<?xml version="1.0" encoding="UTF-8"?>
<urlset
  xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
  xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"
>
  <url>
    <loc>https://invaders.ie/resources/blog/vulnerability/one-click-githubdev-attack-lets-malicious-repos-steal-full-github-tokens</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-03T14:00:20.563Z</news:publication_date>
      <news:title>One-Click github.dev Attack Lets Malicious Repos Steal Full GitHub Tokens</news:title>
      <news:keywords>github.dev token stealing, VSCode webview vulnerability, GitHub OAuth token theft, one-click GitHub attack, developer security, malicious VSCode extension</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://invaders.ie/resources/blog/vulnerability/flagleft-turns-microsoft-365-android-apps-into-a-silent-account-takeover-path</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-03T04:24:18.207Z</news:publication_date>
      <news:title>FlagLeft Turns Microsoft 365 Android Apps Into a Silent Account Takeover Path</news:title>
      <news:keywords>FlagLeft Microsoft 365 Android, Microsoft 365 Android account takeover, FOCI token abuse, debug flag in production, Android token sharing vulnerability, silent Microsoft account takeover</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://invaders.ie/resources/blog/threat-hunting-and-intel/llmshare-turns-trusted-ai-domains-into-malware-delivery-infrastructure</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-03T04:12:35.469Z</news:publication_date>
      <news:title>LLMShare Turns Trusted AI Domains Into Malware Delivery Infrastructure</news:title>
      <news:keywords>LLMShare, ChatGPT malware delivery, Claude shared conversation malware, malvertising and SEO poisoning, trusted domain abuse, browser-based attacks</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://invaders.ie/resources/blog/vulnerability/drupal-postgresql-sqli-shows-how-select-only-injection-becomes-rce</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-03T03:55:50.185Z</news:publication_date>
      <news:title>Drupal PostgreSQL SQLi shows how SELECT-only injection becomes RCE</news:title>
      <news:keywords>CVE-2026-9082, Drupal PostgreSQL SQL injection, SELECT-only SQLi to RCE, Drupal JSON:API vulnerability, PostgreSQL session_preload_libraries exploit</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://invaders.ie/resources/blog/vulnerability/unfixed-gogs-flaw-can-turn-pull-requests-into-server-side-rce</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-06-02T08:09:14.454Z</news:publication_date>
      <news:title>Unfixed Gogs flaw can turn pull requests into server-side RCE</news:title>
      <news:keywords>Gogs authenticated RCE, Gogs argument injection, Rapid7 Gogs rebase vulnerability, self-hosted Git server security, Gogs no patch</news:keywords>
    </news:news>
  </url>
</urlset>