<?xml version="1.0" encoding="UTF-8"?>
<!--generator='jetpack-15.8-a.7'-->
<!--Jetpack_Sitemap_Buffer_News_XMLWriter-->
<?xml-stylesheet type="text/xsl" href="//labs.cloudsecurityalliance.org/news-sitemap.xsl"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd">
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260429/</loc>
  <lastmod>2026-04-29T13:18:04Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>CISO Daily Briefing — April 29, 2026</news:title>
   <news:publication_date>2026-04-29T13:18:04Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/ai-saas-oauth-supply-chain-systemic-risk-v1-0-csa-styled/</loc>
  <lastmod>2026-04-29T13:17:49Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>AI SaaS OAuth Trust Chains: Systemic Enterprise Attack Surface</news:title>
   <news:publication_date>2026-04-29T13:17:49Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-nist-nvd-enrichment-overhaul-20260429-csa/</loc>
  <lastmod>2026-04-29T13:17:41Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>NVD Triage Overhaul: End of Universal CVE Enrichment</news:title>
   <news:publication_date>2026-04-29T13:17:41Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-lerobot-cve-2026-25874-unauth-rce-20260429/</loc>
  <lastmod>2026-04-29T13:17:26Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>LeRobot CVE-2026-25874: Unauthenticated RCE via Pickle</news:title>
   <news:publication_date>2026-04-29T13:17:26Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-pypi-elementarydata-supply-chain-20260429/</loc>
  <lastmod>2026-04-29T13:17:19Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>elementary-data PyPI Compromise: Cloud Credential Theft via CI/CD Hijack</news:title>
   <news:publication_date>2026-04-29T13:17:19Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-vect2-ransomware-wiper-unrecoverable-20260/</loc>
  <lastmod>2026-04-29T13:17:10Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>VECT 2.0: Paying the Ransom Cannot Recover Enterprise Data</news:title>
   <news:publication_date>2026-04-29T13:17:10Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260428/</loc>
  <lastmod>2026-04-28T22:24:12Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>CISO Daily Briefing - April 28, 2026</news:title>
   <news:publication_date>2026-04-28T22:24:12Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-ai-powered-supply-chain-wave-20260428-csa/</loc>
  <lastmod>2026-04-28T22:23:59Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>AI-Powered Supply Chain Wave: Five Campaigns, One Pattern</news:title>
   <news:publication_date>2026-04-28T22:23:59Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-pren-18286-iso-42001-20260428-cs/</loc>
  <lastmod>2026-04-28T22:23:52Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>EU AI Act Compliance: prEN 18286 and ISO 42001</news:title>
   <news:publication_date>2026-04-28T22:23:52Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-litellm-pre-auth-sqli-20260428-csa-styled/</loc>
  <lastmod>2026-04-28T22:23:45Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>LiteLLM Pre-Auth SQL Injection Exploited in 36 Hours</news:title>
   <news:publication_date>2026-04-28T22:23:45Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-github-push-option-rce-20260428-csa-styled/</loc>
  <lastmod>2026-04-28T22:23:38Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>GitHub CVE-2026-3854: Push-Option Injection RCE on GHES</news:title>
   <news:publication_date>2026-04-28T22:23:38Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-entra-agent-id-admin-takeover-20260428-csa/</loc>
  <lastmod>2026-04-28T22:23:31Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>Entra Agent ID Administrator Flaw: Service Principal Takeover</news:title>
   <news:publication_date>2026-04-28T22:23:31Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
</urlset>
