<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
<url><loc>https://zerodayroom.com/index.html</loc><lastmod>2026-08-19</lastmod><image:image><image:loc>https://zerodayroom.com/share-home.svg</image:loc></image:image></url>
<url><loc>https://zerodayroom.com/twinloot-abuses-sharepoint-teams.html</loc><lastmod>2026-08-19</lastmod><image:image><image:loc>https://zerodayroom.com/share-twinloot-abuses-sharepoint-teams.svg</image:loc><image:title>TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks</image:title><image:caption>Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT, which abuses SharePoint and Teams to steal credentials and move across networks.</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/typosquatted-rubygems-packages-steal.html</loc><lastmod>2026-08-19</lastmod><image:image><image:loc>https://zerodayroom.com/share-typosquatted-rubygems-packages-steal.svg</image:loc><image:title>Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets</image:title><image:caption>Cybersecurity researchers have discovered a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. The campaign, dubbed StubMaker, has been tracked by...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/one-attacker-scrapes-salesforce.html</loc><lastmod>2026-08-19</lastmod><image:image><image:loc>https://zerodayroom.com/share-one-attacker-scrapes-salesforce.svg</image:loc><image:title>One Attacker Scrapes Salesforce and ServiceNow Portals</image:title><image:caption>A single attacker has been scraping records from both Salesforce and ServiceNow customer portals across multiple industries for over a year. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/safepal-hardware-wallet-maker.html</loc><lastmod>2026-08-19</lastmod><image:image><image:loc>https://zerodayroom.com/share-safepal-hardware-wallet-maker.svg</image:loc><image:title>SafePal Hardware Wallet Maker Discloses Data Exposure Affecting Nearly 40,000 Customers</image:title><image:caption>SafePal, a hardware wallet maker, has disclosed an authorization flaw in an order-tracking plug-in that exposed the data of approximately 39,798 customers. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/attackers-exploit-mlflow-ssrf.html</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-attackers-exploit-mlflow-ssrf.svg</image:loc><image:title>Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets</image:title><image:caption>Malicious actors are targeting open-source AI platform MLflow and web-based SCADA software FUXA with critical vulnerabilities. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/ransomware-affiliate-ransom-busters.html</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-ransomware-affiliate-ransom-busters.svg</image:loc><image:title>Ransomware Affiliate &#x27;Ransom Busters&#x27; Claims to Delete Stolen Data for a Fee</image:title><image:caption>A ransomware affiliate, &#x27;Ransom Busters&#x27;, has been sending emails to victim organizations claiming to delete stolen data from ransomware groups&#x27; servers in exchange for a fee ranging from $20,000 to...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/ai-mind-viruses-demonstrate.html</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-ai-mind-viruses-demonstrate.svg</image:loc><image:title>AI &#x27;Mind Viruses&#x27; Demonstrate Self-Replicating Payloads Across Agent Networks</image:title><image:caption>Researchers at Anthropic and EPFL have shown that AI agents can spread self-propagating payloads, dubbed &#x27;mind viruses,&#x27; through persistent system prompt files. While no wild infections have been...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/microsoft-copilot-personal-flaws.html</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-microsoft-copilot-personal-flaws.svg</image:loc><image:title>Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps</image:title><image:caption>Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that could allow a single click on a crafted link to silently pull data from connected apps and other information...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/cisa-flags-actively-exploited.html</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-cisa-flags-actively-exploited.svg</image:loc><image:title>CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE</image:title><image:caption>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/critical-gitlab-graphql-flaw.html</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-critical-gitlab-graphql-flaw.svg</image:loc><image:title>Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects</image:title><image:caption>GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/unisoc-volte-video-call.html</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-unisoc-volte-video-call.svg</image:loc><image:title>Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access</image:title><image:caption>Security researchers have discovered a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/mcp-servers-hidden-gap.html</loc><lastmod>2026-08-18</lastmod><image:image><image:loc>https://zerodayroom.com/share-mcp-servers-hidden-gap.svg</image:loc><image:title>MCP Servers: A Hidden Gap in Enterprise Security</image:title><image:caption>MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access, and prompt injection, highlighting the need for robust security measures to protect...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/cavern-c2-framework-evolves.html</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-cavern-c2-framework-evolves.svg</image:loc><image:title>Cavern C2 Framework Evolves with New Communication Module and Google Apps Script Relay</image:title><image:caption>Kaspersky researchers have discovered new components in the Cavern command-and-control framework used by Iranian nation-state hackers, expanding its communication capabilities and allowing it to...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/cybersecurity-threats-week-review.html</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-cybersecurity-threats-week-review.svg</image:loc><image:title>Cybersecurity Threats: A Week in Review</image:title><image:caption>A summary of the latest cybersecurity threats and vulnerabilities. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/snowflake-github-actions-flaw.html</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-snowflake-github-actions-flaw.svg</image:loc><image:title>Snowflake GitHub Actions Flaw Exposes Jira Credentials to Workflow Injection Attacks</image:title><image:caption>A vulnerability in Snowflake&#x27;s public GitHub repository allowed attackers to inject commands into a workflow containing internal Jira credentials, potentially exposing sensitive information.</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/critical-flaws-wordpress-plugins.html</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-critical-flaws-wordpress-plugins.svg</image:loc><image:title>Critical Flaws in WordPress Plugins Expose Sites to Unauthenticated RCE and Auth Bypass Attacks</image:title><image:caption>Two high-severity vulnerabilities have been discovered in popular WordPress plugins, Forminator Forms and User Profile Builder, allowing unauthenticated attackers to execute arbitrary code and gain...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/microsoft-defender-patch-bypass-e95232.html</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-microsoft-defender-patch-bypass-e95232.svg</image:loc><image:title>Microsoft Defender Patch Bypass Exploit Claims SYSTEM Access</image:title><image:caption>A security researcher has released a proof-of-concept exploit for a Microsoft zero-day vulnerability, claiming it can bypass a previously released patch and grant an attacker SYSTEM-level privileges.</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/cisco-asa-ftd-flaw-ede96a.html</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-cisco-asa-ftd-flaw-ede96a.svg</image:loc><image:title>Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS</image:title><image:caption>A high-severity vulnerability in Cisco&#x27;s Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild, allowing an...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/sap-commerce-cloud-vulnerability-9c4fb6.html</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-sap-commerce-cloud-vulnerability-9c4fb6.svg</image:loc><image:title>SAP Commerce Cloud Vulnerability Allows Unauthenticated Attackers to Execute Arbitrary Code</image:title><image:caption>SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/microsoft-patches-flaws-including-73b10d.html</loc><lastmod>2026-08-17</lastmod><image:image><image:loc>https://zerodayroom.com/share-microsoft-patches-flaws-including-73b10d.svg</image:loc><image:title>Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack</image:title><image:caption>Microsoft has released its monthly security updates, addressing 398 flaws, including a Windows driver zero-day under active attack. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/adobe-patches-critical-flaws-96b5e1.html</loc><lastmod>2026-08-16</lastmod><image:image><image:loc>https://zerodayroom.com/share-adobe-patches-critical-flaws-96b5e1.svg</image:loc><image:title>Adobe Patches Critical Flaws in ColdFusion, Commerce, and Campaign Classic</image:title><image:caption>Adobe releases updates to address multiple critical security vulnerabilities in ColdFusion, Commerce, and Campaign Classic, with some flaws having a CVSS score of 10.0. (Source: The Hacker News)</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/malicious-litellm-releases-may-1b59d6.html</loc><lastmod>2026-08-16</lastmod><image:image><image:loc>https://zerodayroom.com/share-malicious-litellm-releases-may-1b59d6.svg</image:loc><image:title>Malicious LiteLLM Releases May Have Exposed Thousands of Organizations</image:title><image:caption>A recent investigation has revealed that two malicious LiteLLM releases were published on PyPI in March, potentially exposing over 2,500 organizations to credential-stealing code.</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/attackers-exploit-vmware-vcenter-a0ae0c.html</loc><lastmod>2026-08-16</lastmod><image:image><image:loc>https://zerodayroom.com/share-attackers-exploit-vmware-vcenter-a0ae0c.svg</image:loc><image:title>Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access</image:title><image:caption>Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability, CVE-2026-59310, is a...</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/enterprise-defenses-recovered-edge-2689d1.html</loc><lastmod>2026-08-16</lastmod><image:image><image:loc>https://zerodayroom.com/share-enterprise-defenses-recovered-edge-2689d1.svg</image:loc><image:title>Enterprise Defenses Recovered at the Edge, Collapsed Inside</image:title><image:caption>A recent report by Picus Labs reveals that enterprise defenses have made significant improvements at the perimeter, but are struggling to prevent quiet attacks inside the network.</image:caption></image:image></url>
<url><loc>https://zerodayroom.com/category-vulnerabilities.html</loc><lastmod>2026-08-18</lastmod></url>
<url><loc>https://zerodayroom.com/category-threats.html</loc><lastmod>2026-08-18</lastmod></url>
<url><loc>https://zerodayroom.com/about.html</loc></url>
<url><loc>https://zerodayroom.com/sources-and-methods.html</loc></url>
<url><loc>https://zerodayroom.com/corrections.html</loc></url>
</urlset>