<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://rootnotes.in/article/comparitech-q3-2026-the-record-is-2627-claimed-and-247-confirmed</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-10T07:21:20.079Z</news:publication_date>
      <news:title>The record quarter counts 2,627 attacks, and the victims confirmed 247 of them</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/flax-typhoon-seizures-and-the-five-kev-additions-from-2015-and-2016</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-10T07:18:16.807Z</news:publication_date>
      <news:title>Three of the five vulnerabilities added to the exploited catalog this week were disclosed in 2015 and 2016</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/monstercloud-indictment-prosecutors-say-the-decryption-was-a-ransom-payment</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-10T07:17:45.546Z</news:publication_date>
      <news:title>Prosecutors say the proprietary decryption technology was a payment to the people holding the keys</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/lmcache-cve-2026-105192-unpickled-before-the-type-check</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-10T06:35:49.918Z</news:publication_date>
      <news:title>The cache unpickles the message before it checks what kind of message it is</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/artex-south-korean-finance-the-open-directory-held-the-operators-own-cv</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-10T06:21:15.484Z</news:publication_date>
      <news:title>The server running the intrusions had a browsable folder, and what was in it looked like the operator&apos;s CV</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/cctld-registry-hijacks-the-certificates-were-issued-correctly</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-10T06:21:02.168Z</news:publication_date>
      <news:title>The certificates were issued correctly — the attackers controlled the DNS, which is all the check asks for</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/matchboil-uac-0099-in-development-a-year-before-anyone-documented-it</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-09T12:58:00.900Z</news:publication_date>
      <news:title>The downloader&apos;s compile dates run a year earlier than the first public report of it</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/fakegit-17610-repositories-and-almost-none-of-them-new</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-09T12:57:50.121Z</news:publication_date>
      <news:title>Nobody had to create a single new repository — the operator edited the README on the ones that already existed</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/midnight-mimosa-the-malware-is-in-the-system-partition-before-the-first-boot</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-09T12:34:35.442Z</news:publication_date>
      <news:title>The malware sits in the system partition, which means the first owner was infected before the first boot</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/double-counter-discord-bot-breach-the-server-they-had-already-moved-off</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-09T05:51:25.935Z</news:publication_date>
      <news:title>The breach came through a server the company had already migrated away from, still running an analytics tool</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/firefox-wallet-extensions-the-real-wallet-code-with-one-function-hooked</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-09T05:47:21.022Z</news:publication_date>
      <news:title>Four of the fake wallets were the real wallet&apos;s code with the import function hooked</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/sungrow-isolarcloud-cve-2026-107194-one-field-set-to-five-ignores-the-password</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-09T05:41:32.549Z</news:publication_date>
      <news:title>One field set to five logged the researcher in as anyone, and the account owner was never told</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/azazel-gentlemen-mcp-as-a-command-channel-and-the-affiliate-who-kept-the-money</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-08T12:01:52.358Z</news:publication_date>
      <news:title>The ransomware affiliate ran his commands through an AI assistant&apos;s tool protocol, then scanned the internet for more of them</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://rootnotes.in/article/denmark-cpr-register-8-8-million-looked-up-through-lawful-access</loc>
    <news:news>
      <news:publication>
        <news:name>Root Notes</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-08T11:59:31.911Z</news:publication_date>
      <news:title>Nobody broke into Denmark&apos;s population register — a company allowed to search it looked up 8.8 million people</news:title>
    </news:news>
  </url>
</urlset>