<?xml version="1.0" encoding="UTF-8"?>
<!--generator='jetpack-16.3-a.1'-->
<!--Jetpack_Sitemap_Buffer_News_XMLWriter-->
<?xml-stylesheet type="text/xsl" href="//sra.io/news-sitemap.xsl"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd">
 <url>
  <loc>https://opensourcemalware.com/blog/introducing-weaselbiscuit#new_tab</loc>
  <lastmod>2026-09-18T19:14:47Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>🚩 WeaselBiscuit Infostealer Found in npm Packages With Suspected DPRK Links</news:title>
   <news:publication_date>2026-09-18T19:14:47Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://www.air.security/blog-posts/plugin4shell#new_tab</loc>
  <lastmod>2026-09-18T19:13:38Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>Plugin4Shell SHA Pinning Bypass Enables Zero Click RCE Across Major AI Coding Agents</news:title>
   <news:publication_date>2026-09-18T19:13:38Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://www.huntress.com/blog/new-settra-ransomware-variant#new_tab</loc>
  <lastmod>2026-09-18T19:12:19Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>🚩 Settra ransomware deploys MeshAgent for persistent access before encrypting systems and disrupting Windows recovery.</news:title>
   <news:publication_date>2026-09-18T19:12:19Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and#new_tab</loc>
  <lastmod>2026-09-17T18:50:16Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>🚩 APT36 deploys new Rust-based malware and file-stealing tools to target government and defense organizations and reach air-gapped networks.</news:title>
   <news:publication_date>2026-09-17T18:50:16Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf#new_tab</loc>
  <lastmod>2026-09-17T18:49:23Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>CISA Releases Cyber Decoy Guidance to Improve Detection of Lateral Movement and Living-Off-the-Land Activity</news:title>
   <news:publication_date>2026-09-17T18:49:23Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/#new_tab</loc>
  <lastmod>2026-09-17T18:48:09Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>🚩 NightEagle APT Expands to Russian Targets Using GhostContainer Backdoor and RDP Tunneling</news:title>
   <news:publication_date>2026-09-17T18:48:09Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
</urlset>
