<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://pulse.adyog.com/insights/wordpress-invoice-generator-unauthenticated-admin-cve-2026-12415</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-28</news:publication_date>
      <news:title>WordPress Invoice Generator: Unauthenticated Visitors Can Become Admin. CVSS 9.8. No Exploit Kit Required.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/post-mythos-ai-cybersecurity-keep-calm-wrong-answer</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-28</news:publication_date>
      <news:title>&quot;Keep Calm&quot; Is the Wrong Response to Mythos and GPT-5.6 Sol. Here's Why the Cybersecurity Industry Should Be Reorganizing.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/nodejs-tls-nul-byte-hostname-bypass-cve-2026-48930-cvss-dispute</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-28</news:publication_date>
      <news:title>Node.js TLS Hostname Bypass: NVD Says CVSS 9.8. HackerOne Says 5.6. Every Framework Built on Node Is Caught in the Middle.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/nezha-monitoring-pre-auth-config-leak-terminal-hijack-cvss-9-9</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-28</news:publication_date>
      <news:title>Nezha Monitoring: Pre-Auth Config Leak + Cross-Tenant Terminal Hijack. The Observability Pattern Continues.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/htmx-4-0-beta-anti-framework-reaches-version-parity</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-28</news:publication_date>
      <news:title>HTMX 4.0 Beta: The Anti-Framework Reaches Version Parity</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/gonic-arbitrary-file-write-self-hosted-app-authentication-not-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-28</news:publication_date>
      <news:title>Gonic Music Server: Any Logged-In User Can Write Arbitrary Files to the Host</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/django-ecosystem-three-tools-one-week-open-source-bet</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-28</news:publication_date>
      <news:title>Django's Open-Source Bet: When Paid Tools Go MIT</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/dan-abramov-nextjs-react-talent-consolidation-signal</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-28</news:publication_date>
      <news:title>React's Most Influential Voice Moves to Next.js</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/semantic-router-pth-file-persistence-ai-dependency-credential-theft</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-27</news:publication_date>
      <news:title>A Python .pth File Ran Before Import. AI Routing Library semantic-router Shipped Compromised Credentials Harvester.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/pnpm-8-cves-supply-chain-lockfile-exploit-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-27</news:publication_date>
      <news:title>pnpm Discloses 8 CVEs in One Day. Your Lockfile Is the Exploit.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/gpt-5-6-sol-government-gated-ai-export-controls-security</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-27</news:publication_date>
      <news:title>GPT-5.6 Sol Requires U.S. Government Approval to Access. AI Just Became Export-Controlled Infrastructure.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/fluentd-rce-tag-injection-cve-2026-44024-cvss-9-8-observability</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-27</news:publication_date>
      <news:title>Fluentd RCE via Tag Injection (CVE-2026-44024, CVSS 9.8): The Observability Stack Just Became the Attack Surface</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/cursor-ai-sandbox-escape-cvss-9-8-arbitrary-file-write</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-27</news:publication_date>
      <news:title>Cursor AI Editor: Two CVSS 9.8 Sandbox Escapes Let a Malicious Agent Write Anywhere on Disk</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/nextjs-163-instant-navigations-agent-skills</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>Next.js 16.3 Ships Agent Skills Alongside Instant Navigations</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/n8n-flowise-17-cves-mcp-endpoints-ai-infrastructure-attack-surface</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>17 Critical Vulnerabilities Hit n8n and Flowise. MCP Endpoints Are the Weakest Link in AI Infrastructure.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/mastra-npm-supply-chain-north-korea-sapphire-sleet-ai-framework</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>North Korea Hijacked an AI Agent Framework With 8M Weekly Downloads. It Took 88 Minutes.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/klue-breach-oauth-cascade-hackerone-snyk-recorded-future</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>The Cybersecurity Industry Got Breached Through a Sales Tool. OAuth Tokens Are the New Skeleton Keys.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/jwt-algorithm-confusion-flask-netflix-lemur</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>Netflix's Lemur Shows Why JWT Algorithm Pinning Is Non-Negotiable</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/i18next-prototype-pollution-translation-layer-npm-supply-chain</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>i18next Prototype Pollution: The Translation Layer Nobody Thought to Secure.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/gravity-smtp-wordpress-api-keys-leaked-17m-attacks</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>A Permission Callback That Returns True. 100,000 WordPress Sites Leaked Live API Keys. 17 Million Attacks Followed.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/gpt-55-cyber-ai-vulnerability-hunting-patch-the-planet</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>GPT-5.5-Cyber Scores 85.6% on Vulnerability Detection. Your Framework Just Got a New Dimension: AI-Defensibility.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/go-crypto-ssh-10-cves-cvss-10-infrastructure-crisis</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>Go's SSH Library Just Dropped 10 CVEs in One Day. One Is a Perfect 10.0.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/framework-velocity-june-2026-vue-angular-fastapi</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>Release Velocity This Week: Vue, Angular, and FastAPI All Ship</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/fortibleed-86000-devices-110m-credentials-perimeter-is-dead</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>FortiBleed: 86,000 Firewalls Compromised, 110 Million Credentials Harvested. Your Perimeter Just Became the Attack.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/difytap-dify-ai-platform-cross-tenant-data-exposure-cvss-9-4</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>DifyTap: The AI Platform Powering 1 Million Apps Was Leaking Private Chats Between Tenants. CVSS 9.4.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/cordyceps-cicd-300-repos-microsoft-google-supply-chain-hijack</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>Cordyceps: 300+ GitHub Repos at Microsoft, Google, Cloudflare Exploitable via CI/CD Flaws. Your Framework Is Only as Secure as Its Build Pipeline.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/cisco-sd-wan-seventh-zero-day-2026-cisa-kev-siege</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>Cisco SD-WAN Logs Its Seventh Zero-Day of 2026. CISA Deadlines Are Piling Up.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/autojack-one-web-page-hijacks-microsoft-autogen-ai-agent</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>AutoJack: An AI Agent Visited a Web Page. That Web Page Took Over the Machine.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://pulse.adyog.com/insights/akamai-api-security-87-percent-breached-visibility-collapsing</loc>
    <news:news>
      <news:publication>
        <news:name>adyog WebPulse</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-26</news:publication_date>
      <news:title>87% of Organisations Suffered an API Security Incident. The Worse Number Is the One That Went Down.</news:title>
    </news:news>
  </url>
</urlset>