<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/auditing-redis-for-lua-sandbox-rce-a-practical-guide-to-detecting-and-preventing-host-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-09T00:00:00.000Z</news:publication_date>
      <news:title>Auditing Redis for Lua Sandbox RCE: A Practical Guide to Detecting and Preventing Host Takeover</news:title>
      <news:keywords>redis, lua, rce, vulnerability-management</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/beyond-the-chrome-patch-making-your-javascript-resilient-to-v8-type-confusion-exploits</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-09T00:00:00.000Z</news:publication_date>
      <news:title>Beyond the Chrome Patch: Making Your JavaScript Resilient to V8 Type Confusion Exploits</news:title>
      <news:keywords>javascript, v8, chrome-security, type-confusion</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/breaking-fortisandbox-command-injection-via-untrusted-input-in-a-developer-facing-api</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-09T00:00:00.000Z</news:publication_date>
      <news:title>Breaking FortiSandbox: Command Injection via Untrusted Input in a Developer-Facing API</news:title>
      <news:keywords>fortisandbox, command-injection, api-security, cybersecurity</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/from-llm-calls-to-remote-shell-auditing-the-litellm-vulnerability-being-actively-exploited</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-09T00:00:00.000Z</news:publication_date>
      <news:title>From LLM Calls to Remote Shell: Auditing the LiteLLM Vulnerability Being Actively Exploited</news:title>
      <news:keywords>litellm, rce, llmops, cybersecurity</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/hardening-your-litellm-deployment-to-block-cve-2026-42271-attacks</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-09T00:00:00.000Z</news:publication_date>
      <news:title>Hardening Your LiteLLM Deployment to Block CVE-2026-42271 Attacks</news:title>
      <news:keywords>litellm, cve-2026-42271, cybersecurity, devsecops</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/how-to-audit-sap-systems-for-patch-day-vulnerabilities-without-commercial-tools</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-09T00:00:00.000Z</news:publication_date>
      <news:title>How to Audit SAP Systems for Patch-Day Vulnerabilities Without Commercial Tools</news:title>
      <news:keywords>sap, cybersecurity, vulnerability-management, patch-management</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-admin-interfaces-for-stored-xss-patterns-from-vmwares-latest-fixes</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-08T00:00:00.000Z</news:publication_date>
      <news:title>Auditing Admin Interfaces for Stored XSS: Patterns from VMware’s Latest Fixes</news:title>
      <news:keywords>xss, vmware, admin-interfaces, web-security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-github-repos-for-self-replicating-malware-lessons-from-the-recent-worm</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-08T00:00:00.000Z</news:publication_date>
      <news:title>Auditing GitHub Repos for Self-Replicating Malware: Lessons from the Recent Worm</news:title>
      <news:keywords>github, malware, supply-chain-security, code-audit</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-vpn-configuration-post-exploit-lessons-from-cve-2026-50751</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-08T00:00:00.000Z</news:publication_date>
      <news:title>Auditing VPN Configuration Post-Exploit: Lessons from CVE-2026-50751</news:title>
      <news:keywords>cybersecurity, vpn, incident-response, check-point</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/breaking-down-the-whatsapp-pegasus-incident-memory-corruption-trust-boundaries-and-defensive-takeaways</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-08T00:00:00.000Z</news:publication_date>
      <news:title>Breaking Down the WhatsApp-Pegasus Incident: Memory Corruption, Trust Boundaries, and Defensive Takeaways</news:title>
      <news:keywords>cybersecurity, memory-corruption, exploit-development, whatsapp, defensive-security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/fixing-the-ie-webbrowser-control-rce-a-developers-remediation-checklist</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-08T00:00:00.000Z</news:publication_date>
      <news:title>Fixing the IE WebBrowser Control RCE: A Developer’s Remediation Checklist</news:title>
      <news:keywords>internet-explorer, webbrowser-control, rce, cybersecurity</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/solarwinds-serv-u-cve-2026-28318-when-unhandled-resource-exhaustion-becomes-a-dos</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-08T00:00:00.000Z</news:publication_date>
      <news:title>SolarWinds Serv-U CVE-2026-28318: When Unhandled Resource Exhaustion Becomes a DoS</news:title>
      <news:keywords>solarwinds, serv-u, cve-2026-28318, cisa</news:keywords>
    </news:news>
  </url>
</urlset>
