<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://blog.arrakis.security</loc>
<lastmod>2026-06-09T21:02:25.301Z</lastmod>
<changefreq>daily</changefreq>
<priority>1</priority>
</url>
<url>
<loc>https://blog.arrakis.security/ghost-rider-how-attackers-burned-46-000-a-day-on-stolen-ai-compute</loc>
<lastmod>2026-06-01T11:37:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://blog.arrakis.security/glass-weight-how-weaponized-hugging-face-models-turned-mlops-into-a-deserialization-attack-surface</loc>
<lastmod>2026-06-01T11:36:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://blog.arrakis.security/the-pipe-crawl-how-shared-ai-compute-lets-attackers-slide-between-tenants</loc>
<lastmod>2026-06-01T11:36:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://blog.arrakis.security/the-autonomous-rat-how-indirect-prompt-injection-replaced-the-remote-access-trojan</loc>
<lastmod>2026-06-01T11:36:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://blog.arrakis.security/phantom-ink-how-invisible-unicode-in-repository-configs-quietly-reprograms-ai-coding-assistants</loc>
<lastmod>2026-05-20T09:04:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://blog.arrakis.security/trojan-glyph-the-prompt-injection-your-sanitizer-can-t-see</loc>
<lastmod>2026-05-19T14:35:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://blog.arrakis.security/cicada-shell-how-sleeper-agents-evade-ai-safety-training</loc>
<lastmod>2026-05-27T13:50:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://blog.arrakis.security/murmuration-when-a-swarm-of-benign-agents-steals-in-plain-sight</loc>
<lastmod>2026-05-20T09:10:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://blog.arrakis.security/infinite-hallway-how-hallucinated-mcp-servers-become-attacker-c2-on-the-loopback</loc>
<lastmod>2026-05-19T13:56:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://blog.arrakis.security/vibe-coding-runaway-how-agent-generated-unreviewed-code-introduces-blind-sqli-by-design</loc>
<lastmod>2026-06-01T12:08:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://blog.arrakis.security/ghost-in-the-shell-when-the-ai-scanner-becomes-the-accomplice</loc>
<lastmod>2026-05-19T14:58:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://blog.arrakis.security/when-ai-deletes-production-the-replit-database-incident-and-hallucination-concealment</loc>
<lastmod>2026-05-20T09:12:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
</urlset>
