<?xml version="1.0" encoding="UTF-8"?>
<!--generator='jetpack-15.8-a.7'-->
<!--Jetpack_Sitemap_Buffer_News_XMLWriter-->
<?xml-stylesheet type="text/xsl" href="//labs.cloudsecurityalliance.org/news-sitemap.xsl"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd">
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260428/</loc>
  <lastmod>2026-04-28T22:24:12Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>CISO Daily Briefing - April 28, 2026</news:title>
   <news:publication_date>2026-04-28T22:24:12Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-ai-powered-supply-chain-wave-20260428-csa/</loc>
  <lastmod>2026-04-28T22:23:59Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>AI-Powered Supply Chain Wave: Five Campaigns, One Pattern</news:title>
   <news:publication_date>2026-04-28T22:23:59Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-pren-18286-iso-42001-20260428-cs/</loc>
  <lastmod>2026-04-28T22:23:52Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>EU AI Act Compliance: prEN 18286 and ISO 42001</news:title>
   <news:publication_date>2026-04-28T22:23:52Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-litellm-pre-auth-sqli-20260428-csa-styled/</loc>
  <lastmod>2026-04-28T22:23:45Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>LiteLLM Pre-Auth SQL Injection Exploited in 36 Hours</news:title>
   <news:publication_date>2026-04-28T22:23:45Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-github-push-option-rce-20260428-csa-styled/</loc>
  <lastmod>2026-04-28T22:23:38Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>GitHub CVE-2026-3854: Push-Option Injection RCE on GHES</news:title>
   <news:publication_date>2026-04-28T22:23:38Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-entra-agent-id-admin-takeover-20260428-csa/</loc>
  <lastmod>2026-04-28T22:23:31Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>Entra Agent ID Administrator Flaw: Service Principal Takeover</news:title>
   <news:publication_date>2026-04-28T22:23:31Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260427/</loc>
  <lastmod>2026-04-27T13:18:46Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>CISO Daily Briefing - April 27, 2026</news:title>
   <news:publication_date>2026-04-27T13:18:46Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-enisa-ncaf-2-nis2-alignment-20260427-csa-s/</loc>
  <lastmod>2026-04-27T13:18:31Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ENISA NCAF 2.0: EU Cybersecurity Maturity Framework Aligned to NIS2</news:title>
   <news:publication_date>2026-04-27T13:18:31Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-phantomcore-trueconf-exploit-chain-reprodu/</loc>
  <lastmod>2026-04-27T13:18:22Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>PhantomCore-Class Agents Could Reproduce TrueConf Chain Without a Public PoC</news:title>
   <news:publication_date>2026-04-27T13:18:22Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-glassworm-v2-openvsx-ai-dev-supply-chain-2/</loc>
  <lastmod>2026-04-27T13:18:13Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>GlassWorm v2: 73 Sleeper Extensions Target AI Developer Toolchains</news:title>
   <news:publication_date>2026-04-27T13:18:13Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://labs.cloudsecurityalliance.org/research/csa-research-note-n8n-webhook-abuse-ai-workflow-weaponizatio/</loc>
  <lastmod>2026-04-27T13:18:03Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>Lab Space</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>n8n Webhook Abuse: Weaponizing AI Workflow Automation for Malware Delivery</news:title>
   <news:publication_date>2026-04-27T13:18:03Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
</urlset>
