<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url><loc>https://celvexgroup.com/</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/about.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/2026-05-14-chain-crossing-business-logic-to-cloud-admin.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/2026-05-15-netscaler-session-mixup-citrixbleed-sibling.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/2026-05-22-trojanized-ide-extensions-initial-access.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/2026-05-26-saml-desync-forged-session.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/2026-05-28-panos-management-plane-cluster-reaudit.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/2026-05-29-extortion-economy-tamperedchef-roadtools-detection.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/2026-06-01-multi-tenant-isolation-cross-tenant-read.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/2026-06-02-mcp-unauthenticated-tool-invocation.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/cloud-metadata-ssrf-credential-theft.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/jwt-alg-confusion-2026.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/lateral-movement-at-ai-speed.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/oauth-state-parameter-takeover.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/attack-research/thirty-second-exploit-and-fix-cycle.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/001-we-scanned-50-companies.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/002-regresshion-cve-2024-6387.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/003-security-headers-saas.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/004-sast-false-positives.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/005-xz-utils-supply-chain.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/006-email-security-dmarc-spf-dkim.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/008-nextjs-middleware-auth-bypass-cve-2026-29155.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/009-fortinet-fortios-ssl-vpn-cve-2026-24472.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/010-erlang-ssh-rce-cve-2026-32433.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/011-woocommerce-payment-bypass-cve-2026-9876.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/014-kubernetes-ingressnightmare-cve-2025-1974.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/016-admin-consent-phishing-the-oauth-grant-you-never-audit.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/017-snowflake-token-breach-was-not-about-snowflake.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/019-change-healthcare-14-months-later-blackcat-forensics.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/020-crlf-to-account-takeover-5-step-chain.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/021-dark-web-monitoring-3-months-watching-your-domain.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/022-moveit-goanywhere-cleo-file-transfer-pattern.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/023-okta-har-file-session-cookies-are-auth.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/024-cross-team-vectors-web-findings-predict-cloud-breach.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/025-microsoft-storm-0558-stolen-key-25-tenants.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/026-retest-every-customer-48-hours-cisa-kev.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/027-five-saas-tenant-misconfigurations-compound.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/028-tmobile-att-api-leaks-100m-records-one-curl.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/029-log4shell-four-years-later-still-twice-a-month.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/030-bug-bounty-triage-91-percent-p1-wrong.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/031-github-git-push-rce-cve-2026-3854.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/032-apache-http2-double-free-cve-2026-23918.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/033-copy-fail-linux-kernel-cve-2026-31431.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/034-cpanel-auth-bypass-cve-2026-41940.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/035-arelle-plugin-rce-cve-2026-42796.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/036-lethal-trifecta-architecture-not-prompt-filter.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/037-mcp-tool-poisoning-rug-pulls-line-jumping.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-04-23-endpoint-defender-coverage-map.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-04-27-detection-window-auditing.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-04-30-compound-blackouts-72h.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-04_storm_2603_velociraptor_killchain.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-14-cross-domain-attack-chains.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-15-ksmbd-and-camel-k-trust-the-bytes-you-did-not-write.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-15-the-ai-app-attack-surface-prompts-tools-and-tokens.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-20-the-unverified-callback-webhook-signature-failures.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-21-namespace-is-not-a-boundary-kubernetes-tenancy-bypass.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-21-shell-quote-the-newline-that-escapes-the-escaper.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-22-nginx-rewrite-module-overlapping-pcre-captures.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-22-role-confusion-in-self-hosted-dashboards.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-23-pan-os-globalprotect-auth-bypass-cve-2026-0257.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-25-what-landed-in-cve-land-this-week.html</loc><lastmod>2026-06-07</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-26-patterns-from-this-weeks-pentests.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-27-risk-projector-one-forgotten-subdomain.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-28-edge-identity-the-pre-auth-gateway-is-the-front-door.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-05-29-cve-land-supply-chain-erp-and-the-edge.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-06-01-the-edge-appliance-is-your-identity-boundary.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-06-02-cve-digest-authorization-was-the-theme-of-the-week.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-06-02-kubernetes-confused-deputy-externalips-and-webhooks.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-06-03-postiz-pwn-request-github-actions-cve-2026-42298.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/2026-06-04-langroid-sqlchatagent-prompt-injection-to-rce-cve-2026-25879.html</loc><lastmod>2026-06-07</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/anonymized-engagement-lessons-may-2026.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/bind-doh-uaf-cluster-cve-2026-3593.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/compound-chain-attacks.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/continuous-validation-ctem-platform.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/coverage-gap-is-a-finding.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/customer-dashboard-remediation-roadmap.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/cve-to-poc-pipeline.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/dark-web-grooming-signals.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/defender-supply-chain-auditing.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/epss-as-triage-signal.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/fim-stack-blind-spots.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/l7-evasion-at-scale-2026.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/measured-mitre-coverage.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/patch-diff-competitive-moat.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/plugin-trust-ecosystems-single-approver-risk.html</loc><lastmod>2026-06-04</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/predicting-zero-days-from-patch-diffs.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/rsync-toctou-class-cve-2026-29518.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/scadabr-ot-ics-gap-cve-2026-8602.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/scheduled-scans-beat-quarterly-pentests.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/test-capsule-per-test-proof.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/blog/version-drift-is-the-finding.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/book.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/capabilities/</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/capabilities/adversary-emulation.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/capabilities/api-security.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/capabilities/automated-penetration-testing.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/capabilities/cloud-security-validation.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/capabilities/continuous-attack-surface.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/capabilities/supply-chain-validation.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/capabilities/vulnerability-validation.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/capabilities/web-application-testing.html</loc><lastmod>2026-06-03</lastmod></url>
  <url><loc>https://celvexgroup.com/contact.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/ctem.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/enterprise.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/for-resellers.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/glossary.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/how-it-works.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/partner-waitlist.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/platform.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/pricing.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/privacy.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/proof-capsule.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/responsible-disclosure.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/scan.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/security.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/terms.html</loc><lastmod>2026-06-11</lastmod></url>
  <url><loc>https://celvexgroup.com/trust.html</loc><lastmod>2026-06-11</lastmod></url>
</urlset>
