<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/auditing-a-wordpresswoocommerce-stack-for-plugin-patch-lag-and-post-compromise-indicators</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T00:00:00.000Z</news:publication_date>
      <news:title>Auditing a WordPress/WooCommerce Stack for Plugin Patch Lag and Post-Compromise Indicators</news:title>
      <news:keywords>wordpress, woocommerce, security, incident-response, plugin-supply-chain</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-ai-coding-agents-for-gitspawn-style-prompt-to-commit-attacks</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T00:00:00.000Z</news:publication_date>
      <news:title>Auditing AI Coding Agents for GitSpawn-Style Prompt-to-Commit Attacks</news:title>
      <news:keywords>ai-security, prompt-injection, devtools, git, appsec</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/pre-auth-sql-injection-in-cisco-secure-email-gateway-tracing-crafted-email-to-root</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T00:00:00.000Z</news:publication_date>
      <news:title>Pre-Auth SQL Injection in Cisco Secure Email Gateway: Tracing Crafted Email to Root</news:title>
      <news:keywords>cisco, sql-injection, email-security, zero-day, vulnerability-management</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/remediating-the-exploited-acronis-backup-plugin-across-a-shared-hosting-fleet</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T00:00:00.000Z</news:publication_date>
      <news:title>Remediating the Exploited Acronis Backup Plugin Across a Shared-Hosting Fleet</news:title>
      <news:keywords>security, cpanel, plesk, acronis, shared-hosting</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/reverse-engineering-the-kremlin-chrome-extension-permission-abuse-dnr-rules-and-native-messaging</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T00:00:00.000Z</news:publication_date>
      <news:title>Reverse-Engineering the KREMLIN Chrome Extension: Permission Abuse, DNR Rules, and Native Messaging</news:title>
      <news:keywords>chrome-extensions, malware-analysis, browser-security, declarative-net-request, native-messaging</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-telegram-desktops-html-export-for-incomplete-escaping-xss</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T00:00:00.000Z</news:publication_date>
      <news:title>Auditing Telegram Desktop&apos;s HTML Export for Incomplete-Escaping XSS</news:title>
      <news:keywords>xss, javascript-security, telegram-desktop, html-escaping, electron-security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/testing-homebrew-700s-vulnerability-scanner-with-a-deliberately-vulnerable-tap</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T00:00:00.000Z</news:publication_date>
      <news:title>Testing Homebrew 7.0.0&apos;s Vulnerability Scanner with a Deliberately Vulnerable Tap</news:title>
      <news:keywords>homebrew, supply-chain-security, vulnerability-scanner, sandboxing, devtools</news:keywords>
    </news:news>
  </url>
</urlset>
