<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="//bhedan.com/main-sitemap.xsl"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd http://www.google.com/schemas/sitemap-image/1.1 http://www.google.com/schemas/sitemap-image/1.1/sitemap-image.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
	<url>
		<loc>https://bhedan.com/blog/</loc>
		<lastmod>2026-08-24T10:30:29+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/from-regex-matching-to-autonomous-reasoning-the-evolution-of-vulnerability-detection/</loc>
		<lastmod>2026-08-24T11:20:48+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/why-no-exploit-no-invoice-changes-the-security-testing-model/</loc>
		<lastmod>2026-08-24T11:20:47+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/understanding-cvss-scores-in-the-context-of-chained-exploits/</loc>
		<lastmod>2026-08-24T11:20:47+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/what-skilled-human-pentesters-do-that-automated-tools-dont/</loc>
		<lastmod>2026-08-24T11:20:46+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/5-signs-your-current-scanner-is-giving-you-a-false-sense-of-security/</loc>
		<lastmod>2026-08-24T11:20:45+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/continuous-security-testing-vs-the-annual-pentest/</loc>
		<lastmod>2026-08-24T11:20:45+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/how-adversarial-ai-reasons-differently-than-a-traditional-scanner/</loc>
		<lastmod>2026-08-24T11:20:44+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/the-true-cost-of-a-6-week-pentest-cycle/</loc>
		<lastmod>2026-08-24T11:20:44+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/why-a-working-proof-of-concept-beats-a-theoretical-alert-every-time/</loc>
		<lastmod>2026-08-24T11:20:43+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/idor-explained-a-practical-guide-for-engineering-teams/</loc>
		<lastmod>2026-08-24T11:20:43+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/business-logic-flaws-the-vulnerabilities-automated-tools-cant-see/</loc>
		<lastmod>2026-08-24T11:20:42+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/how-multi-step-exploit-chaining-actually-works/</loc>
		<lastmod>2026-08-24T11:20:42+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/why-signature-based-scanners-have-such-a-high-false-positive-rate/</loc>
		<lastmod>2026-08-24T11:20:41+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/the-difference-between-a-vulnerability-and-an-exploit-chain/</loc>
		<lastmod>2026-08-24T11:20:41+00:00</lastmod>
	</url>
	<url>
		<loc>https://bhedan.com/what-is-bola-and-why-legacy-scanners-miss-it/</loc>
		<lastmod>2026-08-24T11:20:40+00:00</lastmod>
	</url>
</urlset>
<!-- XML Sitemap generated by Rank Math SEO Plugin (c) Rank Math - rankmath.com -->