<?xml version="1.0" encoding="UTF-8"?>
<urlset
  xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
  xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"
>
  <url>
    <loc>https://invaders.ie/resources/blog/vulnerability/nginx-ui-cve-2026-33032-full-nginx-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-04-15T20:31:18.382Z</news:publication_date>
      <news:title>CVE-2026-33032 in nginx-ui Enables Full Nginx Server Takeover via Unauthenticated MCP Access</news:title>
      <news:keywords>nginx-ui, CVE-2026-33032, Authentication Bypass, Nginx, MCP, Server Takeover</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://invaders.ie/resources/blog/cloud-and-application-security/malicious-chrome-extensions-oauth-token-risk</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-04-15T08:06:03.540Z</news:publication_date>
      <news:title>Malicious Chrome extensions turn OAuth tokens into enterprise risk</news:title>
      <news:keywords>Chrome Web Store malicious extensions, OAuth token theft, browser security, credential theft, command and control, Google account abuse, browser extensions</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://invaders.ie/resources/blog/vulnerability/cve-2026-5194-wolfssl-certificate-trust-risk</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-04-14T08:05:04.421Z</news:publication_date>
      <news:title>CVE-2026-5194 weakens wolfSSL certificate trust in embedded deployments</news:title>
      <news:keywords>CVE-2026-5194, wolfSSL vulnerability, certificate validation flaw, embedded security, IoT TLS library, cryptography patching</news:keywords>
    </news:news>
  </url>
</urlset>