<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
<url>
  <loc>https://hackwatch.io/alert/shinyhunters-bypass-waf-rules-to-resume-oracle-peoplesoft-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-26T13:36:11Z</news:publication_date>
    <news:title>Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/old-school-credit-card-scams-are-far-from-dead</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-26T12:00:00Z</news:publication_date>
    <news:title>Old-School Credit Card Scams Are Far From Dead</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/kiteworks-warns-users-to-take-systems-offline-amid-suspected-zero-day-threat</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-26T07:45:21Z</news:publication_date>
    <news:title>Kiteworks Warns Users to Take Systems Offline Amid Suspected Zero-Day Threat</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/openais-ai-agents-tried-hacking-4-websites-without-being-prompted</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-26T04:36:57Z</news:publication_date>
    <news:title>OpenAI’s AI Agents Tried Hacking 4 Websites Without Being Prompted</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/16-year-old-researcher-finds-microsoft-auth-vulnerability-that-exposes-17-3-trillion-store</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-26T03:55:43Z</news:publication_date>
    <news:title>16-Year-Old Researcher Finds Microsoft Auth Vulnerability that Exposes 17.3 Trillion Stored Record</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bbc-technology-technology-health-environment-ai-4</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T23:17:28Z</news:publication_date>
    <news:title>BBC Technology | Technology, Health, Environment, AI</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/rydox-marketplace-operator-pleads-guilty-to-identity-theft-and-money-laundering</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T22:52:08Z</news:publication_date>
    <news:title>Rydox marketplace operator pleads guilty to identity theft and money laundering</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-carbonato-botnet-uses-ai-framework-to-target-insecure-docker-daemons</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T22:09:40Z</news:publication_date>
    <news:title>New Carbonato botnet uses AI framework to target insecure Docker daemons</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/elementor-plugin-vulnerability-allows-admin-account-creation</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T22:04:40Z</news:publication_date>
    <news:title>Elementor plugin vulnerability allows admin account creation</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T21:41:07Z</news:publication_date>
    <news:title>Kiteworks urges 6-hour server shutdown over potential zero-day attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T20:57:55Z</news:publication_date>
    <news:title>ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/gemini-hacked-three-companies-the-ai-isn-t-the-part-that-should-scare-you</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T19:20:36Z</news:publication_date>
    <news:title>Gemini hacked three companies. The AI isn&apos;t the part that should scare you</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/elementor-wordpress-flaw-lets-attackers-create-admin-accounts</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T18:13:33Z</news:publication_date>
    <news:title>Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/red-heron-exploits-critical-gitea-flaw-to-steal-repositories-and-deploy-linux-rootkit</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T18:02:16Z</news:publication_date>
    <news:title>Red Heron Exploits Critical Gitea Flaw to Steal Repositories and Deploy Linux Rootkit</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/attackers-target-unpatched-roundcube-servers-with-cve-2026-48842</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T17:54:48Z</news:publication_date>
    <news:title>Attackers Target Unpatched Roundcube Servers With CVE-2026-48842</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/ai-tools-help-hacker-break-in-for-25-per-target</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T17:38:42Z</news:publication_date>
    <news:title>AI tools help hacker break in for $25 per target</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T17:24:20Z</news:publication_date>
    <news:title>SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/staying-ahead-of-the-ransomware-industry-new-cyber-risk-reported-by-securitymagazine-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T16:00:00Z</news:publication_date>
    <news:title>Staying Ahead of the Ransomware Industry: new cyber risk reported by securitymagazine.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/why-ransomware-is-so-dangerous-for-healthcare-new-cyber-risk-reported-by-scmagazine-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T15:42:14Z</news:publication_date>
    <news:title>Why ransomware is so dangerous for healthcare: new cyber risk reported by scmagazine.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T15:35:08Z</news:publication_date>
    <news:title>Storm-3168 Hackers Abuse Compromised Service Principals to Destroy Azure Cloud Resources</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/how-to-prove-ransomware-recovery-works-clean-room-restoration-and-recovery-assurance</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T15:05:09Z</news:publication_date>
    <news:title>How to prove ransomware recovery works: clean-room restoration and recovery assurance</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-russian-infostealer-targeting-ukrainian-users</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T15:00:00Z</news:publication_date>
    <news:title>New Russian Infostealer Targeting Ukrainian Users</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T14:51:10Z</news:publication_date>
    <news:title>With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/stopping-it-worker-scams-requires-revamped-hr-process</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T14:46:13Z</news:publication_date>
    <news:title>Stopping IT Worker Scams Requires Revamped HR Process</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/compromised-github-actions-came-back-online-and-resumed-executing-mini-shai-hulud-malware</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T14:44:41Z</news:publication_date>
    <news:title>Compromised GitHub Actions re-enabled, posing supply chain risks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/researchers-found-a-botnet-that-uses-an-ai-agent-to-operate-inside-compromised-servers</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T14:17:54Z</news:publication_date>
    <news:title>Researchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/sauron-loader-malware-uses-dll-side-loading-and-in-memory-decryption-to-evade-detection</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T13:47:28Z</news:publication_date>
    <news:title>Kothamine malware uses Tailscale’s tailcat to evade network detection</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/zero-click-vulnerabilities-in-salesforce-agentforce-expose-wider-ai-agent-risk</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T13:30:00Z</news:publication_date>
    <news:title>Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/14-year-old-linux-kernel-vulnerability-enables-root-access-and-docker-escape</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T12:48:13Z</news:publication_date>
    <news:title>14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/google-chrome-154-fixes-108-security-flaws-11-are-rated-critical</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T12:30:09Z</news:publication_date>
    <news:title>Google Chrome 154 Fixes 108 Security Flaws: 11 Are Rated Critical</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-servicenow-vulnerabilities-let-attackers-bypass-authorization-update-now</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T12:18:09Z</news:publication_date>
    <news:title>Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization – Update Now!</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/attackers-are-turning-everyday-business-emails-into-malware-delivery-machines</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T12:01:17Z</news:publication_date>
    <news:title>Attackers Are Turning Everyday Business Emails Into Malware Delivery Machines</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T11:35:14Z</news:publication_date>
    <news:title>Rydox marketplace admin pleads guilty, faces 22 years in prison</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/on-anthropics-ai-misuse-report-new-cyber-risk-reported-by-schneier-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T11:07:22Z</news:publication_date>
    <news:title>On Anthropic’s AI Misuse Report: new cyber risk reported by schneier.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/party-invite-phishing-scams-are-the-new-missed-connections</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T11:00:00Z</news:publication_date>
    <news:title>Party Invite Phishing Scams Are the New Missed Connections</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/servicenow-security-flaws-allow-attackers-to-execute-sql-and-modify-instance-data</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T10:58:04Z</news:publication_date>
    <news:title>ServiceNow Security Flaws Allow Attackers to Execute SQL and Modify Instance Data</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bitget-says-suspected-north-korean-hackers-stole-351-6m-after-backend-compromise</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T10:35:55Z</news:publication_date>
    <news:title>Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-flags-wso2-security-flaw-under-active-exploitation</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T10:14:50Z</news:publication_date>
    <news:title>CISA Flags WSO2 Security Flaw Under Active Exploitation</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/roundcube-pre-auth-sql-injection-flaw-actively-exploited-in-the-wild</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T10:14:02Z</news:publication_date>
    <news:title>Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-finds-ransomware-group-using-same-attack-blueprint-across-multiple-malware-famil</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T10:11:25Z</news:publication_date>
    <news:title>Microsoft Finds Ransomware Group Using Same Attack Blueprint Across Multiple Malware Families</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/microsoft-password-reset-portal-could-reveal-users-and-mfa-protection-details</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T09:53:32Z</news:publication_date>
    <news:title>Microsoft Password Reset Portal Could Reveal Users and MFA Protection Details</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/wordpress-flaw-under-active-attack-hackers-target-cve-2026-87902-for-code-execution</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T09:51:07Z</news:publication_date>
    <news:title>WordPress Flaw Under Active Attack: Hackers Target CVE-2026-87902 for Code Execution</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/remcontrol-banking-trojan-gives-attackers-remote-control-of-android-devices</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T09:30:00Z</news:publication_date>
    <news:title>RemControl Banking Trojan Gives Attackers Remote Control of Android Devices</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/macsync-info-stealing-malware-hides-malicious-commands-in-an-icloud-calendar</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T09:22:45Z</news:publication_date>
    <news:title>MacSync info-stealing malware hides malicious commands in an iCloud calendar</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/researchers-identify-aliexpress-phishing-domains-before-registration</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T08:30:00Z</news:publication_date>
    <news:title>Researchers Identify AliExpress Phishing Domains Before Registration</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/salesforce-agentforce-flaw-enables-0-click-data-exfiltration-via-prompt-injection</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T07:47:45Z</news:publication_date>
    <news:title>Salesforce Indirect Prompt Injection Vulnerability Enables 0-click Data Exfiltration</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/sudo-vulnerability-lets-attackers-bypass-time-based-authorization-controls</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T07:26:40Z</news:publication_date>
    <news:title>Sudo Security Vulnerability Lets Attackers Escalate Privileges</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/roundcube-webmail-vulnerability-in-attackers-crosshairs</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T06:57:40Z</news:publication_date>
    <news:title>Roundcube Webmail Vulnerability in Attackers’ Crosshairs</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/duelbits-confirms-7-million-hot-wallet-hack-forcing-systems-offline</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T05:41:52Z</news:publication_date>
    <news:title>Duelbits Confirms $7 Million Hot-Wallet Hack, forcing Systems offline</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/hackers-exploited-ethereum-bridge-contract-to-drain-full-balance-from-payy-network</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T05:18:27Z</news:publication_date>
    <news:title>Hackers Exploited Ethereum Bridge Contract to Drain Full Balance from Payy Network</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bbc-technology-technology-health-environment-ai-3</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T05:17:35Z</news:publication_date>
    <news:title>BBC Technology | Technology, Health, Environment, AI</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/only-26-of-detected-cisa-known-exploited-vulnerabilities-were-fully-remediated</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T04:46:34Z</news:publication_date>
    <news:title>CISA Adds One Known Exploited Vulnerability to Catalog</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/bitget-hot-wallet-hacked-attackers-stole-351-6-million-from-hot-wallets</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T03:34:38Z</news:publication_date>
    <news:title>Bitget Hot Wallet Hacked – Attackers Stole $351.6 Million From Hot Wallets</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cloudflare-containers-vulnerability-could-leak-data-between-customer-workloads</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T03:13:12Z</news:publication_date>
    <news:title>Cloudflare Containers Vulnerability Could Leak Data Between Customer Workloads</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/security-news-hkcert-new-cyber-risk-reported-by-hkcert-org-2</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T02:00:26Z</news:publication_date>
    <news:title>Security News | HKCERT: new cyber risk reported by hkcert.org</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-ransomware-group-n0n-escalates-threats-by-targeting-backups</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T00:22:44Z</news:publication_date>
    <news:title>New ransomware group n0n escalates threats by targeting backups</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/using-threat-intelligence-to-stop-ransomware-attacks</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-25T00:00:00Z</news:publication_date>
    <news:title>Using Threat Intelligence to Stop Ransomware Attacks</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/scammers-impersonating-police-and-government-officials-have-stolen-1-6-billion</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T23:50:26Z</news:publication_date>
    <news:title>Scammers impersonating police and government officials have stolen $1.6 billion</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/f5-patches-critical-zero-day-flaw-exploited-in-big-ip-apm</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T23:45:26Z</news:publication_date>
    <news:title>F5 patches critical zero-day flaw exploited in BIG-IP APM</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-windows-botnet-offers-ai-credit-draining-and-other-attack-methods</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T23:13:08Z</news:publication_date>
    <news:title>New Windows botnet offers AI credit draining and other attack methods</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/botnet-carbonato-ataca-docker-e-instala-agente-de-ia-hermes</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T23:01:30Z</news:publication_date>
    <news:title>Botnet Carbonato ataca Docker e instala agente de IA Hermes</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/sectoprat-returns-hiding-inside-a-legitimate-application</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T20:32:50Z</news:publication_date>
    <news:title>SectopRAT Returns, Hiding Inside a Legitimate Application</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/wordpress-patches-a-critical-severity-security-vulnerability</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T20:26:22Z</news:publication_date>
    <news:title>WordPress patches a critical severity security vulnerability</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-macsync-malware-turns-macos-apps-into-tools-for-crypto-and-password-theft</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T20:10:48Z</news:publication_date>
    <news:title>TWEAKOS Malware Turns Telegram Into a Stealer, C2 Platform and Stolen Account Marketplace</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/falha-no-wordpress-escala-para-comprometimentos-ativos</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T20:08:58Z</news:publication_date>
    <news:title>Falha no WordPress escala para comprometimentos ativos</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/i-think-i-found-an-ai-agent-worth-the-risk-new-cyber-risk-reported-by-wired-com</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T19:36:35Z</news:publication_date>
    <news:title>I Think I Found an AI Agent Worth the Risk: new cyber risk reported by wired.com</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/critical-9-8-jetbrains-teamcity-rce-exploited-by-ransomware-says-cisa</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T19:25:35Z</news:publication_date>
    <news:title>Critical 9.8 JetBrains TeamCity RCE exploited by ransomware, says CISA</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cyber-recovery-plans-lag-behind-ai-ransomware-threats</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T18:20:56Z</news:publication_date>
    <news:title>Cyber recovery plans lag behind AI, ransomware threats</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/cisa-adds-two-known-exploited-vulnerabilities-to-catalog</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T18:16:27Z</news:publication_date>
    <news:title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/burger-king-russia-customer-data-leaked-online-after-2024-breach</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T17:53:42Z</news:publication_date>
    <news:title>Burger King Russia customer data leaked online after 2024 breach</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/threatsday-ai-search-poisoning-ai-coding-tool-leaking-repos-one-click-code-execution-and-1</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T17:52:43Z</news:publication_date>
    <news:title>Zero-click flaw enables remote code execution in four mainstream AI coding agents: report</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/exposed-gitlab-project-email-addresses-let-attackers-push-code</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T17:47:44Z</news:publication_date>
    <news:title>Private GitLab email addresses exposed in public documentation</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/new-trustsink-attack-steals-passwords-via-rogue-mfa-provider</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T16:44:06Z</news:publication_date>
    <news:title>New TrustSink attack steals passwords via rogue MFA provider</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/beyond-the-ransomware-tracking-storm-2570s-consistent-tradecraft-across-deployments</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T16:00:00Z</news:publication_date>
    <news:title>Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments</news:title>
  </news:news>
</url>
<url>
  <loc>https://hackwatch.io/alert/eufy-omni-c20-omni-x10-pro-new-cyber-risk-reported-by-cisa-gov</loc>
  <news:news>
    <news:publication>
      <news:name>HackWatch</news:name>
      <news:language>en</news:language>
    </news:publication>
    <news:publication_date>2026-09-24T15:16:09Z</news:publication_date>
    <news:title>Eufy Omni C20, Omni X10 Pro: new cyber risk reported by cisa.gov</news:title>
  </news:news>
</url>
</urlset>