<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"><url><loc>https://diggingbeagle.com/</loc></url><url><loc>https://diggingbeagle.com/search/</loc></url><url><loc>https://diggingbeagle.com/about/</loc></url><url><loc>https://diggingbeagle.com/methodology/</loc></url><url><loc>https://diggingbeagle.com/cite/</loc></url><url><loc>https://diggingbeagle.com/articles/</loc></url><url><loc>https://diggingbeagle.com/cases/</loc></url><url><loc>https://diggingbeagle.com/concepts/</loc></url><url><loc>https://diggingbeagle.com/organizations/</loc></url><url><loc>https://diggingbeagle.com/people/</loc></url><url><loc>https://diggingbeagle.com/entities/</loc></url><url><loc>https://diggingbeagle.com/news/</loc></url><url><loc>https://diggingbeagle.com/sources/</loc></url><url><loc>https://diggingbeagle.com/updates/</loc></url><url><loc>https://diggingbeagle.com/articles/what-changes-when-one-operator-runs-a-multi-agent-attack-loop/</loc></url><url><loc>https://diggingbeagle.com/articles/what-2026-agent-incidents-changed-about-evaluation-security/</loc></url><url><loc>https://diggingbeagle.com/articles/from-finding-to-exploit-the-new-automated-exploit-loop/</loc></url><url><loc>https://diggingbeagle.com/articles/when-a-research-agent-can-write-to-the-public-internet/</loc></url><url><loc>https://diggingbeagle.com/articles/the-sandbox-was-isolated-the-shared-service-was-not/</loc></url><url><loc>https://diggingbeagle.com/articles/what-ai-driven-operations-stole-exposed-and-changed-in-2026/</loc></url><url><loc>https://diggingbeagle.com/cases/spain-s-aepd-received-its-first-ai-agent-linked-personal-data-breach-notificatio/</loc></url><url><loc>https://diggingbeagle.com/cases/aisi-agents-took-unsanctioned-actions-on-the-live-internet/</loc></url><url><loc>https://diggingbeagle.com/cases/anthropic-accused-alibaba-of-large-scale-unauthorized-claude-distillation/</loc></url><url><loc>https://diggingbeagle.com/cases/claude-cyber-evaluations-reached-real-third-party-systems/</loc></url><url><loc>https://diggingbeagle.com/cases/anthropic-says-russian-freelancers-used-claude-code-to-develop-autonomous-fpv-at/</loc></url><url><loc>https://diggingbeagle.com/cases/anthropic-attributed-claude-assisted-content-production-to-russian-state-media-l/</loc></url><url><loc>https://diggingbeagle.com/cases/anthropic-says-a-russian-procurement-operator-used-claude-to-route-restricted-go/</loc></url><url><loc>https://diggingbeagle.com/cases/autojack-crossed-from-hostile-web-content-into-a-local-mcp-control-plane/</loc></url><url><loc>https://diggingbeagle.com/cases/an-ai-generated-malware-idea-exposed-a-workable-browser-only-ransomware-path/</loc></url><url><loc>https://diggingbeagle.com/cases/a-shared-internal-service-became-a-cross-account-chatgpt-data-channel/</loc></url><url><loc>https://diggingbeagle.com/cases/gtg-10007-built-an-autonomous-exploit-foundry-and-used-the-outputs-in-real-intru/</loc></url><url><loc>https://diggingbeagle.com/cases/a-dating-app-network-mixed-thousands-of-ai-personas-with-real-workers/</loc></url><url><loc>https://diggingbeagle.com/cases/anthropic-says-deepseek-silently-routed-selected-customer-traffic-through-claude/</loc></url><url><loc>https://diggingbeagle.com/cases/anthropic-attributes-a-large-reasoning-trace-extraction-pipeline-to-zhipu-z-ai/</loc></url><url><loc>https://diggingbeagle.com/cases/gtg-20006-automated-parts-of-a-russian-espionage-workflow/</loc></url><url><loc>https://diggingbeagle.com/cases/gtg-50014-used-agentic-pipelines-to-turn-exposed-credentials-into-rapid-multi-vi/</loc></url><url><loc>https://diggingbeagle.com/cases/gtg-50020-used-prompt-injection-against-an-ai-evaluation-sandbox/</loc></url><url><loc>https://diggingbeagle.com/cases/a-fake-claude-reseller-stole-the-credentials-of-the-customers-it-claimed-to-serv/</loc></url><url><loc>https://diggingbeagle.com/cases/gtg-50029-used-agentic-workflows-across-a-european-hacktivist-campaign/</loc></url><url><loc>https://diggingbeagle.com/cases/jadepuffer-automated-database-extortion-with-an-llm-agent/</loc></url><url><loc>https://diggingbeagle.com/cases/kass-turned-smart-contract-findings-into-executable-attack-simulations/</loc></url><url><loc>https://diggingbeagle.com/cases/hijacked-ai-coding-assistant-session-became-the-entry-path-for-shai-hulud-across/</loc></url><url><loc>https://diggingbeagle.com/cases/mcp-python-sdk-tasks-crossed-client-session-boundaries/</loc></url><url><loc>https://diggingbeagle.com/cases/a-deprecated-mcp-websocket-transport-trusted-the-browser-origin/</loc></url><url><loc>https://diggingbeagle.com/cases/openai-agents-used-a-public-wiki-as-an-unintended-message-board/</loc></url><url><loc>https://diggingbeagle.com/cases/openai-cyber-evaluation-agents-reached-hugging-face-production/</loc></url><url><loc>https://diggingbeagle.com/cases/the-may-rubygems-package-flood-is-now-linked-to-openai-agents-but-attribution-re/</loc></url><url><loc>https://diggingbeagle.com/cases/semantic-kernel-prompt-injection-reached-host-code-execution/</loc></url><url><loc>https://diggingbeagle.com/cases/windows-mcp-http-modes-exposed-powershell-behind-a-weak-control-plane/</loc></url><url><loc>https://diggingbeagle.com/concepts/agent-authority/</loc></url><url><loc>https://diggingbeagle.com/concepts/agent-spam-and-unintended-public-writes/</loc></url><url><loc>https://diggingbeagle.com/concepts/ai-credentials-as-loot-compute-and-cover/</loc></url><url><loc>https://diggingbeagle.com/concepts/autonomous-cyber-operations/</loc></url><url><loc>https://diggingbeagle.com/concepts/stolen-ai-credentials-as-attack-infrastructure/</loc></url><url><loc>https://diggingbeagle.com/concepts/cross-session-authorization/</loc></url><url><loc>https://diggingbeagle.com/concepts/deceptive-ai-personas/</loc></url><url><loc>https://diggingbeagle.com/concepts/evaluation-containment/</loc></url><url><loc>https://diggingbeagle.com/concepts/executable-exploit-synthesis/</loc></url><url><loc>https://diggingbeagle.com/concepts/goal-directed-deception-in-agent-evaluations/</loc></url><url><loc>https://diggingbeagle.com/concepts/indirect-prompt-injection/</loc></url><url><loc>https://diggingbeagle.com/concepts/localhost-is-not-a-trust-boundary-for-agents/</loc></url><url><loc>https://diggingbeagle.com/concepts/mcp-control-plane-exposure/</loc></url><url><loc>https://diggingbeagle.com/concepts/illicit-model-distillation/</loc></url><url><loc>https://diggingbeagle.com/concepts/undisclosed-model-routing/</loc></url><url><loc>https://diggingbeagle.com/concepts/shared-service-isolation-failure/</loc></url><url><loc>https://diggingbeagle.com/concepts/agent-enabled-software-supply-chain-attack/</loc></url><url><loc>https://diggingbeagle.com/concepts/model-controlled-tool-parameters/</loc></url><url><loc>https://diggingbeagle.com/organizations/uk-ai-security-institute/</loc></url><url><loc>https://diggingbeagle.com/people/alexey-bukhteyev/</loc></url><url><loc>https://diggingbeagle.com/organizations/anthropic/</loc></url><url><loc>https://diggingbeagle.com/entities/autogen-studio/</loc></url><url><loc>https://diggingbeagle.com/entities/chatgpt/</loc></url><url><loc>https://diggingbeagle.com/organizations/check-point-research/</loc></url><url><loc>https://diggingbeagle.com/entities/cve-2026-26030/</loc></url><url><loc>https://diggingbeagle.com/entities/cve-2026-48989/</loc></url><url><loc>https://diggingbeagle.com/entities/cve-2026-52870/</loc></url><url><loc>https://diggingbeagle.com/entities/cve-2026-59950/</loc></url><url><loc>https://diggingbeagle.com/organizations/deepseek/</loc></url><url><loc>https://diggingbeagle.com/entities/github/</loc></url><url><loc>https://diggingbeagle.com/organizations/gtg-50021/</loc></url><url><loc>https://diggingbeagle.com/organizations/hugging-face/</loc></url><url><loc>https://diggingbeagle.com/people/jakub-pachocki/</loc></url><url><loc>https://diggingbeagle.com/entities/kass/</loc></url><url><loc>https://diggingbeagle.com/entities/mcp-python-sdk/</loc></url><url><loc>https://diggingbeagle.com/organizations/metr/</loc></url><url><loc>https://diggingbeagle.com/organizations/microsoft/</loc></url><url><loc>https://diggingbeagle.com/organizations/nightingale-collective/</loc></url><url><loc>https://diggingbeagle.com/organizations/openai/</loc></url><url><loc>https://diggingbeagle.com/entities/pentagi/</loc></url><url><loc>https://diggingbeagle.com/entities/pypi/</loc></url><url><loc>https://diggingbeagle.com/organizations/redwood-research/</loc></url><url><loc>https://diggingbeagle.com/entities/rubydoc-info/</loc></url><url><loc>https://diggingbeagle.com/entities/rubygems-org/</loc></url><url><loc>https://diggingbeagle.com/entities/semantic-kernel/</loc></url><url><loc>https://diggingbeagle.com/organizations/shinyhunters-affiliate-clusters/</loc></url><url><loc>https://diggingbeagle.com/people/sydney-von-arx/</loc></url><url><loc>https://diggingbeagle.com/people/thomas-larsen/</loc></url><url><loc>https://diggingbeagle.com/entities/windows-mcp/</loc></url><url><loc>https://diggingbeagle.com/people/xianhao-zhang/</loc></url><url><loc>https://diggingbeagle.com/organizations/zhipu-ai-z-ai/</loc></url><url><loc>https://diggingbeagle.com/news/researchers-reconstruct-openai-agent-message-board-on-the-public-web/</loc><lastmod>2026-09-04</lastmod></url><url><loc>https://diggingbeagle.com/news/anthropic-september-report-shows-agentic-cyber-operations-moving-from-assistance-to-throughput/</loc><lastmod>2026-09-10</lastmod></url><url><loc>https://diggingbeagle.com/news/check-point-turns-ai-generated-malware-idea-into-browser-only-ransomware-poc/</loc><lastmod>2026-07-01</lastmod></url><url><loc>https://diggingbeagle.com/news/kass-moves-smart-contract-security-from-detection-to-executable-exploit-testing/</loc><lastmod>2026-07-17</lastmod></url><url><loc>https://diggingbeagle.com/news/mcp-python-sdk-advisories-expose-task-ownership-and-browser-origin-gaps/</loc><lastmod>2026-07-16</lastmod></url><url><loc>https://diggingbeagle.com/news/rubygems-confirms-may-spam-campaign-as-openai-reviews-agent-attribution/</loc></url><url><loc>https://diggingbeagle.com/news/check-point-demonstrates-cross-account-task-channel-inside-chatgpt-sandboxes/</loc><lastmod>2026-09-08</lastmod></url><url><loc>https://diggingbeagle.com/sources/aepd-primera-notificacio-n-de-una-brecha-de-datos-personales-causada-por-un-ataq/</loc></url><url><loc>https://diggingbeagle.com/sources/incident-report-unsanctioned-agent-behaviour-during-cyber-testing/</loc></url><url><loc>https://diggingbeagle.com/sources/an-alignment-assessment-of-recent-cybersecurity-incidents/</loc></url><url><loc>https://diggingbeagle.com/sources/investigating-three-real-world-incidents-in-our-cybersecurity-evaluations/</loc></url><url><loc>https://diggingbeagle.com/sources/countering-misuse-of-ai-september-2026/</loc></url><url><loc>https://diggingbeagle.com/sources/practitioner-critique-of-the-openai-evaluation-containment/</loc></url><url><loc>https://diggingbeagle.com/sources/browser-only-ransomware-from-llm-hallucinations-to-a-practical-attack-technique/</loc></url><url><loc>https://diggingbeagle.com/sources/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/</loc></url><url><loc>https://diggingbeagle.com/sources/discovery-of-a-new-openai-agent-message-board/</loc></url><url><loc>https://diggingbeagle.com/sources/windows-mcp-v0-7-5-security-patch-cors-and-dns-rebinding/</loc></url><url><loc>https://diggingbeagle.com/sources/http-transports-expose-unauthenticated-powershell-control-with-wildcard-cors/</loc></url><url><loc>https://diggingbeagle.com/sources/microsoft-semantic-kernel-inmemoryvectorstore-filter-functionality-vulnerable-to/</loc></url><url><loc>https://diggingbeagle.com/sources/anatomy-of-a-frontier-lab-agent-intrusion-a-technical-timeline-of-the-july-2026-/</loc></url><url><loc>https://diggingbeagle.com/sources/hacker-news-discussion-anatomy-of-a-frontier-lab-agent-intrusion/</loc></url><url><loc>https://diggingbeagle.com/sources/beyond-detection-agentic-attack-synthesis-and-simulation-for-smart-contracts/</loc></url><url><loc>https://diggingbeagle.com/sources/hugging-face-agent-intrusion-investigation/</loc></url><url><loc>https://diggingbeagle.com/sources/mandiant-ai-risk-and-resilience-report-2026-case-study-1/</loc></url><url><loc>https://diggingbeagle.com/sources/mcp-python-sdk-experimental-task-handlers-allowed-cross-client-task-access/</loc></url><url><loc>https://diggingbeagle.com/sources/mcp-python-sdk-deprecated-websocket-transport-lacked-host-and-origin-validation/</loc></url><url><loc>https://diggingbeagle.com/sources/brief-independent-investigation-of-agents-behavior-reasoning-and-collaboration-i/</loc></url><url><loc>https://diggingbeagle.com/sources/microsoft-autojack-end-to-end-exploitation-figure/</loc></url><url><loc>https://diggingbeagle.com/sources/autojack-how-a-single-page-can-rce-the-host-running-your-ai-agent/</loc></url><url><loc>https://diggingbeagle.com/sources/microsoft-semantic-kernel-cve-2026-26030-exploitation-figure/</loc></url><url><loc>https://diggingbeagle.com/sources/when-prompts-become-shells-rce-vulnerabilities-in-ai-agent-frameworks/</loc></url><url><loc>https://diggingbeagle.com/sources/the-hugging-face-incident-and-the-road-ahead/</loc></url><url><loc>https://diggingbeagle.com/sources/the-hugging-face-incident-and-other-third-party-impact-from-misaligned-models/</loc></url><url><loc>https://diggingbeagle.com/sources/an-alien-mind/</loc></url><url><loc>https://diggingbeagle.com/sources/reddit-r-cybersecurity-discussion-the-hugging-face-incident-is-not-an-ai-story/</loc></url><url><loc>https://diggingbeagle.com/sources/spanish-data-watchdog-publicises-first-ai-agent-linked-data-breach-report/</loc></url><url><loc>https://diggingbeagle.com/sources/reuters-anthropic-alleges-alibaba-illicitly-extracted-claude-capabilities/</loc></url><url><loc>https://diggingbeagle.com/sources/openai-agents-attacked-rubygems-before-hugging-face-incident-researchers-say/</loc></url><url><loc>https://diggingbeagle.com/sources/an-update-on-the-may-spam-publishing-campaign-on-rubygems-org/</loc></url><url><loc>https://diggingbeagle.com/sources/sysdig-jadepuffer-agentic-ransomware/</loc></url><url><loc>https://diggingbeagle.com/sources/sysdig-jadepuffer-evolves-to-target-ai-ml-assets/</loc></url><url><loc>https://diggingbeagle.com/sources/techcrunch-microsoft-open-source-projects-compromised-to-steal-ai-developer-cred/</loc></url><url><loc>https://diggingbeagle.com/sources/techcrunch-anthropic-multi-agent-turf-war-experiment/</loc></url><url><loc>https://diggingbeagle.com/sources/the-hacker-news-claude-opus-4-6-gym-booking-boundary-violation-reproduction/</loc></url><url><loc>https://diggingbeagle.com/sources/trellix-openclaw-supply-chain-crisis-clawhavoc/</loc></url><url><loc>https://diggingbeagle.com/sources/thomas-larsen-thread-on-the-rubygems-investigation/</loc></url><url><loc>https://diggingbeagle.com/updates/stolen-ai-credentials-are-now-showing-up-as-attacker-infrastructure/</loc><lastmod>2026-09-10</lastmod></url><url><loc>https://diggingbeagle.com/updates/anthropic-revises-cyber-evaluation-incident-assessment/</loc></url><url><loc>https://diggingbeagle.com/updates/openai-says-agent-spam-disclosure-criteria-are-still-being-defined/</loc><lastmod>2026-09-06</lastmod></url></urlset>