<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/auditing-your-stripe-integration-for-c2-abuse-lessons-from-the-magecart-attack</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-05T00:00:00.000Z</news:publication_date>
      <news:title>Auditing Your Stripe Integration for C2 Abuse: Lessons from the Magecart Attack</news:title>
      <news:keywords>stripe, magecart, web-security, supply-chain-security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/defending-active-directory-service-accounts-against-automated-kerberoasting-a-lab-driven-guide</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-05T00:00:00.000Z</news:publication_date>
      <news:title>Defending Active Directory Service Accounts Against Automated Kerberoasting: A Lab-Driven Guide</news:title>
      <news:keywords>active-directory, kerberoasting, service-accounts, detection-engineering</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/making-patch-decisions-without-cve-severity-scores-june-2026-edition</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-05T00:00:00.000Z</news:publication_date>
      <news:title>Making Patch Decisions Without CVE Severity Scores: June 2026 Edition</news:title>
      <news:keywords>cybersecurity, patch-management, vulnerability-management, cve</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/nodejs-supply-chain-attack-tracing-the-bindinggyp-npm-compromise</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-05T00:00:00.000Z</news:publication_date>
      <news:title>Node.js Supply Chain Attack: Tracing the binding.gyp npm Compromise</news:title>
      <news:keywords>nodejs, npm, supply-chain-security, cybersecurity</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/virtual-patching-without-waiting-for-plugin-updates-inside-patchstacks-godaddy-partnership</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-05T00:00:00.000Z</news:publication_date>
      <news:title>Virtual Patching Without Waiting for Plugin Updates: Inside Patchstack’s GoDaddy Partnership</news:title>
      <news:keywords>cybersecurity, wordpress, virtual-patching, patchstack, godaddy</news:keywords>
    </news:news>
  </url>
</urlset>
