<?xml version="1.0" encoding="UTF-8"?>
<!--generator='jetpack-16.3-a.7'-->
<!--Jetpack_Sitemap_Buffer_News_XMLWriter-->
<?xml-stylesheet type="text/xsl" href="//sra.io/news-sitemap.xsl"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd">
 <url>
  <loc>https://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/#new_tab</loc>
  <lastmod>2026-10-02T20:02:36Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>GitLab Patches Critical AI Gateway CVE-2026-90970 Enabling Arbitrary Command Execution</news:title>
   <news:publication_date>2026-10-02T20:02:36Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure#new_tab</loc>
  <lastmod>2026-10-02T19:58:57Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>🚩 Warlock Ransomware Uses SharePoint Exploitation, BYOVD, and SYSVOL for Domain-Wide Deployment</news:title>
   <news:publication_date>2026-10-02T19:58:57Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://fortiguard.fortinet.com/psirt/FG-IR-26-175#new_tab</loc>
  <lastmod>2026-10-02T19:57:19Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>🚩 Fortinet Warns of Critical, Actively Exploited FortiMail Path Traversal Vulnerability Allowing Unauthenticated File Writes.</news:title>
   <news:publication_date>2026-10-02T19:57:19Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sra.io/wp-content/uploads/2026/10/TB20261002-NetScaler-ZeroDays-CVE-2026-88771-and-CVE-2026-88772-.pdf#new_tab</loc>
  <lastmod>2026-10-02T21:46:00Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>TB20261002 - NetScaler ZeroDays (CVE-2026-88771 and CVE-2026-88772)</news:title>
   <news:publication_date>2026-10-02T19:46:46Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/#new_tab</loc>
  <lastmod>2026-10-01T19:46:15Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>🚩 NetScaler Zero Days Exploited in the Wild to Deploy Web Shells on ADC and Gateway Appliances</news:title>
   <news:publication_date>2026-10-01T19:46:15Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://blog.sucuri.net/2026/09/sc-wordpress-malware-a-self-healing-mesh-of-loaders-drop-ins-and-a-blockchain-controlled-backdoor.html#new_tab</loc>
  <lastmod>2026-10-01T19:45:19Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>SC WordPress Malware Uses Self-Healing Component Mesh and Blockchain-Based Command and Control</news:title>
   <news:publication_date>2026-10-01T19:45:19Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/#new_tab</loc>
  <lastmod>2026-10-01T19:44:27Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>🚩 Threat Actors Exploit CVE-2026-73570 for Unauthenticated Command Execution Against Internet-facing Zimbra Mail Servers.</news:title>
   <news:publication_date>2026-10-01T19:44:27Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
</urlset>
