<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/spotting-malicious-redirects-in-npm-mirrors-before-they-reach-developers</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-26T00:00:00.000Z</news:publication_date>
      <news:title>Spotting Malicious Redirects in npm Mirrors Before They Reach Developers</news:title>
      <news:keywords>npm, phishing, supply-chain, security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/the-91-spring-cves-are-not-equal-finding-exploitable-paths-before-patching-209000-dependencies</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-26T00:00:00.000Z</news:publication_date>
      <news:title>The 91 Spring CVEs Are Not Equal: Finding Exploitable Paths Before Patching 209,000 Dependencies</news:title>
      <news:keywords>spring, cve, supply-chain-security, dependency-management</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/finding-and-blocking-redc2-in-linux-ci-with-npm-security-checks</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T00:00:00.000Z</news:publication_date>
      <news:title>Finding and Blocking RedC2 in Linux CI with npm Security Checks</news:title>
      <news:keywords>npm-security, linux-ci, redc2, supply-chain-security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/testing-the-isolated-vm-sandbox-escape-path-from-guest-javascript-to-host-execution</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T00:00:00.000Z</news:publication_date>
      <news:title>Testing the isolated-vm Sandbox Escape Path from Guest JavaScript to Host Execution</news:title>
      <news:keywords>cybersecurity, javascript, sandbox-escape, vulnerability</news:keywords>
    </news:news>
  </url>
</urlset>
