<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://rootnotes.in/article/bitget-388-million-the-security-appliance-was-the-way-in</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T11:02:31.502Z</news:publication_date>
      <news:title>Bitget lost about 388 million dollars, and the way in was the security product</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/anssi-dgfip-report-the-tax-agency-learned-of-the-theft-from-the-thief</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T10:36:33.357Z</news:publication_date>
      <news:title>France&apos;s tax agency learned of the theft from the thief, seven weeks after it started</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/malicious-custom-gpts-clickfix-rat-hosted-on-chatgpt-com</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T09:29:09.268Z</news:publication_date>
      <news:title>The malicious GPT sat on chatgpt.com, the ad was bought on Google, and the victim pasted the command themselves</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/openai-cancelled-gpt-6-1-astra-release-and-published-none-of-the-numbers</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T07:47:29.984Z</news:publication_date>
      <news:title>OpenAI says it cancelled a finished model over its own safety tests, and published none of the numbers</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/zimbra-cve-2026-73570-an-email-reaches-the-snmp-path-and-takes-the-auth-keys</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T07:36:56.033Z</news:publication_date>
      <news:title>The Zimbra flaw arrives as an email, and what it takes is the pair of keys that make passwords beside the point</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/phantomsub-101-npm-packages-subscribe-the-developers-whatsapp-account</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T05:36:31.549Z</news:publication_date>
      <news:title>101 npm packages stole nothing. They signed the developer&apos;s WhatsApp account up to a channel</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/cisco-sd-wan-manager-cve-2026-76504-one-encoded-character-walks-past-the-login</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T05:36:18.157Z</news:publication_date>
      <news:title>One hex-encoded letter walks past Cisco SD-WAN Manager&apos;s login, and it is already being used</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/spectre-v2-btr-the-cpu-forgets-the-code-and-remembers-where-it-jumped</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T05:32:36.542Z</news:publication_date>
      <news:title>The CPU forgets the code and remembers where it jumped. That is enough to read the root hash</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/pixelleak-coding-agents-published-13000-internal-screenshots-to-public-repositories</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T05:22:56.675Z</news:publication_date>
      <news:title>The agent could not attach a screenshot to a pull request, so it published one. Then 13,000 of them</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/zscaler-threatlabz-2026-attacks-up-275-percent-named-victims-down-3-percent</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T05:21:06.354Z</news:publication_date>
      <news:title>Zscaler counts 275% more ransomware and 3% fewer named victims. Those are two different things being counted</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/netscaler-zero-days-the-web-shell-answers-a-request-for-a-missing-icon</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-01T05:18:21.534Z</news:publication_date>
      <news:title>The NetScaler web shell answers a request for a missing icon, and CISA says hunt before you patch</news:title>
    </news:news>
  </url>
</urlset>