<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://threatfrontier.com/articles/claude-max-team-plans-monthly-api-credits-not-claude-code</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-08T02:53:21.790Z</news:publication_date>
      <news:title>Claude Max and Team Plans Now Include Monthly API Credits, but Claude Code Is Not Covered</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/claude-haiku-5-5-price-cut-real-cost-math-vs-haiku-4-5</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-08T02:49:33.040Z</news:publication_date>
      <news:title>Claude Haiku 5.5 is 90% cheaper per token, until a prompt crosses 100K</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/cisco-nexus-nx-os-ngoam-mpls-oam-nx-api-rce-cve-2026-76485</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-08T01:53:56.986Z</news:publication_date>
      <news:title>Three Unauthenticated Root RCEs Hit Cisco Nexus 3000 and 9000: Check Which Feature Is On</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/splunk-enterprise-patroni-rce-cve-2026-76268</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-08T01:50:09.670Z</news:publication_date>
      <news:title>Splunk Enterprise search head clusters exposed to critical unauthenticated RCE in Patroni API (CVE-2026-76268)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/lmcache-pickle-rce-cve-2026-105192-no-fix</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-08T01:44:20.879Z</news:publication_date>
      <news:title>LMCache CVE-2026-105192: Unauthenticated Pickle RCE in Multiprocess Mode, With No Fixed Release Yet</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/atlassian-data-center-unauthenticated-file-read-cve-2026-21589</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-07T11:10:27.591Z</news:publication_date>
      <news:title>Atlassian Patches Unauthenticated File Read CVE-2026-21589 Across Eight Data Center Products</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/fake-chatgpt-gemini-claude-muse-ad-portals-steal-ad-account-logins-mfa</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-07T10:30:58.564Z</news:publication_date>
      <news:title>Fake ChatGPT, Gemini, Claude and Muse ad portals use a fake browser window to steal ad-account logins</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/openai-notifies-100-organizations-misaligned-model-activity-what-defenders-should-check</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-07T10:14:24.643Z</news:publication_date>
      <news:title>OpenAI Notified 100+ Organizations About Model Activity: A Notice Is Not a Compromise</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/openai-api-usage-tiers-build-launch-grow-500-unlocks-200000</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-07T02:34:56.319Z</news:publication_date>
      <news:title>OpenAI Collapses API Usage Tiers From Five to Three: Grow Unlocks $200,000 a Month at $500</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/mcp-typescript-sdk-oauth-credential-leak-cve-2026-104850</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-07T01:31:14.240Z</news:publication_date>
      <news:title>MCP TypeScript SDK Lets a Malicious Server Pull OAuth Secrets From Clients (CVE-2026-104850)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/mistral-large-4-reduced-moderation-cyber-tier-82-percent-claim</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-06T14:31:34.998Z</news:publication_date>
      <news:title>Mistral Large 4 preview ships a reduced-moderation cyber tier, and Artificial Analysis lists its 82% as the top score</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/nextchat-proxy-ssrf-cve-2026-105238-no-patched-release</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-06T14:03:13.090Z</news:publication_date>
      <news:title>NextChat proxy fallback lets unauthenticated callers make the server fetch any URL (CVE-2026-105238)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://threatfrontier.com/articles/dify-cve-2026-105762-unauthenticated-ssrf-remote-files-upload</loc>
    <news:news>
      <news:publication>
        <news:name>ThreatFrontier.com</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-06T13:33:25.678Z</news:publication_date>
      <news:title>Dify CVE-2026-105762: Unauthenticated SSRF in Remote-File Upload Reaches Internal Services and Cloud Metadata</news:title>
    </news:news>
  </url>
</urlset>
