<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/bragjack-and-the-missing-sender-validation-in-agent-bridges</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T00:00:00.000Z</news:publication_date>
      <news:title>BragJack and the Missing Sender Validation in Agent Bridges</news:title>
      <news:keywords>browser-extensions, ai-agents, web-security, postmessage, browser-security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/waterplums-fake-coding-test-how-a-node-take-home-became-a-persistent-rat</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T00:00:00.000Z</news:publication_date>
      <news:title>WaterPlum&apos;s Fake Coding Test: How a Node Take-Home Became a Persistent RAT</news:title>
      <news:keywords>security, malware, nodejs, devsecops, supply-chain</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/why-egress-allowlists-beat-policy-prompts-in-the-gemini-agent-breach</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T00:00:00.000Z</news:publication_date>
      <news:title>Why Egress Allowlists Beat Policy Prompts in the Gemini Agent Breach</news:title>
      <news:keywords>ai-agents, security, sandboxing, llm-guardrails, network-isolation</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/why-ephemeral-ci-runners-break-standard-kernel-patch-triage</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T00:00:00.000Z</news:publication_date>
      <news:title>Why Ephemeral CI Runners Break Standard Kernel Patch Triage</news:title>
      <news:keywords>linux-kernel, ci-cd, container-security, patch-management, privilege-escalation</news:keywords>
    </news:news>
  </url>
</urlset>
