<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/auditing-ai-coding-agents-for-context-injection-lessons-from-mozilla-0dins-claude-code-research</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-28T00:00:00.000Z</news:publication_date>
      <news:title>Auditing AI Coding Agents for Context Injection: Lessons from Mozilla 0din’s Claude Code Research</news:title>
      <news:keywords>ai-security, prompt-injection, claude-code, github</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/hardening-javascript-apis-against-supply-chain-attacks-lessons-from-the-bajaj-auto-breach</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-28T00:00:00.000Z</news:publication_date>
      <news:title>Hardening JavaScript APIs Against Supply Chain Attacks: Lessons from the Bajaj Auto Breach</news:title>
      <news:keywords>javascript, api-security, supply-chain-security, cybersecurity</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/the-missing-authorization-check-behind-rony-dass-android-vulnerability-report</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-28T00:00:00.000Z</news:publication_date>
      <news:title>The Missing Authorization Check Behind Rony Das&apos;s Android Vulnerability Report</news:title>
      <news:keywords>android, cybersecurity, authorization, vulnerability, bug-bounty</news:keywords>
    </news:news>
  </url>
</urlset>
