<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://threatfrontier.com/articles/langflow-mcp-stdio-cve-2026-105697-cve-2026-105740-rce</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-06T01:42:20.455Z</news:publication_date>
      <news:title>Langflow MCP Stdio Flaws Give Any Logged-In User a Shell: CVE-2026-105697 and CVE-2026-105740</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/sagemaker-distribution-cve-2026-104019-startup-script-injection</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T09:33:06.466Z</news:publication_date>
      <news:title>AWS Patches Critical SageMaker Distribution Flaw That Lets a Project Contributor Hijack Another User&apos;s Studio Space</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/aws-loom-cve-2026-103956-no-idp-admin-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T09:24:03.268Z</news:publication_date>
      <news:title>AWS fixes Loom flaw that gave any network client admin rights on deployments without an identity provider</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/mindsearch-planner-agent-code-injection-cve-2026-105135</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T01:41:12.384Z</news:publication_date>
      <news:title>MindSearch code-injection flaw (CVE-2026-105135) has a public PoC and no fix</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/citrix-netscaler-saml-cve-2026-88779-kev</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T01:32:28.753Z</news:publication_date>
      <news:title>Citrix NetScaler SAML Memory Flaw CVE-2026-88779 Added to CISA KEV, and Last Month&apos;s Patch Does Not Cover It</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/github-copilot-business-enterprise-upfront-seat-billing-october-1</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-04T07:10:05.451Z</news:publication_date>
      <news:title>GitHub Copilot Business and Enterprise Now Bill Seats Upfront: What Changed on Oct 1</news:title>
    </news:news>
  </url>
</urlset>
