<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/ai-generated-code-supply-chain-attack-dissecting-the-miasma-worm</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-07T00:00:00.000Z</news:publication_date>
      <news:title>AI-Generated Code Supply Chain Attack: Dissecting the Miasma Worm</news:title>
      <news:keywords>cybersecurity, supply-chain, github, ai-coding-tools</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/how-to-detect-and-mitigate-the-actively-exploited-linux-kernel-improper-authentication-flaw</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-07T00:00:00.000Z</news:publication_date>
      <news:title>How to Detect and Mitigate the Actively Exploited Linux Kernel Improper Authentication Flaw</news:title>
      <news:keywords>linux, kernel, cisa, vulnerability, authentication</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/testing-ai-powered-web-apps-for-prompt-injection-and-data-leakage-with-javascript</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-07T00:00:00.000Z</news:publication_date>
      <news:title>Testing AI-Powered Web Apps for Prompt Injection and Data Leakage with JavaScript</news:title>
      <news:keywords>javascript, ai-security, prompt-injection, web-security, data-leakage</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/ai-fuzzing-finds-21-ffmpeg-bugs-media-pipeline-defense-in-practice</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-06T00:00:00.000Z</news:publication_date>
      <news:title>AI Fuzzing Finds 21 FFmpeg Bugs: Media Pipeline Defense in Practice</news:title>
      <news:keywords>ffmpeg, fuzzing, security, media-pipeline</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-the-hugging-face-transformers-rce-vulnerability-practical-developer-defense</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-06T00:00:00.000Z</news:publication_date>
      <news:title>Auditing the Hugging Face Transformers RCE Vulnerability: Practical Developer Defense</news:title>
      <news:keywords>cybersecurity, hugging-face, transformers, remote-code-execution</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/claude-codes-github-token-exposure-microsofts-findings-and-your-defense-checklist</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-06T00:00:00.000Z</news:publication_date>
      <news:title>Claude Code&apos;s GitHub Token Exposure: Microsoft&apos;s Findings and Your Defense Checklist</news:title>
      <news:keywords>claude-code, github, ai-security, credential-theft, microsoft</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/edges-javascript-zero-day-and-the-pwa-attack-surface-it-could-have-opened</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-06T00:00:00.000Z</news:publication_date>
      <news:title>Edge’s JavaScript Zero-Day and the PWA Attack Surface It Could Have Opened</news:title>
      <news:keywords>microsoft-edge, javascript, pwa, zero-day</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/hardening-gcp-workloads-after-googles-cloud-security-layoffs-a-developers-checklist</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-06T00:00:00.000Z</news:publication_date>
      <news:title>Hardening GCP Workloads After Google’s Cloud Security Layoffs: A Developer’s Checklist</news:title>
      <news:keywords>gcp, cloud-security, devops, iam</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/miasma-worm-supply-chain-attack-hardening-github-actions-and-npm-for-javascript-teams</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-06T00:00:00.000Z</news:publication_date>
      <news:title>Miasma Worm Supply Chain Attack: Hardening GitHub Actions and npm for JavaScript Teams</news:title>
      <news:keywords>github-actions, npm, supply-chain-security, javascript</news:keywords>
    </news:news>
  </url>
</urlset>
