<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/defending-unpatched-langflow-instances-against-remote-code-execution-cve-2026-5027</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-10T00:00:00.000Z</news:publication_date>
      <news:title>Defending Unpatched Langflow Instances Against Remote Code Execution (CVE-2026-5027)</news:title>
      <news:keywords>langflow, cve-2026-5027, rce, application-security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/mitigating-windows-rdp-credential-and-data-exposure-patterns-for-platform-engineers</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-10T00:00:00.000Z</news:publication_date>
      <news:title>Mitigating Windows RDP Credential and Data Exposure: Patterns for Platform Engineers</news:title>
      <news:keywords>windows, rdp, credential-security, platform-engineering</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/patch-your-toolchain-dissecting-the-javascript-and-net-rces-from-june-2025-patch-tuesday</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-10T00:00:00.000Z</news:publication_date>
      <news:title>Patch Your Toolchain: Dissecting the JavaScript and .NET RCEs from June 2025 Patch Tuesday</news:title>
      <news:keywords>microsoft, patch-tuesday, javascript, dotnet, rce</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/testing-llm-agent-tool-authorization-with-a-phishing-simulation-the-openclaw-case</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-10T00:00:00.000Z</news:publication_date>
      <news:title>Testing LLM Agent Tool Authorization with a Phishing Simulation: The OpenClaw Case</news:title>
      <news:keywords>llm-security, agent-authz, phishing-simulation, prompt-injection, cybersecurity</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/the-fake-free-software-trap-analyzing-tiktok-and-instagram-reel-malware-campaigns</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-10T00:00:00.000Z</news:publication_date>
      <news:title>The Fake Free Software Trap: Analyzing TikTok and Instagram Reel Malware Campaigns</news:title>
      <news:keywords>cybersecurity, malware, social-engineering, tiktok, instagram</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/when-researchers-drop-zero-days-defending-your-apps-after-the-microsoft-exploit-dump</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-10T00:00:00.000Z</news:publication_date>
      <news:title>When Researchers Drop Zero-Days: Defending Your Apps After the Microsoft Exploit Dump</news:title>
      <news:keywords>cybersecurity, microsoft, zero-day, application-security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-redis-for-lua-sandbox-rce-a-practical-guide-to-detecting-and-preventing-host-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-09T00:00:00.000Z</news:publication_date>
      <news:title>Auditing Redis for Lua Sandbox RCE: A Practical Guide to Detecting and Preventing Host Takeover</news:title>
      <news:keywords>redis, lua, rce, vulnerability-management</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/beyond-the-chrome-patch-making-your-javascript-resilient-to-v8-type-confusion-exploits</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-09T00:00:00.000Z</news:publication_date>
      <news:title>Beyond the Chrome Patch: Making Your JavaScript Resilient to V8 Type Confusion Exploits</news:title>
      <news:keywords>javascript, v8, chrome-security, type-confusion</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/breaking-fortisandbox-command-injection-via-untrusted-input-in-a-developer-facing-api</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-09T00:00:00.000Z</news:publication_date>
      <news:title>Breaking FortiSandbox: Command Injection via Untrusted Input in a Developer-Facing API</news:title>
      <news:keywords>fortisandbox, command-injection, api-security, cybersecurity</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/from-llm-calls-to-remote-shell-auditing-the-litellm-vulnerability-being-actively-exploited</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-09T00:00:00.000Z</news:publication_date>
      <news:title>From LLM Calls to Remote Shell: Auditing the LiteLLM Vulnerability Being Actively Exploited</news:title>
      <news:keywords>litellm, rce, llmops, cybersecurity</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/hardening-your-litellm-deployment-to-block-cve-2026-42271-attacks</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-09T00:00:00.000Z</news:publication_date>
      <news:title>Hardening Your LiteLLM Deployment to Block CVE-2026-42271 Attacks</news:title>
      <news:keywords>litellm, cve-2026-42271, cybersecurity, devsecops</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/how-to-audit-sap-systems-for-patch-day-vulnerabilities-without-commercial-tools</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-09T00:00:00.000Z</news:publication_date>
      <news:title>How to Audit SAP Systems for Patch-Day Vulnerabilities Without Commercial Tools</news:title>
      <news:keywords>sap, cybersecurity, vulnerability-management, patch-management</news:keywords>
    </news:news>
  </url>
</urlset>
