<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" xmlns:video="http://www.google.com/schemas/sitemap-video/1.1"><url><loc>https://appsecco.com</loc></url><url><loc>https://appsecco.com/about</loc></url><url><loc>https://appsecco.com/ai-security</loc></url><url><loc>https://appsecco.com/ai-security/ai-agent-security</loc></url><url><loc>https://appsecco.com/ai-security/llm-integration</loc></url><url><loc>https://appsecco.com/ai-security/mcp-pentesting</loc></url><url><loc>https://appsecco.com/blog</loc></url><url><loc>https://appsecco.com/blog/a-pentester-s-approach-to-kubernetes-security-part-1</loc></url><url><loc>https://appsecco.com/blog/a-pentester-s-approach-to-kubernetes-security-part-2</loc></url><url><loc>https://appsecco.com/blog/automating-migration-to-version-2-of-aws-ec2-instance-metada</loc></url><url><loc>https://appsecco.com/blog/aws-ec2-imdsv2-versus-an-esoteric-http-method</loc></url><url><loc>https://appsecco.com/blog/backdooring-amis-for-fun-and-profit</loc></url><url><loc>https://appsecco.com/blog/category/appsec-engineering</loc></url><url><loc>https://appsecco.com/blog/category/cloud-security</loc></url><url><loc>https://appsecco.com/blog/category/container-security</loc></url><url><loc>https://appsecco.com/blog/category/identity-auth</loc></url><url><loc>https://appsecco.com/blog/category/kubernetes</loc></url><url><loc>https://appsecco.com/blog/category/vulnerability-analysis</loc></url><url><loc>https://appsecco.com/blog/exploiting-iam-security-misconfigurations-part-1</loc></url><url><loc>https://appsecco.com/blog/exploiting-iam-security-misconfigurations-part-2</loc></url><url><loc>https://appsecco.com/blog/exploiting-weak-configurations-in-amazon-cognito-in-aws</loc></url><url><loc>https://appsecco.com/blog/exploiting-weak-configurations-in-google-identity-platform</loc></url><url><loc>https://appsecco.com/blog/finding-ssrf-via-html-injection-inside-a-pdf-file-on-aws-ec2</loc></url><url><loc>https://appsecco.com/blog/finding-treasures-in-github-and-exploiting-aws-for-fun-and-p</loc></url><url><loc>https://appsecco.com/blog/getting-shell-and-data-access-in-aws-app-runner</loc></url><url><loc>https://appsecco.com/blog/getting-started-with-version-2-of-aws-ec2-instance-metadata-</loc></url><url><loc>https://appsecco.com/blog/hacker-days-understanding-aws-cloud-attacks-using-cloudgoat-</loc></url><url><loc>https://appsecco.com/blog/hacking-an-aws-hosted-kubernetes-backed-product-and-failing</loc></url><url><loc>https://appsecco.com/blog/hacking-apps-using-nosql-injection</loc></url><url><loc>https://appsecco.com/blog/hacking-aws-lambda-for-security-fun-and-profit</loc></url><url><loc>https://appsecco.com/blog/how-was-uber-hacked-and-what-can-we-learn-from-the-incident</loc></url><url><loc>https://appsecco.com/blog/kubernetes-from-an-attacker-s-perspective-owasp-bay-area-mee</loc></url><url><loc>https://appsecco.com/blog/microservices-authorization-using-open-policy-agent-and-trae</loc></url><url><loc>https://appsecco.com/blog/security-analysis-of-lastpass-credential-leak-by-bypassing-d</loc></url><url><loc>https://appsecco.com/blog/security-guidance-for-the-apache-log4j-vulnerability-cve-202</loc></url><url><loc>https://appsecco.com/blog/server-side-request-forgery-ssrf-and-aws-ec2-instances-after</loc></url><url><loc>https://appsecco.com/blog/server-side-request-forgery-via-html-injection-in-pdf-downlo</loc></url><url><loc>https://appsecco.com/blog/top-10-docker-hardening-best-practices</loc></url><url><loc>https://appsecco.com/blog/zerologon-cve-2020-1472-detection-patching-and-monitoring</loc></url><url><loc>https://appsecco.com/careers</loc></url><url><loc>https://appsecco.com/case-studies</loc></url><url><loc>https://appsecco.com/case-study/ecommerce</loc></url><url><loc>https://appsecco.com/case-study/fintech</loc></url><url><loc>https://appsecco.com/case-study/saas</loc></url><url><loc>https://appsecco.com/checklist</loc></url><url><loc>https://appsecco.com/compliance/gdpr</loc></url><url><loc>https://appsecco.com/compliance/hipaa</loc></url><url><loc>https://appsecco.com/compliance/iso27001</loc></url><url><loc>https://appsecco.com/compliance/pci-dss</loc></url><url><loc>https://appsecco.com/compliance/soc2</loc></url><url><loc>https://appsecco.com/contact</loc></url><url><loc>https://appsecco.com/faq</loc></url><url><loc>https://appsecco.com/for/ctos</loc></url><url><loc>https://appsecco.com/for/security-leaders</loc></url><url><loc>https://appsecco.com/for/vp-engineering</loc></url><url><loc>https://appsecco.com/get-assessment</loc></url><url><loc>https://appsecco.com/how-we-work</loc></url><url><loc>https://appsecco.com/industries</loc></url><url><loc>https://appsecco.com/industries/fintech</loc></url><url><loc>https://appsecco.com/industries/healthtech</loc></url><url><loc>https://appsecco.com/industries/saas</loc></url><url><loc>https://appsecco.com/masterclass/pentesting-mcp-servers</loc></url><url><loc>https://appsecco.com/mcp-pentesting</loc></url><url><loc>https://appsecco.com/methodology</loc></url><url><loc>https://appsecco.com/open-source</loc></url><url><loc>https://appsecco.com/pricing</loc></url><url><loc>https://appsecco.com/privacy</loc></url><url><loc>https://appsecco.com/product-security-testing</loc></url><url><loc>https://appsecco.com/product-security-testing/ai-mcp</loc></url><url><loc>https://appsecco.com/product-security-testing/apps-apis</loc></url><url><loc>https://appsecco.com/product-security-testing/cloud-k8s-iam</loc></url><url><loc>https://appsecco.com/product-security-testing/reports</loc></url><url><loc>https://appsecco.com/real-world-breaches/salesloft-drift-breach-sep2025</loc></url><url><loc>https://appsecco.com/resources/glossary</loc></url><url><loc>https://appsecco.com/resources/glossary/ai-agent-security</loc></url><url><loc>https://appsecco.com/resources/glossary/ai-red-teaming</loc></url><url><loc>https://appsecco.com/resources/glossary/api-security-testing</loc></url><url><loc>https://appsecco.com/resources/glossary/business-logic-testing</loc></url><url><loc>https://appsecco.com/resources/glossary/cloud-security-testing</loc></url><url><loc>https://appsecco.com/resources/glossary/iam-security</loc></url><url><loc>https://appsecco.com/resources/glossary/kubernetes-security</loc></url><url><loc>https://appsecco.com/resources/glossary/llm-security</loc></url><url><loc>https://appsecco.com/resources/glossary/mcp-security</loc></url><url><loc>https://appsecco.com/resources/glossary/penetration-testing</loc></url><url><loc>https://appsecco.com/resources/glossary/prompt-injection</loc></url><url><loc>https://appsecco.com/resources/guides/ai-red-teaming-for-llm-applications</loc></url><url><loc>https://appsecco.com/resources/guides/ai-red-teaming-vs-ai-security-testing</loc></url><url><loc>https://appsecco.com/resources/guides/first-pentest</loc></url><url><loc>https://appsecco.com/resources/guides/pentest-rfp-template</loc></url><url><loc>https://appsecco.com/responsible-disclosure</loc></url><url><loc>https://appsecco.com/sample-report</loc></url><url><loc>https://appsecco.com/security</loc></url><url><loc>https://appsecco.com/terms</loc></url><url><loc>https://appsecco.com/testimonials</loc></url><url><loc>https://appsecco.com/vs/automated-scanners</loc></url><url><loc>https://appsecco.com/vs/bug-bounty</loc></url><url><loc>https://appsecco.com/vs/in-house-testing</loc></url><url><loc>https://appsecco.com/vs/traditional-vapt</loc></url><url><loc>https://appsecco.com/we-are-different</loc></url></urlset>