<?xml version="1.0" encoding="UTF-8"?>
<urlset
  xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
  xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"
>
  <url>
    <loc>https://invaders.ie/resources/blog/supply-chain-attack/github-breach-forces-ghes-signing-key-rotation</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-04T08:06:43.819Z</news:publication_date>
      <news:title>GitHub breach forces GHES signing-key rotation</news:title>
      <news:keywords>GitHub internal repositories breach 2026, GitHub Enterprise Server signing key rotation, poisoned VS Code extension GitHub, developer tool supply chain risk, GHES signing key rotation May 2026</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://invaders.ie/resources/blog/vulnerability/one-click-githubdev-attack-lets-malicious-repos-steal-full-github-tokens</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-03T14:00:20.563Z</news:publication_date>
      <news:title>One-Click github.dev Attack Lets Malicious Repos Steal Full GitHub Tokens</news:title>
      <news:keywords>github.dev token stealing, VSCode webview vulnerability, GitHub OAuth token theft, one-click GitHub attack, developer security, malicious VSCode extension</news:keywords>
    </news:news>
  </url>
</urlset>