<?xml version="1.0" encoding="UTF-8"?>
<urlset
  xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
  xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"
>
  <url>
    <loc>https://invaders.ie/resources/blog/vulnerability/cve-2026-33032-nginx-ui-mcp-server-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-04-27T08:03:32.709Z</news:publication_date>
      <news:title>CVE-2026-33032 lets attackers take over exposed nginx-ui servers</news:title>
      <news:keywords>CVE-2026-33032, nginx-ui vulnerability, MCP auth bypass, nginx server takeover, reverse proxy security, active exploitation</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://invaders.ie/resources/blog/threat-hunting-and-intel/firestarter-leaves-patched-cisco-firewalls-at-continued-risk</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-04-26T08:05:02.570Z</news:publication_date>
      <news:title>Firestarter leaves patched Cisco firewalls at continued risk</news:title>
      <news:keywords>Firestarter Cisco firewall persistence, Cisco Firepower Firestarter malware, ArcaneDoor UAT-4356 persistence, Cisco ASA FTD post patch compromise, CISA Firestarter backdoor guidance</news:keywords>
    </news:news>
  </url>
</urlset>