<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/auditing-the-mcp-python-sdk-and-authlib-for-oauth-credential-leaks-and-missing-signature-checks</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>Auditing the MCP Python SDK and Authlib for OAuth Credential Leaks and Missing Signature Checks</news:title>
      <news:keywords>python, oauth, mcp, security, authlib</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/cve-2026-86950-auditing-the-coregraphics-image-and-font-decoding-path-after-an-in-the-wild-zero-day</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>CVE-2026-86950: Auditing the CoreGraphics Image and Font Decoding Path After an In-the-Wild Zero-Day</news:title>
      <news:keywords>apple, zero-day, coregraphics, memory-safety, spyware</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/measuring-eu-latency-to-alibaba-clouds-new-europe-regions-against-aws-and-azure</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>Measuring EU Latency to Alibaba Cloud&apos;s New Europe Regions Against AWS and Azure</news:title>
      <news:keywords>alibaba-cloud, aws, azure, latency, cloud-computing</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/metering-always-on-agents-in-nodejs-cost-per-task-across-gpt-61-sol-and-astra</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-30T00:00:00.000Z</news:publication_date>
      <news:title>Metering Always-On Agents in Node.js: Cost per Task Across GPT-6.1 Sol and Astra</news:title>
      <news:keywords>nodejs, ai-agents, llm-cost-optimization, observability, openai</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-a-self-hosted-computer-use-agent-stack-for-element-blindness-and-checkout-abuse</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-29T00:00:00.000Z</news:publication_date>
      <news:title>Auditing a Self-Hosted Computer-Use Agent Stack for Element-Blindness and Checkout Abuse</news:title>
      <news:keywords>computer-use-agents, self-hosted-ai, gui-grounding, open-weight-models, browser-automation</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/building-agent-governance-into-your-api-instead-of-bolting-it-on-policy-audit-and-cli-surfaces</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-29T00:00:00.000Z</news:publication_date>
      <news:title>Building Agent Governance Into Your API Instead of Bolting It On: Policy, Audit, and CLI Surfaces</news:title>
      <news:keywords>ai-agents, api-design, governance, security, developer-tools</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/what-cloudflares-voidzero-report-says-about-oxc-rolldown-and-vite-build-times</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-29T00:00:00.000Z</news:publication_date>
      <news:title>What Cloudflare&apos;s VoidZero Report Says About Oxc, Rolldown, and Vite Build Times</news:title>
      <news:keywords>cloudflare, voidzero, oxc, rolldown, vite</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/why-a-waf-alone-would-not-stop-the-peoplesoft-cve-2026-35273-web-shell-drop</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-29T00:00:00.000Z</news:publication_date>
      <news:title>Why a WAF Alone Would Not Stop the PeopleSoft CVE-2026-35273 Web Shell Drop</news:title>
      <news:keywords>peoplesoft, web-shell, waf-bypass, shinyhunters, incident-response</news:keywords>
    </news:news>
  </url>
</urlset>
