<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/build-chain-signals-for-spotting-kimsuky-style-opencode-lnk-decoys</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
      <news:title>Build-Chain Signals for Spotting Kimsuky-Style OpenCode LNK Decoys</news:title>
      <news:keywords>cybersecurity, kimsuky, phishing, lnk, threat-detection</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/patching-is-not-containment-n-central-cve-2026-86218-in-managed-environments</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
      <news:title>Patching Is Not Containment: N-central CVE-2026-86218 in Managed Environments</news:title>
      <news:keywords>cybersecurity, cve, n-able, patch-management, msp</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-asus-control-center-cve-2026-75754-root-without-credentials</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
      <news:title>Auditing ASUS Control Center CVE-2026-75754: Root Without Credentials</news:title>
      <news:keywords>cybersecurity, asus-control-center, cve-2026-75754, vulnerability-management</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/metabase-as-an-attack-surface-what-the-shipmonk-trezor-incident-tells-developers-to-audit-first</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
      <news:title>Metabase as an Attack Surface: What the ShipMonk Trezor Incident Tells Developers to Audit First</news:title>
      <news:keywords>metabase, cybersecurity, data-breach, application-security</news:keywords>
    </news:news>
  </url>
</urlset>
