date>
    <news:title>Microsoft Disrupts EvilTokens Device Code Phishing Service</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T15:00:00Z</news:publication_date>
    <news:title>Unmasking EvilTokens: Getting to the root of device code phishing</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload-risk</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T14:56:08Z</news:publication_date>
    <news:title>Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/payload-il-ransomware-che-trasforma-active-directory-in-strumento-dattacco</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T14:15:36Z</news:publication_date>
    <news:title>PAYLOAD, il ransomware che trasforma Active Directory in strumento d’attacco</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/autonomous-ai-agents-hack-retailers-for-25-and-steal-600000-credit-cards</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T14:00:00Z</news:publication_date>
    <news:title>Autonomous AI Agents Hack Retailers for $25 and Steal 600,000 Credit Cards</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/researchers-uncover-malware-that-uses-ai-to-choose-its-next-move</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-22T13:56:55Z</news:publication_date>
    <news:title>Researchers uncover malware that uses AI to choose its next move</news:title>
  </news:news>
</url>
</urlset>