<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:video="http://www.google.com/schemas/sitemap-video/1.1">
  <url>
    <loc>https://nullsector.co/</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://nullsector.co/en/</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://nullsector.co/sobre-mi</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/sobre-mi"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/about"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/sobre-mi"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://nullsector.co/en/about</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/sobre-mi"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/about"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/sobre-mi"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://nullsector.co/investigacion</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://nullsector.co/en/research</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://nullsector.co/contacto</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/contacto"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/contact"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/contacto"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://nullsector.co/en/contact</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/contacto"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/contact"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/contacto"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://nullsector.co/investigacion/gitlab-cve-2026-85706</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/gitlab-cve-2026-85706"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/gitlab-cve-2026-85706"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/gitlab-cve-2026-85706"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/GhQlpf9YUBw/hqdefault.jpg</video:thumbnail_loc>
      <video:title>GitLab CE/EE: lectura de archivos sin autenticación en la API de commits</video:title>
      <video:description>Reconstrucción controlada con agentes de IA del path traversal sin autenticación de la API de commits de GitLab, ya divulgada y remediada por el fabricante. El caso reproduce la lectura arbitraria en la versión vulnerable, verifica el cierre en la versión parcheada y publica cuatro reglas de detección con su evidencia de disparo.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/GhQlpf9YUBw</video:player_loc>
      <video:duration>258</video:duration>
      <video:publication_date>2026-09-16</video:publication_date>
    </video:video>
  </url>
  <url>
    <loc>https://nullsector.co/en/research/gitlab-cve-2026-85706</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/gitlab-cve-2026-85706"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/gitlab-cve-2026-85706"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/gitlab-cve-2026-85706"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/GhQlpf9YUBw/hqdefault.jpg</video:thumbnail_loc>
      <video:title>GitLab CE/EE: unauthenticated file read in the commits API</video:title>
      <video:description>A controlled reconstruction with AI agents of the unauthenticated path traversal in the GitLab commits API, already disclosed and remediated by the vendor. The case reproduces the arbitrary read on the vulnerable version, verifies the closure on the patched version and publishes four detection rules with evidence of them firing.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/GhQlpf9YUBw</video:player_loc>
      <video:duration>258</video:duration>
      <video:publication_date>2026-09-16</video:publication_date>
    </video:video>
  </url>
  <url>
    <loc>https://nullsector.co/investigacion/papercut-cve-2026-82078</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/papercut-cve-2026-82078"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/papercut-cve-2026-82078"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/papercut-cve-2026-82078"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/n2uTpe8LW3I/hqdefault.jpg</video:thumbnail_loc>
      <video:title>PaperCut NG/MF: de un bypass de autenticación a cargar la clase que tú quieras</video:title>
      <video:description>Reconstrucción de la cadena que publica PaperCut el 27 de agosto de 2026: un acceso indebido a la interfaz de administración permite reescribir la configuración de la base de datos, y la carga dinámica de clases del conector ejecuta la clase que esa configuración nombre. El caso mide cuándo dispara y cuándo muere en cada versión del fabricante.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/n2uTpe8LW3I</video:player_loc>
      <video:duration>132</video:duration>
      <video:publication_date>2026-09-12</video:publication_date>
    </video:video>
  </url>
  <url>
    <loc>https://nullsector.co/en/research/papercut-cve-2026-82078</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/papercut-cve-2026-82078"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/papercut-cve-2026-82078"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/papercut-cve-2026-82078"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/n2uTpe8LW3I/hqdefault.jpg</video:thumbnail_loc>
      <video:title>PaperCut NG/MF: from an authentication bypass to loading any class you name</video:title>
      <video:description>Reconstruction of the chain PaperCut disclosed on 27 August 2026: improper access to the administration interface allows rewriting the database configuration, and the dynamic class loading in the connector then runs the class that configuration names. The case measures when it fires and when it dies on each vendor version.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/n2uTpe8LW3I</video:player_loc>
      <video:duration>132</video:duration>
      <video:publication_date>2026-09-12</video:publication_date>
    </video:video>
  </url>
  <url>
    <loc>https://nullsector.co/investigacion/gitea-cve-2026-60004</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/gitea-cve-2026-60004"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/gitea-cve-2026-60004"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/gitea-cve-2026-60004"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/YwHgCjs08Q8/hqdefault.jpg</video:thumbnail_loc>
      <video:title>Gitea diffpatch: ejecución de código desde una cuenta sin permisos de administrador</video:title>
      <video:description>Reconstrucción de la inyección de código por la ruta diffpatch de Gitea, divulgada por el fabricante con prueba de concepto funcional. El caso prueba a nivel de proceso quién ejecuta realmente, mide la latencia desde una cuenta sin permisos de administrador y publica el falso positivo que midió en sus propias reglas.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/YwHgCjs08Q8</video:player_loc>
      <video:duration>131</video:duration>
      <video:publication_date>2026-09-01</video:publication_date>
    </video:video>
  </url>
  <url>
    <loc>https://nullsector.co/en/research/gitea-cve-2026-60004</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/gitea-cve-2026-60004"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/gitea-cve-2026-60004"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/gitea-cve-2026-60004"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/YwHgCjs08Q8/hqdefault.jpg</video:thumbnail_loc>
      <video:title>Gitea diffpatch: code execution from an account without administrator privileges</video:title>
      <video:description>Reconstruction of the code injection through the Gitea diffpatch route, disclosed by the vendor with a working proof of concept. The case proves at process level who actually executes, measures the latency from an account without administrator privileges and publishes the false positive it measured in its own rules.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/YwHgCjs08Q8</video:player_loc>
      <video:duration>131</video:duration>
      <video:publication_date>2026-09-01</video:publication_date>
    </video:video>
  </url>
  <url>
    <loc>https://nullsector.co/investigacion/zimbra-cve-2026-73570</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/zimbra-cve-2026-73570"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/zimbra-cve-2026-73570"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/zimbra-cve-2026-73570"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
  </url>
  <url>
    <loc>https://nullsector.co/en/research/zimbra-cve-2026-73570</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/zimbra-cve-2026-73570"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/zimbra-cve-2026-73570"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/zimbra-cve-2026-73570"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
  </url>
  <url>
    <loc>https://nullsector.co/investigacion/rgs</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/rgs"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/rgs"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/rgs"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/ED45kjvfaSQ/hqdefault.jpg</video:thumbnail_loc>
      <video:title>RGS · Report Generative Security Tool</video:title>
      <video:description>RGS genera el informe de una auditoría de vulnerabilidades a partir de los hallazgos, usando un LLM por API compatible con OpenAI y núcleos CUDA de NVIDIA. Nació como entrada al Generative AI Agents Developer Contest de NVIDIA y LangChain, donde recibió una mención honorable. Es la misma idea que luego ha guiado el laboratorio: que la máquina escriba la parte mecánica para que el humano use el tiempo en atacar.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/ED45kjvfaSQ</video:player_loc>
      <video:duration>78</video:duration>
      <video:publication_date>2024-06-02</video:publication_date>
    </video:video>
  </url>
  <url>
    <loc>https://nullsector.co/en/research/rgs</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/rgs"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/rgs"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/rgs"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/ED45kjvfaSQ/hqdefault.jpg</video:thumbnail_loc>
      <video:title>RGS · Report Generative Security Tool</video:title>
      <video:description>RGS turns the findings of a vulnerability audit into the audit report, using an LLM over an OpenAI-compatible API and NVIDIA CUDA cores. It was born as an entry to the Generative AI Agents Developer Contest run by NVIDIA and LangChain, where it received an honorable mention. It is the same idea that has since guided the lab: the machine writes the mechanical part so the human can spend the time attacking.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/ED45kjvfaSQ</video:player_loc>
      <video:duration>78</video:duration>
      <video:publication_date>2024-06-02</video:publication_date>
    </video:video>
  </url>
  <url>
    <loc>https://nullsector.co/investigacion/iphish-agent</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/iphish-agent"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/iphish-agent"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/iphish-agent"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/KvAol_3f6ko/hqdefault.jpg</video:thumbnail_loc>
      <video:title>iPhish Agent</video:title>
      <video:description>Agente local para campañas de concienciación de phishing con GoPhish: un especialista describe el escenario en lenguaje natural y el agente prepara la campaña, las visuales y el enrutado de correo. Todo con modelos abiertos en la máquina, sin LLM en la nube y sin que ningún mensaje salga a un destinatario real sin aprobación humana: primero pasa por una bandeja de revisión en Mailpit.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/KvAol_3f6ko</video:player_loc>
      <video:duration>251</video:duration>
      <video:publication_date>2026-07-01</video:publication_date>
    </video:video>
  </url>
  <url>
    <loc>https://nullsector.co/en/research/iphish-agent</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/iphish-agent"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/iphish-agent"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/iphish-agent"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/KvAol_3f6ko/hqdefault.jpg</video:thumbnail_loc>
      <video:title>iPhish Agent</video:title>
      <video:description>Local agent for phishing awareness campaigns built on GoPhish: a specialist describes the scenario in natural language and the agent prepares the campaign, the visuals and the mail routing. All of it with open models running on the machine, no cloud LLM, and no message reaching a real recipient without human approval: everything goes through a review inbox in Mailpit first.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/KvAol_3f6ko</video:player_loc>
      <video:duration>251</video:duration>
      <video:publication_date>2026-07-01</video:publication_date>
    </video:video>
  </url>
  <url>
    <loc>https://nullsector.co/investigacion/wp2shell</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/wp2shell"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/wp2shell"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/wp2shell"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/rLqMYMdhD50/hqdefault.jpg</video:thumbnail_loc>
      <video:title>WP2Shell Checker</video:title>
      <video:description>Script de lectura que identifica la versión de WordPress publicada por un sitio y la contrasta con los rangos afectados por CVE-2026-60137 (inyección SQL en WP_Query por el parámetro author__not_in) y CVE-2026-63030 (confusión de rutas en el endpoint batch de la REST API). Devuelve potencialmente afectada, no afectada o no determinable; no toca el sitio ni instala dependencias.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/rLqMYMdhD50</video:player_loc>
      <video:duration>37</video:duration>
      <video:publication_date>2026-07-25</video:publication_date>
    </video:video>
  </url>
  <url>
    <loc>https://nullsector.co/en/research/wp2shell</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/wp2shell"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/wp2shell"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/wp2shell"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/rLqMYMdhD50/hqdefault.jpg</video:thumbnail_loc>
      <video:title>WP2Shell Checker</video:title>
      <video:description>Read-only script that identifies the WordPress version a site publishes and compares it against the version ranges affected by CVE-2026-60137 (SQL injection in WP_Query through the author__not_in parameter) and CVE-2026-63030 (path confusion in the REST API batch endpoint). It returns potentially affected, not affected or not determinable; it does not touch the site and installs no dependencies.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/rLqMYMdhD50</video:player_loc>
      <video:duration>37</video:duration>
      <video:publication_date>2026-07-25</video:publication_date>
    </video:video>
  </url>
  <url>
    <loc>https://nullsector.co/investigacion/pentestmcp</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/pentestmcp"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/pentestmcp"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/pentestmcp"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
  </url>
  <url>
    <loc>https://nullsector.co/en/research/pentestmcp</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/pentestmcp"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/pentestmcp"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/pentestmcp"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
  </url>
  <url>
    <loc>https://nullsector.co/investigacion/spectra</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/spectra"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/spectra"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/spectra"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/JgimB0KiSyw/hqdefault.jpg</video:thumbnail_loc>
      <video:title>Proyecto Spectra</video:title>
      <video:description>Spectra es el proyecto con el que empezó todo esto: usar un LLM (Llama 3.1) para que la IA tome decisiones y ejecute acciones de forma autónoma imitando a un atacante humano, con el objetivo declarado de hacer simulaciones de ataque más realistas y con eso mejorar la defensa. Es investigación documentada en el blog y en vídeo, no un repositorio publicado.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/JgimB0KiSyw</video:player_loc>
      <video:duration>139</video:duration>
      <video:publication_date>2024-07-18</video:publication_date>
    </video:video>
  </url>
  <url>
    <loc>https://nullsector.co/en/research/spectra</loc>
    <xhtml:link rel="alternate" hreflang="es" href="https://nullsector.co/investigacion/spectra"/>
    <xhtml:link rel="alternate" hreflang="en" href="https://nullsector.co/en/research/spectra"/>
    <xhtml:link rel="alternate" hreflang="x-default" href="https://nullsector.co/investigacion/spectra"/>
    <lastmod>2026-09-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <video:video>
      <video:thumbnail_loc>https://i.ytimg.com/vi/JgimB0KiSyw/hqdefault.jpg</video:thumbnail_loc>
      <video:title>Spectra Project</video:title>
      <video:description>Spectra is the project all of this started with: using an LLM (Llama 3.1) so the AI makes decisions and carries out actions autonomously, imitating a human attacker, with the declared goal of making attack simulations more realistic and using that to improve defense. It is research documented on the blog and in video, not a published repository.</video:description>
      <video:player_loc>https://www.youtube-nocookie.com/embed/JgimB0KiSyw</video:player_loc>
      <video:duration>139</video:duration>
      <video:publication_date>2024-07-18</video:publication_date>
    </video:video>
  </url>
</urlset>
