<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://nefariousplan.com/</loc>
<lastmod>2026-04-23T20:33:48.125Z</lastmod>
<changefreq>weekly</changefreq>
<priority>1</priority>
</url>
<url>
<loc>https://nefariousplan.com/about</loc>
<lastmod>2026-04-23T20:33:48.125Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.5</priority>
</url>
<url>
<loc>https://nefariousplan.com/pgp</loc>
<lastmod>2026-04-23T20:33:48.125Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns</loc>
<lastmod>2026-04-23T20:33:48.125Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/adobe-acrobat-cve-2026-34621-detection-lie</loc>
<lastmod>2026-04-23T17:55:39.337Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/pix-woocommerce-nonce-is-not-auth</loc>
<lastmod>2026-04-22T17:10:49.605Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/tomcat-encryptinterceptor-fails-open</loc>
<lastmod>2026-04-21T04:02:06.750Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/fortisandbox-cve-2026-39808-unauth-rce</loc>
<lastmod>2026-04-19T18:43:55.937Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/adobe-acrobat-cve-2026-34621-pdf-weaponizer</loc>
<lastmod>2026-04-19T18:43:55.808Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/bluhammer</loc>
<lastmod>2026-04-19T18:43:55.697Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/undefend</loc>
<lastmod>2026-04-19T18:43:55.601Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/the-trust-inversion</loc>
<lastmod>2026-04-19T18:43:55.488Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/redsun-windows-defender-system-write</loc>
<lastmod>2026-04-19T18:43:55.348Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/sap-netweaver-cvss-10-upload-to-webroot</loc>
<lastmod>2026-04-19T18:43:55.206Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/axios-sapphire-sleet-70-million-installs</loc>
<lastmod>2026-04-19T18:43:55.074Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/teampcp-they-came-for-the-scanners</loc>
<lastmod>2026-04-19T18:43:54.683Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/oracle-cloud-the-breach-they-technically-didnt-deny</loc>
<lastmod>2026-04-19T18:43:54.583Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/prompt-injection-is-a-supply-chain-attack</loc>
<lastmod>2026-04-19T18:43:54.464Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/mcp-servers-the-new-npm-left-pad</loc>
<lastmod>2026-04-19T18:43:54.304Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/shai-hulud-the-npm-worm</loc>
<lastmod>2026-04-19T18:43:54.192Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/xrpl-npm-the-official-package-was-the-threat</loc>
<lastmod>2026-04-19T18:43:54.092Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/clfs-ransomwares-favorite-kernel-driver</loc>
<lastmod>2026-04-19T18:43:53.985Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/crushftp-pre-auth-mft-is-the-target</loc>
<lastmod>2026-04-19T18:43:53.873Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/tj-actions-mutable-tags-were-always-a-lie</loc>
<lastmod>2026-04-19T18:43:53.726Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/bybit-safe-ui-poisoning-fifteen-hundred-million</loc>
<lastmod>2026-04-19T18:43:53.625Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/posts/ivanti-the-vulnerability-subscription</loc>
<lastmod>2026-04-19T18:43:53.322Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/trust-inversion</loc>
<lastmod>2026-04-19T18:33:07.325Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/design-debt-driver</loc>
<lastmod>2026-04-19T18:33:52.781Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/disclosure-after-exploitation</loc>
<lastmod>2026-04-19T18:33:53.198Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/security-tool-as-primitive</loc>
<lastmod>2026-04-19T18:33:55.193Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/content-is-command</loc>
<lastmod>2026-04-19T18:33:52.096Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/maintainer-account-compromise</loc>
<lastmod>2026-04-19T18:33:53.897Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/revocation-gap</loc>
<lastmod>2026-04-19T18:34:31.668Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/unauth-write-to-execution-path</loc>
<lastmod>2026-04-19T18:33:56.136Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/disclaimer-wrapped-campaign-kit</loc>
<lastmod>2026-04-19T18:33:52.961Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/mutable-reference-as-immutable</loc>
<lastmod>2026-04-19T18:33:54.342Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/nonce-is-not-auth</loc>
<lastmod>2026-04-19T18:33:54.521Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/persistent-blindspot</loc>
<lastmod>2026-04-19T18:33:54.736Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/the-detector-is-the-target</loc>
<lastmod>2026-04-19T18:33:55.736Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/commented-out-code-is-testimony</loc>
<lastmod>2026-04-19T18:33:51.816Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/denial-by-pedantry</loc>
<lastmod>2026-04-19T18:33:52.491Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/emergent-primitive</loc>
<lastmod>2026-04-19T18:33:53.423Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/fail-open-intercept</loc>
<lastmod>2026-04-19T18:33:53.603Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/junction-preemption</loc>
<lastmod>2026-04-22T03:28:49.987Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/mft-as-primary-target</loc>
<lastmod>2026-04-19T18:33:54.123Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/prototype-pollution-trust-bypass</loc>
<lastmod>2026-04-19T18:33:54.909Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/security-metric-theater</loc>
<lastmod>2026-04-22T04:05:18.088Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/self-propagating-supply-chain</loc>
<lastmod>2026-04-19T18:33:55.351Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/signing-surface-poisoning</loc>
<lastmod>2026-04-19T18:33:55.538Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/toctou-that-isnt</loc>
<lastmod>2026-04-22T04:05:12.686Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/unpatchable-primitive</loc>
<lastmod>2026-04-19T18:33:56.307Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/unsigned-ecosystem-echo</loc>
<lastmod>2026-04-19T18:33:56.544Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://nefariousplan.com/patterns/todo-that-shipped</loc>
<lastmod>2026-04-19T18:33:55.925Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
</urlset>
