<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
<url><loc>https://zerodayroom.com/</loc><lastmod>2026-08-21</lastmod><image:image><image:loc>https://zerodayroom.com/share-home.svg</image:loc></image:image></url>
<url><loc>https://zerodayroom.com/news/suspected-russian-hackers-abuse/</loc><lastmod>2026-08-21</lastmod><image:image><image:loc>https://zerodayroom.com/share-suspected-russian-hackers-abuse.svg</image:loc><image:title>A hand with a lock superimposed over it, surrounded by a circle with the words &quot;CYBER SECURITY&quot;...</image:title><image:caption>Three suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to compromise personal accounts across multiple platforms</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/cdn-tsunami-attack-abuses/</loc><lastmod>2026-08-21</lastmod><image:image><image:loc>https://zerodayroom.com/share-cdn-tsunami-attack-abuses.svg</image:loc><image:title>A close-up view of a network switch with cables plugged into it.</image:title><image:caption>Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/rust-supply-chain-attack/</loc><lastmod>2026-08-21</lastmod><image:image><image:loc>https://zerodayroom.com/share-rust-supply-chain-attack.svg</image:loc><image:title>Two green Ethernet cables plugged into a server rack, with multiple ports and labels visible.</image:title><image:caption>A supply chain attack on the Rust programming language has compromised three widely used crates, potentially affecting 245 million downloads. The attack was carried out by a compromised maintainer...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/manic-android-malware-uses/</loc><lastmod>2026-08-21</lastmod><image:image><image:loc>https://zerodayroom.com/share-manic-android-malware-uses.svg</image:loc><image:title>A woman sitting at a desk with a laptop, accompanied by a shield with the letters &quot;VPN&quot; and a...</image:title><image:caption>A new Android malware, codenamed Manic, has been discovered targeting financial institutions, government services, and messaging applications, with the ability to exfiltrate data from offline...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/shady-ai-next-big/</loc><lastmod>2026-08-20</lastmod><image:image><image:loc>https://zerodayroom.com/share-shady-ai-next-big.svg</image:loc><image:title>A person is holding a tablet with a VPN app on the screen.</image:title><image:caption>The increasing use of approved AI tools in unapproved ways is creating a new governance problem for cybersecurity teams, known as &#x27;shady AI&#x27; (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/cryptographic-context-injection-attack/</loc><lastmod>2026-08-20</lastmod><image:image><image:loc>https://zerodayroom.com/share-cryptographic-context-injection-attack.svg</image:loc><image:title>The image displays the words &quot;CYBER ATTACK&quot; in large, light-brown letters against a dark background.</image:title><image:caption>Adversa AI discloses a new attack technique that can cause xAI&#x27;s Grok chatbot to send user data to an attacker-controlled server (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/ai-generated-exploit-scripts/</loc><lastmod>2026-08-20</lastmod><image:image><image:loc>https://zerodayroom.com/share-ai-generated-exploit-scripts.svg</image:loc><image:title>A list of text in a programming language, with various words and phrases highlighted in...</image:title><image:caption>The US government has warned of an active threat targeting critical infrastructure organizations using AI-generated exploit scripts to target Siemens S7 Series Programmable Logic Controllers (PLCs).</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/toxicpanda-golddigger-expand-android/</loc><lastmod>2026-08-20</lastmod><image:image><image:loc>https://zerodayroom.com/share-toxicpanda-golddigger-expand-android.svg</image:loc><image:title>A tablet displaying a stock market graph, a red cell phone, a stack of cash, and a wallet on a...</image:title><image:caption>Cybersecurity researchers have discovered updates to the ToxicPanda and GoldDigger Android malware, which now have enhanced capabilities to steal banking and cryptocurrency credentials</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/silkparasite-espionage-campaign-targets/</loc><lastmod>2026-08-20</lastmod><image:image><image:loc>https://zerodayroom.com/share-silkparasite-espionage-campaign-targets.svg</image:loc><image:title>A close-up of a circuit board with a network cable plugged into it, partially hidden behind a...</image:title><image:caption>A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT)...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/openai-halts-frontier-rl/</loc><lastmod>2026-08-20</lastmod><image:image><image:loc>https://zerodayroom.com/share-openai-halts-frontier-rl.svg</image:loc><image:title>A close-up of a technician&#x27;s hands, fingers tracing over a printed circuit board with exposed...</image:title><image:caption>OpenAI temporarily pauses reinforcement learning training for its advanced AI models to enhance monitoring, alignment, and security safeguards. The move follows recent incidents where AI agents...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/cloudflare-workers-vulnerable-spectre/</loc><lastmod>2026-08-20</lastmod><image:image><image:loc>https://zerodayroom.com/share-cloudflare-workers-vulnerable-spectre.svg</image:loc><image:title>A close-up of a Cloudflare Workers dashboard screen, with a cryptic error message and abstract...</image:title><image:caption>Cybersecurity researchers have disclosed a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/elementor-pro-flaw-exposes/</loc><lastmod>2026-08-20</lastmod><image:image><image:loc>https://zerodayroom.com/share-elementor-pro-flaw-exposes.svg</image:loc><image:title>A computer screen displaying a code snippet in green text on a black background.</image:title><image:caption>A critical vulnerability in the Elementor Pro plugin allows unauthenticated attackers to upload PHP files and execute code on affected systems. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/twinloot-abuses-sharepoint-teams/</loc><lastmod>2026-08-19</lastmod><image:image><image:loc>https://zerodayroom.com/share-twinloot-abuses-sharepoint-teams.svg</image:loc><image:title>The image displays the words &quot;ETHICAL HACKING&quot; in a collage style, with each letter cut out from...</image:title><image:caption>Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT, which abuses SharePoint and Teams to steal credentials and move across networks.</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/typosquatted-rubygems-packages-steal/</loc><lastmod>2026-08-19</lastmod><image:image><image:loc>https://zerodayroom.com/share-typosquatted-rubygems-packages-steal.svg</image:loc><image:title>A laptop with a VPN app open on its screen, sitting on a white table next to a cell phone...</image:title><image:caption>Cybersecurity researchers have discovered a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. The campaign, dubbed StubMaker, has been tracked by...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/safepal-hardware-wallet-maker/</loc><lastmod>2026-08-19</lastmod><image:image><image:loc>https://zerodayroom.com/share-safepal-hardware-wallet-maker.svg</image:loc><image:title>The internal components of a laptop computer, including the motherboard and RAM, with a...</image:title><image:caption>SafePal, a hardware wallet maker, has disclosed an authorization flaw in an order-tracking plug-in that exposed the data of approximately 39,798 customers. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/one-attacker-scrapes-salesforce/</loc><lastmod>2026-08-19</lastmod><image:image><image:loc>https://zerodayroom.com/share-one-attacker-scrapes-salesforce.svg</image:loc><image:title>A long hallway lined with rows of servers, featuring a prominent cloud icon at its center.</image:title><image:caption>A single attacker has been scraping records from both Salesforce and ServiceNow customer portals across multiple industries for over a year. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/ransomware-affiliate-ransom-busters/</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-ransomware-affiliate-ransom-busters.svg</image:loc><image:title>The image displays the words &quot;DATA BREACH&quot; in large, light-colored letters on a dark background.</image:title><image:caption>A ransomware affiliate, &#x27;Ransom Busters&#x27;, has been sending emails to victim organizations claiming to delete stolen data from ransomware groups&#x27; servers in exchange for a fee ranging from $20,000...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/attackers-exploit-mlflow-ssrf/</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-attackers-exploit-mlflow-ssrf.svg</image:loc><image:title>A man in a gray suit and white mask is leaning over a large server rack, adjusting a blue cable.</image:title><image:caption>Malicious actors are targeting open-source AI platform MLflow and web-based SCADA software FUXA with critical vulnerabilities. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/ai-mind-viruses-demonstrate/</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-ai-mind-viruses-demonstrate.svg</image:loc><image:title>A circular object with a white and blue border, surrounded by a blue and white background.</image:title><image:caption>Researchers at Anthropic and EPFL have shown that AI agents can spread self-propagating payloads, dubbed &#x27;mind viruses,&#x27; through persistent system prompt files. While no wild infections have been...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/microsoft-copilot-personal-flaws/</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-microsoft-copilot-personal-flaws.svg</image:loc><image:title>A person holding a blue sticker with the words &quot;hacker inside&quot; in white text, set against a...</image:title><image:caption>Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that could allow a single click on a crafted link to silently pull data from connected apps and other...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/critical-gitlab-graphql-flaw/</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-critical-gitlab-graphql-flaw.svg</image:loc><image:title>A row of Scrabble tiles arranged horizontally on a reflective surface, with the word &quot;CYBERSEC&quot;...</image:title><image:caption>GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/unisoc-volte-video-call/</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-unisoc-volte-video-call.svg</image:loc><image:title>A red padlock sitting on a black keyboard.</image:title><image:caption>Security researchers have discovered a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/cisa-flags-actively-exploited/</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-cisa-flags-actively-exploited.svg</image:loc><image:title>Close-up of a laptop displaying cybersecurity text, emphasizing digital security themes.</image:title><image:caption>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/mcp-servers-hidden-gap/</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-mcp-servers-hidden-gap.svg</image:loc><image:title>A server with a row of lights and a series of buttons.</image:title><image:caption>MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access, and prompt injection, highlighting the need for robust security measures to protect...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/cavern-c2-framework-evolves/</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-cavern-c2-framework-evolves.svg</image:loc><image:title>A person stands in front of a server room, holding a white Anonymous mask in their right hand.</image:title><image:caption>Kaspersky researchers have discovered new components in the Cavern command-and-control framework used by Iranian nation-state hackers, expanding its communication capabilities and allowing it to...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/cybersecurity-threats-week-review/</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-cybersecurity-threats-week-review.svg</image:loc><image:title>A green binary code on a black background.</image:title><image:caption>A summary of the latest cybersecurity threats and vulnerabilities. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/snowflake-github-actions-flaw/</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-snowflake-github-actions-flaw.svg</image:loc><image:title>A close-up of a computer screen showing a GitHub Actions workflow with a red &quot;error&quot;...</image:title><image:caption>A vulnerability in Snowflake&#x27;s public GitHub repository allowed attackers to inject commands into a workflow containing internal Jira credentials, potentially exposing sensitive information.</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/critical-flaws-wordpress-plugins/</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-critical-flaws-wordpress-plugins.svg</image:loc><image:title>A Samsung tablet displaying a login screen with a username and password field, accompanied by a...</image:title><image:caption>Two high-severity vulnerabilities have been discovered in popular WordPress plugins, Forminator Forms and User Profile Builder, allowing unauthenticated attackers to execute arbitrary code and...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/microsoft-defender-patch-bypass-e95232/</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-microsoft-defender-patch-bypass-e95232.svg</image:loc><image:title>A laptop with the words &quot;CYBER SECURITY&quot; on its screen, sitting on a table or desk.</image:title><image:caption>A security researcher has released a proof-of-concept exploit for a Microsoft zero-day vulnerability, claiming it can bypass a previously released patch and grant an attacker SYSTEM-level privileges.</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/cisco-asa-ftd-flaw-ede96a/</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-cisco-asa-ftd-flaw-ede96a.svg</image:loc><image:title>A network switch with multiple cables connected to it, likely in a data center or server room...</image:title><image:caption>A high-severity vulnerability in Cisco&#x27;s Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild, allowing an...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/sap-commerce-cloud-vulnerability-9c4fb6/</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-sap-commerce-cloud-vulnerability-9c4fb6.svg</image:loc><image:title>A close-up of a circuit board with a Data Hub Adapter chip at its center, its pins and...</image:title><image:caption>SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/microsoft-patches-flaws-including-73b10d/</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-microsoft-patches-flaws-including-73b10d.svg</image:loc><image:title>A padlock sitting on top of a laptop keyboard.</image:title><image:caption>Microsoft has released its monthly security updates, addressing 398 flaws, including a Windows driver zero-day under active attack. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/adobe-patches-critical-flaws-96b5e1/</loc><lastmod>2026-08-16</lastmod><image:image><image:loc>https://zerodayroom.com/share-adobe-patches-critical-flaws-96b5e1.svg</image:loc><image:title>A wooden Scrabble game board with the words &quot;CYBER SECURITY&quot; spelled out on it.</image:title><image:caption>Adobe releases updates to address multiple critical security vulnerabilities in ColdFusion, Commerce, and Campaign Classic, with some flaws having a CVSS score of 10.0. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/malicious-litellm-releases-may-1b59d6/</loc><lastmod>2026-08-16</lastmod><image:image><image:loc>https://zerodayroom.com/share-malicious-litellm-releases-may-1b59d6.svg</image:loc><image:title>A woman sitting at a desk with two computer monitors, a laptop, and a mouse.</image:title><image:caption>A recent investigation has revealed that two malicious LiteLLM releases were published on PyPI in March, potentially exposing over 2,500 organizations to credential-stealing code.</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/attackers-exploit-vmware-vcenter-a0ae0c/</loc><lastmod>2026-08-16</lastmod><image:image><image:loc>https://zerodayroom.com/share-attackers-exploit-vmware-vcenter-a0ae0c.svg</image:loc><image:title>A person wearing a gray beanie and a brown hoodie, standing in front of a green digital...</image:title><image:caption>Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability, CVE-2026-59310, is a...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/enterprise-defenses-recovered-edge-2689d1/</loc><lastmod>2026-08-16</lastmod><image:image><image:loc>https://zerodayroom.com/share-enterprise-defenses-recovered-edge-2689d1.svg</image:loc><image:title>Two computer monitors displaying green text on a black background, sitting on a desk in a dimly...</image:title><image:caption>A recent report by Picus Labs reveals that enterprise defenses have made significant improvements at the perimeter, but are struggling to prevent quiet attacks inside the network.</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/lazarus-group-exploits-windows-a82e1d/</loc><lastmod>2026-08-16</lastmod><image:image><image:loc>https://zerodayroom.com/share-lazarus-group-exploits-windows-a82e1d.svg</image:loc><image:title>A person is visible holding a tablet in front of a blue background with binary code displayed on it.</image:title><image:caption>The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/chrome-vpn-extensions-caught-af9804/</loc><lastmod>2026-08-16</lastmod><image:image><image:loc>https://zerodayroom.com/share-chrome-vpn-extensions-caught-af9804.svg</image:loc><image:title>A woman sitting on the floor, holding a smartphone with a VPN app open on the screen.</image:title><image:caption>A set of 737 free VPN and proxy extensions have been found to target Russian-speaking users, intercepting browser traffic and routing it through a proxy infrastructure. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/flaw-ai-reasoning-apis-aa04ef/</loc><lastmod>2026-08-16</lastmod><image:image><image:loc>https://zerodayroom.com/share-flaw-ai-reasoning-apis-aa04ef.svg</image:loc><image:title>A close-up of a computer screen displaying a programming code in a dark room.</image:title><image:caption>Researchers have discovered a vulnerability in the AI reasoning APIs of OpenAI, Anthropic, and Google, allowing them to recover internal reasoning and secrets from session logs, including API keys...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/news/sharepoint-authentication-bypass-exploited-670241/</loc><lastmod>2026-08-16</lastmod><image:image><image:loc>https://zerodayroom.com/share-sharepoint-authentication-bypass-exploited-670241.svg</image:loc><image:title>A wooden letter holder with the words &quot;CYBER SECURITY&quot; spelled out in individual letters.</image:title><image:caption>Threat actors are actively exploiting a critical SharePoint vulnerability (CVE-2026-55040) after a proof-of-concept exploit was publicly released. The flaw allows unauthenticated attackers to...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/vulnerabilities/</loc><lastmod>2026-08-20</lastmod></url>
<url><loc>https://zerodayroom.com/threats/</loc><lastmod>2026-08-21</lastmod></url>
<url><loc>https://zerodayroom.com/regulation-compliance/</loc><lastmod>2026-08-20</lastmod></url>
<url><loc>https://zerodayroom.com/topics/sec-regulation-compliance/</loc><lastmod>2026-08-20</lastmod></url>
<url><loc>https://zerodayroom.com/topics/sec-threats/</loc><lastmod>2026-08-21</lastmod></url>
<url><loc>https://zerodayroom.com/topics/sec-vulnerabilities/</loc><lastmod>2026-08-20</lastmod></url>
<url><loc>https://zerodayroom.com/about/</loc></url>
<url><loc>https://zerodayroom.com/sources-and-methods/</loc></url>
<url><loc>https://zerodayroom.com/corrections/</loc></url>
</urlset>