<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://plainsec.com/stories/656e9e57-fc96-477b-a13e-e4ad83dd6272/unc6240-bypasses-peoplesoft-waf-rules-again</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>ShinyHunters Reroute PeopleSoft Exploits Around WAFs</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/656e9e57-fc96-477b-a13e-e4ad83dd6272/unc6240-bypasses-peoplesoft-waf-rules-again</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Il bypass del WAF riapre la campagna su PeopleSoft</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/35ab93e1-9a0f-4c2d-8500-d4822c5a58b3/storm-3168-used-azure-identities-to-wreck-tenants</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T10:44:33Z</news:publication_date>
      <news:title>JadePuffer Starts Targeting Azure Recovery Paths</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/35ab93e1-9a0f-4c2d-8500-d4822c5a58b3/storm-3168-used-azure-identities-to-wreck-tenants</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T10:44:33Z</news:publication_date>
      <news:title>Azure, JadePuffer punta anche su backup e recovery</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/dd8bd376-1907-4786-8c76-38952ce33667/gitlab-path-traversal-puts-servers-at-risk</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>GitLab Flaw Hits KEV Under Active Exploitation</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/dd8bd376-1907-4786-8c76-38952ce33667/gitlab-path-traversal-puts-servers-at-risk</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>GitLab passa da advisory a emergenza operativa</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/933701a5-4ac7-42b1-bc8b-6ef288c2f65b/fbi-portal-breach-exposed-personnel-dossiers</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T20:58:37Z</news:publication_date>
      <news:title>FBI Portal Breach Exposed Personnel Dossiers</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/933701a5-4ac7-42b1-bc8b-6ef288c2f65b/fbi-portal-breach-exposed-personnel-dossiers</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T20:58:37Z</news:publication_date>
      <news:title>Dati FBI esposti, il rischio è sul personale</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/459db3dc-8d6e-4eb3-a699-f7f7a4415247/roundcube-flaw-turns-mail-logins-into-server-control</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Roundcube SQL Injection Hits Before Login</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/459db3dc-8d6e-4eb3-a699-f7f7a4415247/roundcube-flaw-turns-mail-logins-into-server-control</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Roundcube passa da abuso di account a compromissione pre-login</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/6bb28d12-5494-4e1c-b5f5-559dcc3ff947/team-cymru-finds-ai-proxy-layer-hiding-abuse-origins</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T16:29:59Z</news:publication_date>
      <news:title>Team Cymru Finds AI Proxy Layer Hiding Abuse Origins</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/6bb28d12-5494-4e1c-b5f5-559dcc3ff947/team-cymru-finds-ai-proxy-layer-hiding-abuse-origins</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T16:29:59Z</news:publication_date>
      <news:title>La proxy economy dell’AI nasconde l’origine degli abusi</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/a2b5d009-167e-441c-a8d1-edcacdf01869/openai-agents-crossed-into-public-web-traffic</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>OpenAI Agents Crossed Into Public Web Traffic</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/a2b5d009-167e-441c-a8d1-edcacdf01869/openai-agents-crossed-into-public-web-traffic</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Agenti OpenAI trasformano le eval in un rischio operativo</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/6b6348ca-ba20-472e-a045-0f023ed6324e/bitget-wallet-theft-exposes-custody-risk</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Bitget’s Backend Became the Thief</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/6b6348ca-ba20-472e-a045-0f023ed6324e/bitget-wallet-theft-exposes-custody-risk</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Bitget, il backend che approva i prelievi è stato tradito</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/c3e7e2c4-9bf8-4902-bb84-c79e36b3ff0c/shinyhunters-kept-going-after-dutch-arrest</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T20:58:37Z</news:publication_date>
      <news:title>ShinyHunters Kept Going After Dutch Arrest</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/c3e7e2c4-9bf8-4902-bb84-c79e36b3ff0c/shinyhunters-kept-going-after-dutch-arrest</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T20:58:37Z</news:publication_date>
      <news:title>L’arresto non ferma ShinyHunters, anzi accelera</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/4dec7c3d-6993-4424-a342-31260fde9394/upguard-finds-supabase-databases-exposing-user-data</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T20:58:37Z</news:publication_date>
      <news:title>UpGuard Finds Supabase Databases Exposing User Data</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/4dec7c3d-6993-4424-a342-31260fde9394/upguard-finds-supabase-databases-exposing-user-data</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T20:58:37Z</news:publication_date>
      <news:title>Migliaia di database Supabase restano pubblici per errore</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/d8541b5e-cc98-4380-a046-b13389151ac9/hugging-face-study-shows-agents-chain-access-into-lateral-movement</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Gemini Test Shows Prompts Don’t Stop Actions</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/d8541b5e-cc98-4380-a046-b13389151ac9/hugging-face-study-shows-agents-chain-access-into-lateral-movement</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>I prompt non bastano quando l’agente può agire</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/9982227b-5bb6-44f4-928e-914b2ba3ee04/carbonato-turns-exposed-docker-daemons-into-botnet-hosts</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T13:00:58Z</news:publication_date>
      <news:title>Carbonato Turns Exposed Docker Daemons into Botnet Hosts</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/9982227b-5bb6-44f4-928e-914b2ba3ee04/carbonato-turns-exposed-docker-daemons-into-botnet-hosts</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T13:00:58Z</news:publication_date>
      <news:title>Docker esposti trasformati in controllo remoto per botnet</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/0bfc92a0-bc14-45ac-addf-fe7decf9670a/infostealers-now-reach-developer-ai-sessions</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Infostealers Now Reach Developer AI Sessions</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/0bfc92a0-bc14-45ac-addf-fe7decf9670a/infostealers-now-reach-developer-ai-sessions</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Gli infostealer allargano il furto ai token degli assistant AI</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/e84514f7-5a34-4f6d-a7fc-a3a8fe0b246f/ncc-group-sees-record-august-ransomware-volume</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T10:44:33Z</news:publication_date>
      <news:title>NCC Group Sees Ransomware Shift Toward Industry</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/e84514f7-5a34-4f6d-a7fc-a3a8fe0b246f/ncc-group-sees-record-august-ransomware-volume</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T10:44:33Z</news:publication_date>
      <news:title>Qilin guida il picco ransomware e sposta il baricentro</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/d710f008-35b8-4b54-984b-66bc27ba98be/cisa-flags-certification-barriers-in-election-patching</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>CISA Flags Certification Barriers in Election Patching</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/d710f008-35b8-4b54-984b-66bc27ba98be/cisa-flags-certification-barriers-in-election-patching</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Piano CISA: la certificazione rallenta le patch</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/8fd0db4f-eecf-411a-9a86-132e1225b758/tdengine-flaw-can-drop-telemetry-visibility</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>TDengine Flaw Can Drop Telemetry Visibility</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/8fd0db4f-eecf-411a-9a86-132e1225b758/tdengine-flaw-can-drop-telemetry-visibility</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Un pacchetto basta a far cadere la telemetria industriale</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/6721938a-41a4-4c5c-96fc-0e4c5bf0b126/macsync-swaps-scripts-for-native-macos-binaries</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T06:50:54Z</news:publication_date>
      <news:title>MacSync Swaps Scripts for Native macOS Binaries</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/6721938a-41a4-4c5c-96fc-0e4c5bf0b126/macsync-swaps-scripts-for-native-macos-binaries</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T06:50:54Z</news:publication_date>
      <news:title>MacSync cambia pelle e sfugge ai controlli statici</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/9bf4a4f1-0261-4bde-835c-56ca45408401/file-notifications-leak-activity-across-user-accounts</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T14:43:30Z</news:publication_date>
      <news:title>File Notifications Leak Activity Across User Accounts</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/9bf4a4f1-0261-4bde-835c-56ca45408401/file-notifications-leak-activity-across-user-accounts</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T14:43:30Z</news:publication_date>
      <news:title>Le notifiche del sistema tradiscono l’attività tra account</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/b545f331-dfcc-4835-9739-282f12d2b0ba/cloudflare-fixed-cross-tenant-storage-leakage</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Cloudflare Fixed Cross-Tenant Storage Leakage</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/b545f331-dfcc-4835-9739-282f12d2b0ba/cloudflare-fixed-cross-tenant-storage-leakage</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Cloudflare chiude una falla che esponeva dati tra tenant</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/dc1d1abc-d61a-4bb5-9faa-a7d68bc0b8c9/microsoft-titan-token-check-opened-admin-sql-access</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T18:56:12Z</news:publication_date>
      <news:title>Microsoft Titan Token Check Opened Admin SQL Access</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/dc1d1abc-d61a-4bb5-9faa-a7d68bc0b8c9/microsoft-titan-token-check-opened-admin-sql-access</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T18:56:12Z</news:publication_date>
      <news:title>Un token falsificato apre l’admin su Titan</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/c5ac9382-9c99-4687-9728-c399cb4073f1/salesforce-agentforce-flaws-turn-leads-into-attackers</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T10:44:33Z</news:publication_date>
      <news:title>Salesforce Agentforce Flaws Turn Leads Into Attackers</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/c5ac9382-9c99-4687-9728-c399cb4073f1/salesforce-agentforce-flaws-turn-leads-into-attackers</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T10:44:33Z</news:publication_date>
      <news:title>Un lead pubblico diventa il canale di controllo di Agentforce</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/3316d19a-f376-4966-bb55-3e0207e11f8b/recorded-future-sees-russia-blending-cyber-and-physical-pressure</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Recorded Future Sees Russia Blending Cyber and Physical Pressure</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/3316d19a-f376-4966-bb55-3e0207e11f8b/recorded-future-sees-russia-blending-cyber-and-physical-pressure</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>La guerra ibrida russa si sposta su cyber, droni e disinformazione</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/f3e63b53-c0e1-4848-99da-a49cc8969a99/former-soldier-sentenced-in-carrier-credential-campaign</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T14:43:30Z</news:publication_date>
      <news:title>Former Soldier Sentenced in Carrier Credential Campaign</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/f3e63b53-c0e1-4848-99da-a49cc8969a99/former-soldier-sentenced-in-carrier-credential-campaign</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T14:43:30Z</news:publication_date>
      <news:title>Una condanna chiude una campagna di furto credenziali tra carrier</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/7e26529a-fe3e-46d2-b804-e007573e55ac/rydox-guilty-plea-confirms-a-disrupted-market</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Rydox Plea Confirms a Real Marketplace Takedown</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/7e26529a-fe3e-46d2-b804-e007573e55ac/rydox-guilty-plea-confirms-a-disrupted-market</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Rydox finisce in aula: il sequestro chiude il market</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/53596929-d845-44e4-be3c-643c2b7baf1d/fake-payroll-apps-hand-over-the-machine</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T10:44:33Z</news:publication_date>
      <news:title>Fake Payroll Apps Hand Over the Machine</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/53596929-d845-44e4-be3c-643c2b7baf1d/fake-payroll-apps-hand-over-the-machine</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T10:44:33Z</news:publication_date>
      <news:title>Un falso desktop per paghe apre la strada alla diversione degli stipendi</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/1afce114-55e0-4d4b-8bda-54a4a273dcc4/snowflake-credential-abuse-lands-soldier-70-month-sentence</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T08:21:22Z</news:publication_date>
      <news:title>Snowflake Case Ends With Sentence, Data Keeps Moving</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/1afce114-55e0-4d4b-8bda-54a4a273dcc4/snowflake-credential-abuse-lands-soldier-70-month-sentence</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T08:21:22Z</news:publication_date>
      <news:title>Snowflake e AT&amp;T, si chiude il caso del soldier hacker</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/7f25fb45-0c0c-4854-ada0-cff21e458c5e/gemini-test-escaped-into-real-company-systems</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Gemini Test Escaped Into Real Company Systems</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/7f25fb45-0c0c-4854-ada0-cff21e458c5e/gemini-test-escaped-into-real-company-systems</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T04:21:12Z</news:publication_date>
      <news:title>Gemini esce dal test e tocca sistemi reali</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/05dcb2d4-6ad3-4a82-a5b9-e2117715ed50/shinyhunters-hits-clops-leak-site-trust</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T06:50:54Z</news:publication_date>
      <news:title>ShinyHunters Raises the Cost of Cl0p's Leak-Site Breach</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/05dcb2d4-6ad3-4a82-a5b9-e2117715ed50/shinyhunters-hits-clops-leak-site-trust</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-28T06:50:54Z</news:publication_date>
      <news:title>La faida tra gang espone i pagamenti delle vittime Cl0p</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/0a9e31dc-2cf0-49cf-9de5-ba66ccd74868/lunex-uses-amd-driver-to-blind-edr</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-27T04:46:35Z</news:publication_date>
      <news:title>Lunex Uses AMD Driver to Blind EDR</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/0a9e31dc-2cf0-49cf-9de5-ba66ccd74868/lunex-uses-amd-driver-to-blind-edr</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-27T04:46:35Z</news:publication_date>
      <news:title>Lunex spegne i controlli kernel prima di rubare credenziali</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/8f8bafcd-b182-4bb6-a770-31d25dbf9e66/wraithtools-sells-botnet-to-drain-ai-credits</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-27T14:50:52Z</news:publication_date>
      <news:title>WraithTools Sells Botnet to Drain AI Credits</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/8f8bafcd-b182-4bb6-a770-31d25dbf9e66/wraithtools-sells-botnet-to-drain-ai-credits</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-27T14:50:52Z</news:publication_date>
      <news:title>Un botnet commerciale trasforma le API AI in una bolletta</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/777533ba-ab4e-4e42-9c0c-07578368f8e2/elementor-csrf-lets-attackers-mint-wordpress-admins</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-27T12:54:18Z</news:publication_date>
      <news:title>Elementor CSRF Lets Attackers Mint WordPress Admins</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/777533ba-ab4e-4e42-9c0c-07578368f8e2/elementor-csrf-lets-attackers-mint-wordpress-admins</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-27T12:54:18Z</news:publication_date>
      <news:title>Elementor crea admin finti e tiene aperta la porta</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/bb7a3201-07b7-4aae-ab88-b2bf36fc6252/remcontrol-uses-iptv-ads-to-reach-android-users</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T10:21:17Z</news:publication_date>
      <news:title>RemControl Uses Fake TVTap to Disarm Android Safety Checks</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/bb7a3201-07b7-4aae-ab88-b2bf36fc6252/remcontrol-uses-iptv-ads-to-reach-android-users</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T10:21:17Z</news:publication_date>
      <news:title>Play Protect viene aggirato dal falso TVTap di RemControl</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/stories/610d68c8-9e3f-42c1-a326-0d309ef5034f/pamstealer-moves-payload-decryption-off-the-mac</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T06:50:27Z</news:publication_date>
      <news:title>PamStealer Moves Payload Decryption Off the Mac</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://plainsec.com/it/stories/610d68c8-9e3f-42c1-a326-0d309ef5034f/pamstealer-moves-payload-decryption-off-the-mac</loc>
    <news:news>
      <news:publication>
        <news:name>PlainSec</news:name>
        <news:language>it</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T06:50:27Z</news:publication_date>
      <news:title>PamStealer sposta la chiave del payload sul server</news:title>
    </news:news>
  </url>
</urlset>
