<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/anatomy-of-the-meta-muse-0-day-how-prompt-injection-becomes-a-hijacked-tool-call</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T00:00:00.000Z</news:publication_date>
      <news:title>Anatomy of the Meta Muse 0-Day: How Prompt Injection Becomes a Hijacked Tool Call</news:title>
      <news:keywords>ai-agents, security, prompt-injection, tool-calling, meta-muse</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-ai-agent-tool-execution-on-macos-after-the-meta-muse-zero-day</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T00:00:00.000Z</news:publication_date>
      <news:title>Auditing AI Agent Tool Execution on macOS After the Meta Muse Zero-Day</news:title>
      <news:keywords>ai-agent-security, macos, zero-day, sandboxing, malware-injection</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-heif-decoding-in-server-side-javascript-after-the-heif-heist</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T00:00:00.000Z</news:publication_date>
      <news:title>Auditing HEIF Decoding in Server-Side JavaScript After the HEIF Heist</news:title>
      <news:keywords>heif, image-parsing, rce, nodejs, security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/building-a-cost-per-task-ledger-for-agent-pipelines-on-gpt-6-opus-55-and-grok-47</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T00:00:00.000Z</news:publication_date>
      <news:title>Building a Cost-Per-Task Ledger for Agent Pipelines on GPT-6, Opus 5.5, and Grok 4.7</news:title>
      <news:keywords>llm-costs, agent-pipelines, inference-economics, prompt-caching, api-pricing</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/lifecycle-script-diffing-and-provenance-checks-hardening-npm-releases-after-the-65-repo-breach</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T00:00:00.000Z</news:publication_date>
      <news:title>Lifecycle-Script Diffing and Provenance Checks: Hardening npm Releases After the 65-Repo Breach</news:title>
      <news:keywords>npm, supply-chain-security, ci-cd, provenance, github-actions</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/porting-a-real-python-backend-to-cloudflare-workers-what-pyodidewasm-actually-breaks</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T00:00:00.000Z</news:publication_date>
      <news:title>Porting a Real Python Backend to Cloudflare Workers: What Pyodide/WASM Actually Breaks</news:title>
      <news:keywords>cloudflare-workers, python, pyodide, wasm, edge-computing</news:keywords>
    </news:news>
  </url>
</urlset>
