<?xml version="1.0" encoding="UTF-8"?>
<!--generator='jetpack-15.8-a.7'-->
<!--Jetpack_Sitemap_Buffer_News_XMLWriter-->
<?xml-stylesheet type="text/xsl" href="//labs.cloudsecurityalliance.org/news-sitemap.xsl"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd">
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260501/</loc>
  <lastmod>2026-05-01T13:17:09Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>CISO Daily Briefing - May 1, 2026</news:title>
   <news:publication_date>2026-05-01T13:17:09Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-oauth-ai-saas-supply-chain-blast-radius-20/</loc>
  <lastmod>2026-05-01T13:16:55Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>The OAuth Gap: AI SaaS Supply Chain Blast Radius</news:title>
   <news:publication_date>2026-05-01T13:16:55Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-cisa-ot-zero-trust-ai-governance-20260501/</loc>
  <lastmod>2026-05-01T13:16:47Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>CISA OT Zero Trust: AI Governance for Industrial Systems</news:title>
   <news:publication_date>2026-05-01T13:16:47Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-mini-shai-hulud-multi-ecosystem-supply-cha/</loc>
  <lastmod>2026-05-01T13:16:38Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>Mini Shai-Hulud: Multi-Ecosystem Developer Supply Chain Attack</news:title>
   <news:publication_date>2026-05-01T13:16:38Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-dprk-promptmink-ai-coding-agent-malware-20/</loc>
  <lastmod>2026-05-01T13:16:29Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>DPRK PromptMink: Nation-State npm Malware Targets AI Coding Agents</news:title>
   <news:publication_date>2026-05-01T13:16:29Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-gemini-cli-cvss10-rce-sandbox-bypass-20260/</loc>
  <lastmod>2026-05-01T13:16:20Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>Gemini CLI CVSS 10.0: Pre-Sandbox RCE in CI/CD Agents</news:title>
   <news:publication_date>2026-05-01T13:16:20Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/archive-2026-04/</loc>
  <lastmod>2026-05-01T12:15:17Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>Research Archive — April 2026</news:title>
   <news:publication_date>2026-05-01T12:15:17Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-cisa-zero-trust-operational-technology-202/</loc>
  <lastmod>2026-04-30T14:13:02Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>CISA Zero Trust for Operational Technology</news:title>
   <news:publication_date>2026-04-30T14:13:02Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260430/</loc>
  <lastmod>2026-04-30T13:01:41Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>CISO Daily Briefing — April 30, 2026</news:title>
   <news:publication_date>2026-04-30T13:01:41Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-ai-coding-tool-rce-cicd-attack-surface-202/</loc>
  <lastmod>2026-04-30T13:01:28Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>AI Coding Tools as a CI/CD Attack Surface</news:title>
   <news:publication_date>2026-04-30T13:01:28Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-promptmink-dprk-ai-generated-supply-chain/</loc>
  <lastmod>2026-04-30T13:01:20Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>PromptMink: AI-Optimized DPRK Supply Chain Attack</news:title>
   <news:publication_date>2026-04-30T13:01:20Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-litellm-cve-2026-42208-ai-proxy-sqli-20260/</loc>
  <lastmod>2026-04-30T13:01:13Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>LiteLLM CVE-2026-42208: Pre-Auth SQL Injection in AI Proxy</news:title>
   <news:publication_date>2026-04-30T13:01:13Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260429/</loc>
  <lastmod>2026-04-29T13:18:04Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>CISO Daily Briefing — April 29, 2026</news:title>
   <news:publication_date>2026-04-29T13:18:04Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/ai-saas-oauth-supply-chain-systemic-risk-v1-0-csa-styled/</loc>
  <lastmod>2026-04-29T13:17:49Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>AI SaaS OAuth Trust Chains: Systemic Enterprise Attack Surface</news:title>
   <news:publication_date>2026-04-29T13:17:49Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-nist-nvd-enrichment-overhaul-20260429-csa/</loc>
  <lastmod>2026-04-29T13:17:41Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>NVD Triage Overhaul: End of Universal CVE Enrichment</news:title>
   <news:publication_date>2026-04-29T13:17:41Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-lerobot-cve-2026-25874-unauth-rce-20260429/</loc>
  <lastmod>2026-04-29T13:17:26Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>LeRobot CVE-2026-25874: Unauthenticated RCE via Pickle</news:title>
   <news:publication_date>2026-04-29T13:17:26Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-pypi-elementarydata-supply-chain-20260429/</loc>
  <lastmod>2026-04-29T13:17:19Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>elementary-data PyPI Compromise: Cloud Credential Theft via CI/CD Hijack</news:title>
   <news:publication_date>2026-04-29T13:17:19Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-vect2-ransomware-wiper-unrecoverable-20260/</loc>
  <lastmod>2026-04-29T13:17:10Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>VECT 2.0: Paying the Ransom Cannot Recover Enterprise Data</news:title>
   <news:publication_date>2026-04-29T13:17:10Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
</urlset>
