<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://threatfrontier.com/articles/sagemaker-distribution-cve-2026-104019-startup-script-injection</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T09:33:06.466Z</news:publication_date>
      <news:title>AWS Patches Critical SageMaker Distribution Flaw That Lets a Project Contributor Hijack Another User&apos;s Studio Space</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/aws-loom-cve-2026-103956-no-idp-admin-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T09:24:03.268Z</news:publication_date>
      <news:title>AWS fixes Loom flaw that gave any network client admin rights on deployments without an identity provider</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/mindsearch-planner-agent-code-injection-cve-2026-105135</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T01:41:12.384Z</news:publication_date>
      <news:title>MindSearch code-injection flaw (CVE-2026-105135) has a public PoC and no fix</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/citrix-netscaler-saml-cve-2026-88779-kev</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T01:32:28.753Z</news:publication_date>
      <news:title>Citrix NetScaler SAML Memory Flaw CVE-2026-88779 Added to CISA KEV, and Last Month&apos;s Patch Does Not Cover It</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/github-copilot-business-enterprise-upfront-seat-billing-october-1</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-04T07:10:05.451Z</news:publication_date>
      <news:title>GitHub Copilot Business and Enterprise Now Bill Seats Upfront: What Changed on Oct 1</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/mcp-fetch-server-ssrf-cve-2026-104120-no-fix</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-04T02:00:31.924Z</news:publication_date>
      <news:title>MCP Fetch Server SSRF (CVE-2026-104120) Has a Public Exploit and No Fix</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/n8n-redis-write-access-npm-package-install-cve-2026-103251</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-04T01:49:10.120Z</news:publication_date>
      <news:title>n8n Queue Mode: Redis Write Access Can Install Any npm Package on Every Instance (CVE-2026-103251)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/langgraph-sdk-auth-bug-actions-ignored-on-auth-on-handlers-cve-2026-104873</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-04T01:45:20.059Z</news:publication_date>
      <news:title>LangGraph SDK Auth Bug: `actions=` Ignored on `@auth.on` Handlers (CVE-2026-104873)</news:title>
    </news:news>
  </url>
</urlset>
