<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/ai-security-tool-unearths-two-year-old-redis-flaw-that-allows-full-server-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-03T00:00:00.000Z</news:publication_date>
      <news:title>AI Security Tool Unearths Two-Year-Old Redis Flaw That Allows Full Server Takeover</news:title>
      <news:keywords>redis, security, vulnerability-management, ai-security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-github-oauth-implementations-for-single-click-token-exposure</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-03T00:00:00.000Z</news:publication_date>
      <news:title>Auditing GitHub OAuth Implementations for Single-Click Token Exposure</news:title>
      <news:keywords>github, oauth, security, tokens</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/countering-ai-driven-attacks-with-exposure-management-developer-takeaways</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-03T00:00:00.000Z</news:publication_date>
      <news:title>Countering AI-Driven Attacks with Exposure Management: Developer Takeaways</news:title>
      <news:keywords>cybersecurity, ai-security, exposure-management, devsecops</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/dissecting-the-githubdev-vulnerability-that-leaks-oauth-tokens-in-one-click</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-03T00:00:00.000Z</news:publication_date>
      <news:title>Dissecting the GitHub.dev Vulnerability That Leaks OAuth Tokens in One Click</news:title>
      <news:keywords>github, oauth, vulnerability, web-security, cybersecurity</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/hardening-windows-against-search-uri-ntlmv2-credential-theft</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-03T00:00:00.000Z</news:publication_date>
      <news:title>Hardening Windows Against Search URI NTLMv2 Credential Theft</news:title>
      <news:keywords>windows-security, ntlmv2, credential-theft, hardening, vulnerability</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/when-attackers-use-ai-to-evade-edr-hardening-build-agents-against-lateral-movement</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-03T00:00:00.000Z</news:publication_date>
      <news:title>When Attackers Use AI to Evade EDR: Hardening Build Agents Against Lateral Movement</news:title>
      <news:keywords>cybersecurity, active-directory, edr, build-agents, lateral-movement</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/defensive-lessons-from-the-android-exploit-chain-that-achieved-device-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-02T00:00:00.000Z</news:publication_date>
      <news:title>Defensive Lessons from the Android Exploit Chain That Achieved Device Takeover</news:title>
      <news:keywords>android, zero-day, mobile-security, exploit-chain</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/dissecting-the-red-hat-npm-supplychain-attack-from-malicious-package-to-credential-exposure</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-02T00:00:00.000Z</news:publication_date>
      <news:title>Dissecting the Red Hat npm Supply‑Chain Attack: From Malicious Package to Credential Exposure</news:title>
      <news:keywords>supply-chain-security, npm, credential-theft, red-hat, malware-analysis</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/how-the-claude-code-github-actions-flaw-can-compromise-your-repo-and-what-to-change-in-your-workflows</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-02T00:00:00.000Z</news:publication_date>
      <news:title>How the Claude Code GitHub Actions Flaw Can Compromise Your Repo and What to Change in Your Workflows</news:title>
      <news:keywords>github-actions, claude-code, supply-chain-security, devsecops</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/june-2026s-actively-exploited-android-flaw-practical-remediation-for-developers</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-02T00:00:00.000Z</news:publication_date>
      <news:title>June 2026’s Actively Exploited Android Flaw: Practical Remediation for Developers</news:title>
      <news:keywords>android, mobile-security, vulnerability-management, patch-management</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/kernel-privilege-escalation-on-android-a-practical-detection-playbook</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-02T00:00:00.000Z</news:publication_date>
      <news:title>Kernel Privilege Escalation on Android: A Practical Detection Playbook</news:title>
      <news:keywords>android, kernel, privilege-escalation, threat-detection, mobile-security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/the-cve-2024-21182-weblogic-t3-exploit-from-kev-listing-to-patch-verification-for-java-teams</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-02T00:00:00.000Z</news:publication_date>
      <news:title>The CVE-2024-21182 WebLogic T3 Exploit: From KEV Listing to Patch Verification for Java Teams</news:title>
      <news:keywords>oracle-weblogic, cve-2024-21182, t3-protocol, kev-listing, patch-verification</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/the-two-year-old-weblogic-flaw-cisa-is-flagging-cve-2023-21839-detection-and-defense</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-02T00:00:00.000Z</news:publication_date>
      <news:title>The Two-Year-Old WebLogic Flaw CISA Is Flagging: CVE-2023-21839 Detection and Defense</news:title>
      <news:keywords>oracle-weblogic, cve-2023-21839, cisa, vulnerability-detection</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/what-the-red-hat-redhat-cloud-services-incident-means-for-your-npm-supply-chain</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-02T00:00:00.000Z</news:publication_date>
      <news:title>What the Red Hat @redhat-cloud-services Incident Means for Your npm Supply Chain</news:title>
      <news:keywords>npm, supply-chain-security, red-hat, package-integrity</news:keywords>
    </news:news>
  </url>
</urlset>
