<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://security-research.hashnode.dev</loc>
    <lastmod>2026-09-18T05:47:23.502Z</lastmod>
    <changefreq>always</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/your-perimeter-will-fail-the-real-question-is-how-far-an-attacker-gets-after</loc>
    <lastmod>2026-09-17T03:45:17.542Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/your-pentest-report-says-sql-injection-on-api-search-it-won-t-say-which-line</loc>
    <lastmod>2026-09-17T03:41:27.054Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/i-automated-copilot-code-review-on-every-pull-request-here-s-what-it-still-can-t-do</loc>
    <lastmod>2026-09-16T06:06:54.141Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/why-your-6-500-penetration-test-will-cost-you-more-than-the-47-000-one</loc>
    <lastmod>2026-09-09T11:13:46.233Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/external-penetration-testing-in-2026-a-technical-methodology-tool-stack-and-attack-surface-guide</loc>
    <lastmod>2026-09-09T10:48:31.457Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/idor-the-vulnerability-class-your-scanners-will-never-find</loc>
    <lastmod>2026-09-08T07:00:06.352Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/black-box-vs-white-box-vs-gray-box-pentesting-picking-the-right-one-most-teams-don-t</loc>
    <lastmod>2026-09-07T11:18:44.892Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/red-team-authorization-solving-the-paradox-of-testing-people-who-can-t-know-they-re-being-tested</loc>
    <lastmod>2026-09-07T07:53:28.571Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/soc-2-penetration-testing-what-auditors-actually-check-for-and-where-most-programs-fail</loc>
    <lastmod>2026-09-07T07:23:28.325Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/the-deployment-velocity-gap-why-annual-pentesting-can-t-keep-up-with-modern-saas</loc>
    <lastmod>2026-09-07T06:37:21.471Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/dissecting-fois-the-log4j2-filter-that-only-does-half-its-job</loc>
    <lastmod>2026-09-01T06:59:33.039Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/how-a-github-triage-role-hijacked-an-already-authorized-claude-code-action-run</loc>
    <lastmod>2026-08-31T09:23:42.115Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/claude-code-macos-sandbox-toctou-vulnerability</loc>
    <lastmod>2026-08-31T09:20:56.206Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/cve-2026-71511-read-a-member-s-card-receive-their-password-hash</loc>
    <lastmod>2026-08-25T10:35:47.313Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/cve-2026-71510-ask-enough-yes-no-questions-and-you-know-everyone-s-salary</loc>
    <lastmod>2026-08-25T11:53:21.627Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/cve-2026-71509-approve-your-own-expenses-and-your-whole-team-s</loc>
    <lastmod>2026-08-25T10:32:16.755Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/cve-2026-71508-set-your-own-salary-and-the-receipt-hides-it</loc>
    <lastmod>2026-08-25T10:30:25.399Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/cve-2026-71507-change-one-number-and-the-payroll-run-pays-you</loc>
    <lastmod>2026-08-25T10:28:20.584Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/cve-2026-71506-the-wrong-key-on-the-lock</loc>
    <lastmod>2026-08-25T10:26:32.954Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/cve-2026-71505-the-read-desk-checks-your-id-the-write-desk-doesn-t</loc>
    <lastmod>2026-08-25T11:33:39.038Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/cve-2026-71504-the-membership-desk-that-could-reset-the-admin-s-password</loc>
    <lastmod>2026-08-25T10:24:17.225Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/cve-2026-71503-one-link-opened-once-mints-a-second-admin</loc>
    <lastmod>2026-08-25T10:24:34.603Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/the-back-office-break-in-nine-dolibarr-findings</loc>
    <lastmod>2026-08-25T10:39:36.373Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/series/dolibarr-security-findings</loc>
    <lastmod>2026-09-18T05:47:23.502Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/archive</loc>
    <lastmod>2026-09-18T05:47:23.502Z</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://security-research.hashnode.dev/recommendations</loc>
    <lastmod>2026-09-18T05:47:23.502Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.4</priority>
  </url>
</urlset>