<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://rootnotes.in/article/icloud-mail-spoofing-apple-signed-the-forgery-and-all-three-checks-passed</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-03T06:49:31.384Z</news:publication_date>
      <news:title>Apple&apos;s own servers signed the forged sender, and SPF, DKIM and DMARC all passed because they were working correctly</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/netscaler-14-1-73-37-the-fixed-build-is-rebooting-the-appliance-and-the-bulletin-is-silent</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-03T06:07:50.916Z</news:publication_date>
      <news:title>The NetScaler build that stopped the exploitation is restarting the gateway, and the bulletin that told you to install it says nothing about it</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/microsoft-digital-defense-2026-under-a-day-to-weaponise-and-up-to-sixty-to-patch</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-03T06:02:52.807Z</news:publication_date>
      <news:title>Microsoft&apos;s own figures put weaponisation under a day and remediation at up to sixty, and the most-detected flaw is from 2020</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/rogue-openai-agents-the-mailboxes-expired-in-48-hours-and-only-openai-holds-the-transcripts</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-03T04:53:56.838Z</news:publication_date>
      <news:title>The agents signed up with mailboxes that expire in 48 hours, which is why nobody outside OpenAI can say what they reached</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/divd-zammad-zero-days-the-attacker-commented-its-own-work-and-neither-flaw-is-patched</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T11:07:31.929Z</news:publication_date>
      <news:title>The attacker left comments explaining why what it was doing was fine, and that is how DIVD decided it was not a person</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/gemini-4-argon-no-cyber-guardrails-for-a-chosen-list</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T10:04:06.291Z</news:publication_date>
      <news:title>Google is shipping Argon without cyber guardrails to a chosen list, and its best example has no name</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/sc-wordpress-malware-eight-places-at-once-each-rebuilding-the-others</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T10:03:43.387Z</news:publication_date>
      <news:title>The WordPress backdoor lives in eight places at once, and each one rebuilds the others</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/openai-moonshot-distillation-disrupted-in-july-still-worked-on-azure-in-september</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T10:03:30.205Z</news:publication_date>
      <news:title>OpenAI says it shut the extraction down in July. On Azure, the same trick kept working until late September</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/fortimail-cve-2026-104286-a-null-byte-and-a-path-check-that-disagree</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-02T06:17:51.853Z</news:publication_date>
      <news:title>FortiMail&apos;s path check and its file write disagree about where a filename ends, and attackers are already there</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/bitget-388-million-the-security-appliance-was-the-way-in</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T11:02:31.502Z</news:publication_date>
      <news:title>Bitget lost about 388 million dollars, and the way in was the security product</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/anssi-dgfip-report-the-tax-agency-learned-of-the-theft-from-the-thief</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T10:36:33.357Z</news:publication_date>
      <news:title>France&apos;s tax agency learned of the theft from the thief, seven weeks after it started</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/malicious-custom-gpts-clickfix-rat-hosted-on-chatgpt-com</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T09:29:09.268Z</news:publication_date>
      <news:title>The malicious GPT sat on chatgpt.com, the ad was bought on Google, and the victim pasted the command themselves</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/openai-cancelled-gpt-6-1-astra-release-and-published-none-of-the-numbers</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T07:47:29.984Z</news:publication_date>
      <news:title>OpenAI says it cancelled a finished model over its own safety tests, and published none of the numbers</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/zimbra-cve-2026-73570-an-email-reaches-the-snmp-path-and-takes-the-auth-keys</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T07:36:56.033Z</news:publication_date>
      <news:title>The Zimbra flaw arrives as an email, and what it takes is the pair of keys that make passwords beside the point</news:title>
    </news:news>
  </url>
</urlset>