<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" xmlns:video="http://www.google.com/schemas/sitemap-video/1.1"><url><loc>https://threatnotes.org/</loc></url><url><loc>https://threatnotes.org/about/</loc></url><url><loc>https://threatnotes.org/courses/</loc></url><url><loc>https://threatnotes.org/courses/intro-to-phishing-defense/</loc></url><url><loc>https://threatnotes.org/courses/intro-to-phishing-defense/how-phishing-actually-works/</loc></url><url><loc>https://threatnotes.org/courses/intro-to-phishing-defense/spotting-the-tells/</loc></url><url><loc>https://threatnotes.org/courses/intro-to-phishing-defense/what-to-do-when-you-click-something-bad/</loc></url><url><loc>https://threatnotes.org/news/</loc></url><url><loc>https://threatnotes.org/news/2026-07-20/</loc></url><url><loc>https://threatnotes.org/posts/</loc></url><url><loc>https://threatnotes.org/posts/anatomy-of-a-credential-stuffing-attack/</loc></url><url><loc>https://threatnotes.org/posts/anatomy-of-a-phishing-email/</loc></url><url><loc>https://threatnotes.org/posts/public-wifi-whats-actually-at-risk/</loc></url><url><loc>https://threatnotes.org/posts/reading-your-first-wireshark-capture/</loc></url><url><loc>https://threatnotes.org/posts/social-engineering-isnt-just-email/</loc></url><url><loc>https://threatnotes.org/posts/tags/authentication/</loc></url><url><loc>https://threatnotes.org/posts/tags/basics/</loc></url><url><loc>https://threatnotes.org/posts/tags/credential-reuse/</loc></url><url><loc>https://threatnotes.org/posts/tags/credential-stuffing/</loc></url><url><loc>https://threatnotes.org/posts/tags/detection/</loc></url><url><loc>https://threatnotes.org/posts/tags/email-security/</loc></url><url><loc>https://threatnotes.org/posts/tags/fundamentals/</loc></url><url><loc>https://threatnotes.org/posts/tags/https/</loc></url><url><loc>https://threatnotes.org/posts/tags/human-factors/</loc></url><url><loc>https://threatnotes.org/posts/tags/mfa/</loc></url><url><loc>https://threatnotes.org/posts/tags/network-security/</loc></url><url><loc>https://threatnotes.org/posts/tags/network/</loc></url><url><loc>https://threatnotes.org/posts/tags/passwords/</loc></url><url><loc>https://threatnotes.org/posts/tags/phishing/</loc></url><url><loc>https://threatnotes.org/posts/tags/social-engineering/</loc></url><url><loc>https://threatnotes.org/posts/tags/tls/</loc></url><url><loc>https://threatnotes.org/posts/tags/web-basics/</loc></url><url><loc>https://threatnotes.org/posts/tags/wifi/</loc></url><url><loc>https://threatnotes.org/posts/tags/wireshark/</loc></url><url><loc>https://threatnotes.org/posts/the-lock-icon-doesnt-mean-safe/</loc></url><url><loc>https://threatnotes.org/posts/what-mfa-actually-protects-you-against/</loc></url><url><loc>https://threatnotes.org/posts/why-mfa-fatigue-attacks-work/</loc></url><url><loc>https://threatnotes.org/posts/why-your-password-isnt-the-problem/</loc></url><url><loc>https://threatnotes.org/privacy/</loc></url><url><loc>https://threatnotes.org/subscribe/</loc></url></urlset>