<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"><url><loc>https://firewallpulse.com/category/vulnerabilities/travesia-wordpress-theme-cwe-502-deserialization/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-11T13:48:56Z</news:publication_date><news:title>Travesia WordPress Theme CWE-502 Deserialization Vulnerability CVE-2026-93929 Hits v1.1.16 and Older</news:title></news:news></url><url><loc>https://firewallpulse.com/category/vulnerabilities/tozed-x300-ippingdiagnostics-handler-vulnerable/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-11T13:16:55Z</news:publication_date><news:title>TOZED X300 IPPingDiagnostics Handler Vulnerable to Remote OS Command Injection</news:title></news:news></url><url><loc>https://firewallpulse.com/category/cyber-attacks/inexpensive-androids-come-with-midnight-mimosa/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-11T12:43:52Z</news:publication_date><news:title>Inexpensive Androids Come With Midnight Mimosa Firmware Bug for Ad Fraud</news:title></news:news></url><url><loc>https://firewallpulse.com/category/data-breaches/unprotected-internet-facing-interfaces-at-8-547/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-11T12:41:52Z</news:publication_date><news:title>Unprotected Internet-Facing Interfaces at 8,547 Global Renewable Sites Enable Remote Turbine Control</news:title></news:news></url><url><loc>https://firewallpulse.com/category/vulnerabilities/wukong-hrm-paramaspect-auth-bypass-cve-2026/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-11T11:45:41Z</news:publication_date><news:title>Wukong_HRM ParamAspect Auth Bypass CVE-2026-108707 Risks Remote HR Data Manipulation and Deletion</news:title></news:news></url><url><loc>https://firewallpulse.com/category/vulnerabilities/sitevault-1-5-19-code-injection-flaw-enables/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-11T08:31:00Z</news:publication_date><news:title>SiteVault 1.5.19: Code Injection Flaw Enables Critical Unauthenticated Remote Code Execution</news:title></news:news></url><url><loc>https://firewallpulse.com/category/vulnerabilities/tonda-membership-plugin-critical-auth-bypass-lets/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-11T08:31:00Z</news:publication_date><news:title>Tonda Membership Plugin Critical Auth Bypass Lets Attackers Gain Admin Access Without Credentials</news:title></news:news></url><url><loc>https://firewallpulse.com/category/cyber-attacks/cctld-compromises-enable-issuance-of-fake-google/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T13:10:21Z</news:publication_date><news:title>ccTLD Compromises Enable Issuance of Fake Google Domains Certificates</news:title></news:news></url><url><loc>https://firewallpulse.com/category/vulnerabilities/ahsaycbs-backup-platform-vulnerabilities/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T13:10:21Z</news:publication_date><news:title>AhsayCBS Backup Platform Vulnerabilities Exploited for Webshell and Miner Deployment</news:title></news:news></url><url><loc>https://firewallpulse.com/category/cyber-attacks/shinyhunters-hit-as-fbi-detains-suspected-member/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T13:10:21Z</news:publication_date><news:title>ShinyHunters Hit as FBI Detains Suspected Member in Cybercrime Crackdown</news:title></news:news></url><url><loc>https://firewallpulse.com/category/cloud-security/cloud-infra-systems-maker-oxide-hits-6b-value/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T13:10:21Z</news:publication_date><news:title>Cloud Infra Systems Maker Oxide Hits $6B Value After $445M Eclipse-Led Series D</news:title></news:news></url><url><loc>https://firewallpulse.com/category/vulnerabilities/aws-ops-wheel-flaws-cve-2026-6911-and-cve-2026/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T13:10:21Z</news:publication_date><news:title>AWS Ops Wheel flaws CVE-2026-6911 and CVE-2026-6912 expose infrastructure configs</news:title></news:news></url><url><loc>https://firewallpulse.com/category/vulnerabilities/gutentype-object-injection-critical/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T09:23:12Z</news:publication_date><news:title>Gutentype Object Injection: Critical Deserialization of Untrusted Data Affects Versions Through 2.1.12</news:title></news:news></url><url><loc>https://firewallpulse.com/category/vulnerabilities/convex-plugin-deserialization-vulnerability/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T08:48:00Z</news:publication_date><news:title>Convex Plugin Deserialization Vulnerability Enables Remote Object Injection on WordPress Sites</news:title></news:news></url><url><loc>https://firewallpulse.com/category/vulnerabilities/wpcom-member-authentication-bypass-allows/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T08:28:50Z</news:publication_date><news:title>WPCOM Member Authentication Bypass Allows Unauthorised Admin Access via Social Login Flaws</news:title></news:news></url><url><loc>https://firewallpulse.com/category/vulnerabilities/themerex-greeny-object-injection-bug-affects-all/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T08:18:16Z</news:publication_date><news:title>ThemeREX Greeny Object Injection Bug Affects All Versions to 2.10.0 With 9.8 CVSS Score</news:title></news:news></url><url><loc>https://firewallpulse.com/category/vulnerabilities/tinacms-cli-rce-in-pre-3-0-0-versions-lets/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-10T08:14:44Z</news:publication_date><news:title>TinaCMS CLI RCE in Pre-3.0.0 Versions Lets Attackers Run Code via Git Branch Names</news:title></news:news></url><url><loc>https://firewallpulse.com/category/vulnerabilities/proftpd-improper-access-control-cisa-sets-11/</loc><news:news><news:publication><news:name>Firewall Pulse</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-10-09T13:58:23Z</news:publication_date><news:title>ProFTPD Improper Access Control: CISA Sets 11 October KEV Deadline</news:title></news:news></url></urlset>