<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://rootnotes.in/article/wikimedia-rogue-openai-agents-the-data-was-already-free-the-proxy-was-not</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-07T09:40:57.176Z</news:publication_date>
      <news:title>Wikipedia&apos;s data is already free, so the agents went after the one thing that was not: a tool that would fetch URLs for them</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/handlebars-cve-2026-106446-the-validator-checked-the-shapes-it-expected-and-emitted-the-rest</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-07T06:21:41.779Z</news:publication_date>
      <news:title>Handlebars checked the parts of the template it expected to see, and compiled everything else into JavaScript</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/atlassian-cve-2026-21589-knowing-the-path-is-not-a-barrier-when-the-vendor-documents-it</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-07T05:36:19.945Z</news:publication_date>
      <news:title>Atlassian says an attacker has to know the exact filename, which for an off-the-shelf product everybody does</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/chrome-155-247-security-fixes-and-what-the-credits-say-about-who-is-finding-bugs</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-07T05:28:08.176Z</news:publication_date>
      <news:title>Chrome shipped 247 security fixes in one release, and the credits show where that number is coming from</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/zachxbt-lazarus-laundering-he-paid-the-five-percent-to-find-out-what-it-buys</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-07T04:42:08.793Z</news:publication_date>
      <news:title>He sent 349,700 dollars to a laundering service to find out how it worked, and the five percent fee is the finding</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/cling-botnet-stun-c2-the-protocol-that-exists-to-tell-you-your-own-address</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-07T04:41:59.758Z</news:publication_date>
      <news:title>The botnet&apos;s command channel is the protocol that exists to tell a machine its own public address, and nobody can block it</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/ta419-ai-policy-phishing-the-first-email-had-no-link-and-the-browser-window-was-a-picture</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-06T08:40:52.824Z</news:publication_date>
      <news:title>The first email carried no link at all, and the browser window the target checked was drawn inside the page</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/exchange-cve-2026-96940-one-mailbox-credential-and-the-authorisation-check-gave-up</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-06T08:40:44.031Z</news:publication_date>
      <news:title>One working mailbox password let an Exchange user read everyone else&apos;s mail, and the cloud was fixed before anyone was told</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/rejetto-hfs-cve-2026-61500-math-random-signed-the-session-and-the-login-leaked-the-seed</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-06T08:40:33.017Z</news:publication_date>
      <news:title>A model found the weak random number generator and, in the same pass, the unauthenticated path that leaks its output</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/glassworm-vs-code-themes-ship-executable-code-hidden-in-invisible-unicode</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-06T06:00:31.393Z</news:publication_date>
      <news:title>A colour theme is supposed to be a file of colours; these shipped 59 KB of code on a single line, hidden in invisible characters</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/apple-full-disk-access-controls-ai-agents-a-permission-that-has-to-be-renewed</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-06T06:00:04.215Z</news:publication_date>
      <news:title>Apple is making Full Disk Access something you re-approve, because the thing holding the permission is no longer a tool you operate</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/netscaler-cve-2026-88779-the-reboots-were-not-the-patch-they-were-a-third-zero-day</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-06T05:59:45.119Z</news:publication_date>
      <news:title>The NetScaler appliances restarting after the patch were not a patch bug — they were a third zero-day, and the sixth crash is the trigger</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/apple-coregraphics-cve-2026-86950-a-targeted-zero-day-with-a-public-proof-of-concept</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T12:42:39.212Z</news:publication_date>
      <news:title>Apple&apos;s font bug was used against a handful of people, and the proof of concept now crashes any unpatched iPhone</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/pentagon-dmdc-breach-nine-months-of-access-and-data-that-cannot-be-rotated</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T12:42:28.616Z</news:publication_date>
      <news:title>Nine months of access to unencrypted Social Security numbers, and the Pentagon says it has no indication of misuse</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/etherhiding-unc5342-the-payload-is-on-chain-and-the-chokepoint-is-the-api-provider</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-05T11:24:53.198Z</news:publication_date>
      <news:title>North Korea put its malware somewhere nobody can take down, and reaches it through a handful of companies that can</news:title>
    </news:news>
  </url>
</urlset>