<?xml version="1.0" encoding="UTF-8"?>
<urlset
  xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
  xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"
>
  <url>
    <loc>https://invaders.ie/resources/blog/threat-hunting-and-intel/glassworm-takedown-shows-how-developer-malware-becomes-supply-chain-risk</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-05-30T08:06:32.763Z</news:publication_date>
      <news:title>GlassWorm takedown shows how developer malware becomes supply-chain risk</news:title>
      <news:keywords>GlassWorm botnet takedown, developer supply chain attack, OpenVSX malware campaign, GitHub credential theft malware, Solana command and control malware, developer workstation supply chain risk</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://invaders.ie/resources/blog/supply-chain-security/github-ghes-signing-key-rotation-puts-admins-on-the-clock</loc>
    <news:news>
      <news:publication>
        <news:name>Invaders Security</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-05-29T08:06:36.477Z</news:publication_date>
      <news:title>GitHub GHES Signing Key Rotation Puts Admins on the Clock</news:title>
      <news:keywords>GitHub Enterprise Server signing key rotation, GHES GPG key rotation, GitHub internal repository breach, software update trust chain, developer security</news:keywords>
    </news:news>
  </url>
</urlset>