<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://threatfrontier.com/articles/windows-cross-device-cve-2026-66804-system-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:31:20.872Z</news:publication_date>
      <news:title>Windows Cross Device flaw gives local users SYSTEM, with a public PoC</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/storm-3168-azure-service-principal-github-issue-7-minute-wipe</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:29:13.494Z</news:publication_date>
      <news:title>Storm-3168: A Secret Left in a GitHub Issue Led to a 7-Minute Azure Deletion Run</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/vllm-nixl-mooncake-kv-connector-dos-cve-2026-94622</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:28:35.735Z</news:publication_date>
      <news:title>vLLM NIXL and Mooncake Flaws Let One Request Kill Decode Engines, With No Fixed Release Named</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/open-webui-0-11-4-19-advisories-session-token-theft</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:28:33.493Z</news:publication_date>
      <news:title>Open WebUI 0.11.4 Patches 19 Advisories, Including Session Token Theft</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/arista-velocloud-orchestrator-cve-2026-93952-exploited-no-fix-for-6-1-and-7-0</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:28:31.095Z</news:publication_date>
      <news:title>Arista VeloCloud Orchestrator Exploited at CVSS 10.0, With No Fix Listed for Two Release Trains</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/claude-desktop-cowork-macos-command-execution-ghsa-v234-4jrq-mgg6</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:27:46.911Z</news:publication_date>
      <news:title>Claude Desktop Cowork Folder Flaw Let a File Run Commands on macOS</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/adobe-commerce-magento-cve-2026-71362-kev-authorization-flaw</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:27:44.564Z</news:publication_date>
      <news:title>Adobe Commerce and Magento Authorization Flaw CVE-2026-71362 Now Exploited</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/litellm-salt-key-ghsa-7hp6-4w63-5g45-proxy-admin-rce</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:27:41.317Z</news:publication_date>
      <news:title>LiteLLM Salt-Key Flaw Lets Any Internal User Forge a Proxy Admin Token and Run Commands</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/oracle-peoplesoft-cve-2026-35273-shinyhunters-waf-bypass-exploited</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:27:39.028Z</news:publication_date>
      <news:title>ShinyHunters Exploits Oracle PeopleSoft CVE-2026-35273 via WAF Bypass</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/gemini-3-8-flash-tts-pricing-doubles-january-2027</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:27:31.798Z</news:publication_date>
      <news:title>Gemini 3.8 TTS Pricing Doubles on Jan 1, 2027: What Voice-App Builders Should Budget</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/coding-agents-tamper-with-own-traces-audit-logs</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:27:11.665Z</news:publication_date>
      <news:title>Coding Agents Can Erase Their Own Audit Trails, and Auto-Mode Monitors Often Miss It</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/zyxel-gs1900-cve-2026-7273-kev-switch-exploitation</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:25:44.708Z</news:publication_date>
      <news:title>Zyxel GS1900 switch overflow exploited on 996 devices, now in CISA KEV</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/microsoft-sharepoint-cve-2026-65660-cisa-kev-rescored-rce</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:25:41.975Z</news:publication_date>
      <news:title>Microsoft SharePoint CVE-2026-65660 Added to CISA KEV After Rescore to RCE</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/cloudflare-clef-decision-models-ollama-systemone</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:25:38.757Z</news:publication_date>
      <news:title>Cloudflare Open-Sources Clef Decision Models as Ollama Adds a Decision-Model API</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/agentxploit-autonomous-red-teaming-ai-agent-frameworks</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:25:37.110Z</news:publication_date>
      <news:title>AgentXploit Rediscovers Known Agent-Framework Flaws 59% of the Time, Beating Codex at 38%</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/salesbleed-salesforce-agentforce-zero-click-dns-exfiltration</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:25:35.236Z</news:publication_date>
      <news:title>SalesBleed: A Public Web Form Let Attackers Pull Agentforce CRM Data Out Over DNS</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/vllm-0-30-upgrade-notes-fast-start-hisparse-breaking-changes</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:25:00.126Z</news:publication_date>
      <news:title>vLLM v0.30.0 Upgrade Notes: Fast Start, HiSparse, New Models and the Breaking Changes</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/anthropic-glm-5-3-open-weight-exploit-development-safeguards</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:22:31.811Z</news:publication_date>
      <news:title>Anthropic: Open-Weight GLM-5.3 Nearly Matches Mythos Preview at Writing Exploits</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/california-sb-1000-ai-transparency-act-no-robo-bosses-sb-947</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T19:22:29.628Z</news:publication_date>
      <news:title>California Drops the 1M-User Threshold From Its AI Transparency Act and Signs No Robo Bosses</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/minimax-m3-1-flash-preview-1m-context-coding-model</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T17:04:56.671Z</news:publication_date>
      <news:title>MiniMax M3.1 Flash: 1M-Context Coding Model That Always Thinks</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/claude-code-mods-unsandboxed-plugins-on-by-default</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T16:37:51.617Z</news:publication_date>
      <news:title>Claude Code Mods Are On by Default, and They Run Unsandboxed With Your Permissions</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/wso2-api-manager-cve-2026-5430-jwt-bypass-exploited</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:06:11.824Z</news:publication_date>
      <news:title>WSO2 API Manager JWT Bypass Exploited 133 Days After the Fix</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/mythos-rejetto-hfs-cve-2026-61500-math-random-admin-cookie</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:06:09.858Z</news:publication_date>
      <news:title>Mythos Cracked Rejetto HFS Sessions From 12 Leaked Math.random() Values</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/f5-big-ip-apm-cve-2026-94127-unauthenticated-rce</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:06:07.265Z</news:publication_date>
      <news:title>F5 BIG-IP APM: An Oversized Bearer Token Is Enough for Unauthenticated RCE</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/apple-coregraphics-zero-day-cve-2026-86950</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:06:02.570Z</news:publication_date>
      <news:title>Apple Patches CoreGraphics Zero-Day Used Against Targeted iPhone Users</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/ollama-agent-mode-cve-2026-102697-approval-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:06:00.441Z</news:publication_date>
      <news:title>Ollama&apos;s Agent Mode Approved Bash Commands by Prefix, So Prompt Injection Could Chain Its Own (CVE-2026-102697)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/wordpress-core-cve-2026-87902-path-traversal-rce-exploited</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:58.661Z</news:publication_date>
      <news:title>WordPress Core Flaw CVE-2026-87902 Drew Exploit Attempts on Patch Day</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/check-point-cve-2026-93616-cve-2026-85102-exploited</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:56.909Z</news:publication_date>
      <news:title>Check Point Management Servers Were a Zero-Day for Two Months Before the Fix</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/mcp-atlassian-cve-2026-77244-unauthenticated-operator-access</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:55.155Z</news:publication_date>
      <news:title>MCP Atlassian Server Let Anyone on the Network Act as the Operator in Jira and Confluence</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/cisco-sd-wan-manager-cve-2026-76504-hex-encoding-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:52.832Z</news:publication_date>
      <news:title>Cisco SD-WAN Manager Zero-Day CVE-2026-76504: One Encoded Character Unlocks the Admin API</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/fortimail-cve-2026-104286-exploited-no-patch</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:50.188Z</news:publication_date>
      <news:title>Exploited FortiMail Flaw Has No Patch Yet: Disable IBE Now</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/citrix-netscaler-zero-days-cve-2026-88771-cve-2026-88772</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:45.080Z</news:publication_date>
      <news:title>Citrix NetScaler Zero-Days Planted Webshells Weeks Before the Patch</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/memtensor-openclaw-plugin-memoryos-sckit-worm</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:42.195Z</news:publication_date>
      <news:title>MemTensor&apos;s OpenClaw Plugin and MemoryOS Shipped the sckit Credential Worm</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/stolen-chatgpt-logins-358-of-482-companies-socradar</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:39.887Z</news:publication_date>
      <news:title>Stolen ChatGPT Logins Turned Up at 358 of 482 Big Companies</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/xing4-0-29b-a4b-china-telecom-swe-bench-coding-model</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:36.258Z</news:publication_date>
      <news:title>Xing4.0-29B-A4B: China Telecom&apos;s Open Coding Model Claims SWE-bench 75 on One GPU</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/github-copilot-retires-six-models-october-19</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:33.050Z</news:publication_date>
      <news:title>GitHub Copilot Drops Six Models on Oct 19: What Replaces GPT-5.5, GPT-5.4 and Grok 4.5</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/openai-moonshot-encrypted-reasoning-replay-distillation</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:30.800Z</news:publication_date>
      <news:title>OpenAI Says Moonshot-Linked Accounts Replayed Encrypted Reasoning to Distill Its Models</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/carbonato-botnet-docker-hermes-agent-ai-api-keys</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:29.029Z</news:publication_date>
      <news:title>CARBONATO Botnet Turns Exposed Docker Hosts Into Hermes Agent Bots That Hunt AI Keys</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/pixelleak-ai-coding-agents-leaked-13000-screenshots-to-public-github</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:27.280Z</news:publication_date>
      <news:title>PixelLeak: AI Coding Agents Pushed 13,000 Internal Screenshots to Public GitHub Repos</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/openai-pauses-tool-use-after-training-agent-escaped-through-dns</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:25.441Z</news:publication_date>
      <news:title>OpenAI Pauses Tool Use on Its Most Capable Models After a Training Agent Escaped Through DNS</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/plugin4shell-pinned-sha-bypass-claude-code-codex-copilot-gemini-cli</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:23.446Z</news:publication_date>
      <news:title>Plugin4Shell: A Pinned Commit SHA Didn&apos;t Stop Repo Owners Swapping Plugin Code in Claude Code, Codex, Copilot and Gemini CLI</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/claude-sonnet-4-5-retirement-sonnet-5-5-migration</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T12:05:20.490Z</news:publication_date>
      <news:title>Claude Sonnet 4.5 Retires Nov 30: Six Requests That Return a 400 on Sonnet 5.5</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/mcp-python-sdk-oauth-credential-theft-issuer-fix</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T11:33:51.820Z</news:publication_date>
      <news:title>Official MCP Python SDK Let Malicious Servers Steal OAuth Secrets, and Upgrading Isn&apos;t Enough</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/ai-agent-breaches-divd-zammad-zero-days</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T11:33:33.999Z</news:publication_date>
      <news:title>AI Agent Breached Bug-Hunting Nonprofit DIVD by Chaining Two Zammad Zero-Days</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/tensorfold-local-llm-server-unauthenticated-api</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T18:56:36.421Z</news:publication_date>
      <news:title>TensorFold Speeds Up Local LLMs but Leaves Its API Unauthenticated</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/gemini-4-argon-vs-gpt-6-astra-vs-claude-opus-5-5</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T06:02:39.034Z</news:publication_date>
      <news:title>Gemini 4 Argon vs GPT-6 Astra vs Claude Opus 5.5: Is Google&apos;s New Model Actually Better?</news:title>
    </news:news>
  </url>
</urlset>
