<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://threatfrontier.com/articles/sagemaker-distribution-cve-2026-104019-startup-script-injection</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T09:33:06.466Z</news:publication_date>
      <news:title>AWS Patches Critical SageMaker Distribution Flaw That Lets a Project Contributor Hijack Another User&apos;s Studio Space</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/aws-loom-cve-2026-103956-no-idp-admin-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T09:24:03.268Z</news:publication_date>
      <news:title>AWS fixes Loom flaw that gave any network client admin rights on deployments without an identity provider</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/mindsearch-planner-agent-code-injection-cve-2026-105135</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T01:41:12.384Z</news:publication_date>
      <news:title>MindSearch code-injection flaw (CVE-2026-105135) has a public PoC and no fix</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/citrix-netscaler-saml-cve-2026-88779-kev</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T01:32:28.753Z</news:publication_date>
      <news:title>Citrix NetScaler SAML Memory Flaw CVE-2026-88779 Added to CISA KEV, and Last Month&apos;s Patch Does Not Cover It</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/github-copilot-business-enterprise-upfront-seat-billing-october-1</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-04T07:10:05.451Z</news:publication_date>
      <news:title>GitHub Copilot Business and Enterprise Now Bill Seats Upfront: What Changed on Oct 1</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/mcp-fetch-server-ssrf-cve-2026-104120-no-fix</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-04T02:00:31.924Z</news:publication_date>
      <news:title>MCP Fetch Server SSRF (CVE-2026-104120) Has a Public Exploit and No Fix</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/n8n-redis-write-access-npm-package-install-cve-2026-103251</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-04T01:49:10.120Z</news:publication_date>
      <news:title>n8n Queue Mode: Redis Write Access Can Install Any npm Package on Every Instance (CVE-2026-103251)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/langgraph-sdk-auth-bug-actions-ignored-on-auth-on-handlers-cve-2026-104873</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-04T01:45:20.059Z</news:publication_date>
      <news:title>LangGraph SDK Auth Bug: `actions=` Ignored on `@auth.on` Handlers (CVE-2026-104873)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/best-10-dollar-open-model-coding-plan-october-2026</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-03T20:59:10.191Z</news:publication_date>
      <news:title>The $10 Open-Model Coding Plan in October 2026: Three Real Options, Six Near Misses, and the Math</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/vibe-trading-ai-agent-unauthenticated-rce-advisories-upgrade</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-03T12:15:20.889Z</news:publication_date>
      <news:title>Vibe-Trading AI Agent Flaws Chain an Open API to Root Code Execution</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/google-gtig-141-exploited-flaws-litellm-cve-2026-42271-langflow-cve-2026-5027</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-03T09:45:48.809Z</news:publication_date>
      <news:title>Google GTIG Counts 141 Exploited Flaws in 8 Months; Patch LiteLLM and Langflow First</news:title>
    </news:news>
  </url>
</urlset>
