<?xml version="1.0" encoding="UTF-8"?>
<!--generator='jetpack-15.8-a.7'-->
<!--Jetpack_Sitemap_Buffer_News_XMLWriter-->
<?xml-stylesheet type="text/xsl" href="//sra.io/news-sitemap.xsl"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd">
 <url>
  <loc>https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.aikido.dev%2Fblog%2Fmini-shai-hulud-has-appeared&amp;#038;data=05%7C02%7Ckimberly.kaleta%40sra.io%7C05aef8b9934c4aa060b308dea6ea2aae%7C9bdee6ea21c54c1ca6c941dc3d08c310%7C0%7C0%7C639131721895179313%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;#038;sdata=L0%2FKYhGKo0HdUznlb1yfYApijjNURNQqde3zkVK%2Ffco%3D&amp;#038;reserved=0#new_tab</loc>
  <lastmod>2026-04-30T20:42:54Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>🚩Malicious npm Packages Target SAP Developer Ecosystem with Credential-Stealing Supply Chain Attack</news:title>
   <news:publication_date>2026-04-30T20:42:54Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fxint.io%2Fblog%2Fcopy-fail-linux-distributions&amp;#038;data=05%7C02%7Ckimberly.kaleta%40sra.io%7C7a4f59d77df248753e0408dea6ea2e49%7C9bdee6ea21c54c1ca6c941dc3d08c310%7C0%7C0%7C639131721878631145%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;#038;sdata=CCWdHeUyAoV5CFeqkTafoRZSxML5fovDzB17DBhw7Kc%3D&amp;#038;reserved=0#new_tab</loc>
  <lastmod>2026-04-30T20:41:16Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>Nine-Year-Old Linux Kernel Flaw Grants Unprivileged Users Full Root Access</news:title>
   <news:publication_date>2026-04-30T20:41:16Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.securonix.com%2Fblog%2Fdeepdoor-python-backdoor-and-credential-stealer%2F&amp;#038;data=05%7C02%7Ckimberly.kaleta%40sra.io%7C80d3e11f646c4839a59208dea6ea2c58%7C9bdee6ea21c54c1ca6c941dc3d08c310%7C0%7C0%7C639131721872118893%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;#038;sdata=DpRgW9C586eP0U4kTvzuOLQBv0X4uuqhmHo9yKY6O9I%3D&amp;#038;reserved=0#new_tab</loc>
  <lastmod>2026-04-30T20:40:23Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>🚩Deep#Door Python RAT Uses Self-Contained Loader and Tunneling C2 to Evade Detection and Enable Full-System Surveillance</news:title>
   <news:publication_date>2026-04-30T20:40:23Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fsecurity%2Fblog%2F2026%2F04%2F28%2Fsimplifying-aws-defense-microsoft-sentinel-ueba%2F&amp;#038;data=05%7C02%7Ckimberly.kaleta%40sra.io%7C3004358d52bb4637d3fe08dea623331e%7C9bdee6ea21c54c1ca6c941dc3d08c310%7C0%7C0%7C639130867319094928%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;#038;sdata=7yg4fUbyvkYprshlBgbOUfBIfWqsZMndW%2B%2Bc4WoOC5Q%3D&amp;#038;reserved=0#new_tab</loc>
  <lastmod>2026-04-29T19:20:12Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>Microsoft Sentinel UEBA Adds Behavioral Context to AWS CloudTrail Activity to Improve Detection of Suspicious Identity, Privilege, and Data-Access Patterns</news:title>
   <news:publication_date>2026-04-29T19:20:12Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.sysdig.com%2Fblog%2Fcve-2026-42208-targeted-sql-injection-against-litellms-authentication-path-discovered-36-hours-following-vulnerability-disclosure&amp;#038;data=05%7C02%7Ckimberly.kaleta%40sra.io%7Cc07caa96426549a7bdaa08dea62334da%7C9bdee6ea21c54c1ca6c941dc3d08c310%7C0%7C0%7C639130867318775015%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;#038;sdata=CrKE8fiP34P0IG3sgtVUolJ2b79i3FVAiD0zKOhpKiE%3D&amp;#038;reserved=0#new_tab</loc>
  <lastmod>2026-04-29T19:19:18Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>🚩Critical Pre-Auth SQL Injection in LiteLLM Exposes AI Gateway Credentials Within 36 Hours of Disclosure</news:title>
   <news:publication_date>2026-04-29T19:19:18Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.cyera.com%2Fresearch%2Fsplitsshell-when-a-comma-becomes-root-how-a-single-character-broke-openssh-certificate-authentication&amp;#038;data=05%7C02%7Ckimberly.kaleta%40sra.io%7Cc35e8e5d0ba249a7aaea08dea6233221%7C9bdee6ea21c54c1ca6c941dc3d08c310%7C0%7C0%7C639130867256096873%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;#038;sdata=Fai4T3OnCXzzhqiOv6nIdBh7SBoK9wOz8NaLLqc3zW0%3D&amp;#038;reserved=0#new_tab</loc>
  <lastmod>2026-04-29T19:18:21Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Security Risk Advisors</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>OpenSSH Certificate Bug Allows CA-Signed SSH Certificates to Be Interpreted as Root Access via Principal Parsing Error (CVE-2026-35414)</news:title>
   <news:publication_date>2026-04-29T19:18:21Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
</urlset>