<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/talos-clearfake-webdav-amatera-zigcryptostealer-netsupport-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>ClearFakeがWebDAV経由でAmateraを拡散 — TalosがBNB Smart Chainを悪用する二重感染チェーンを解明</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/bengalseo-bing-seo-poisoning-mayabot-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>Bing検索を汚染しMayaBotを配布 — インド拠点のBengalSEOが10年規模で展開するSEOポイズニングと偽サポート詐欺</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/talos-clickfix-google-sheets-c2-crypto-theft-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>ClickFixがブラウザに侵入 — TalosがGoogleスプレッドシートをC2に悪用する暗号資産窃取キャンペーンを報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/python-nodestealer-spyware-upgrade-netskope-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>Python NodeStealerがスパイウェア化 — キーロガーと画面窃取、Facebook 20超APIを窃取とNetskopeが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/adobe-commerce-cve-2026-75650-apsb26-146-stylesmuggler-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>Adobe CommerceにCVSS 10.0の未認証RCE脆弱性CVE-2026-75650 — 悪用を野外で確認、ホットフィクスと認証情報の総入れ替えが必要</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/noname05716-renews-opjapan-ddos-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>親ロシア集団NoName057(16)が「#OpJapan」再開 — 8月下旬に26組織へ66件のDDoSを主張とCheck Pointが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/vietnam-apis-220m-traveler-records-exposed-kinryu-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>ベトナム関連の旅客情報2億2,000万件が露出 — Elasticsearchが既定認証情報で公開、2017〜2026年のAPISデータとKinryu Labsが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/sap-september-2026-patch-day-19-notes-cve-2026-44756-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>SAPが9月パッチデーで19件の新規ノートを公開 — CVSS 10.0のメモリ破壊CVE-2026-44756など基盤の重大脆弱性を修正</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/arcticwolf-prey0058-vishing-m365-data-extortion-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>偽ITヘルプデスクの電話が経営層を狙う — Microsoft 365のセッション窃取とデータ恐喝、Arctic Wolfが手口を詳報</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/adobe-commerce-cve-2026-75650-apsb26-146-hotfix-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>Adobe CommerceとMagentoにCVSS 10.0の脆弱性CVE-2026-75650「StyleSmuggler」 — Adobeが緊急ホットフィックスを公開、すでに悪用を確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/injecteave-electromagnetic-injection-headphone-30m-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>ヘッドホンの音声を30m先から盗聴 — 香港科技大学らの「InjectEave」、電磁注入と非線形混合で低周波漏えいを可視化（USENIX Security 2026）</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/telerik-aspnet-ajax-padding-oracle-rce-poc-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>Telerik UI for ASP.NET AJAXに認証なしRCEの連鎖、公開PoCが登場 — 推奨の暗号化キー設定が悪用の前提に</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/mathspace-metabase-breach-1079819-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>豪Mathspaceで107万人超の情報流出 — 内部分析基盤Metabaseの脆弱性を悪用、8月10日から不正アクセス</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/huntress-rogue-screenconnect-worm-vbs-campaign-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>改変ScreenConnectが新規接続先にVBScriptを自動転送 — ワーム状の拡散活動をHuntressが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/bigbear-20-phaas-microsoft365-mfa-bypass-cloudsek-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>MFAをすり抜けるフィッシング代行「BigBear 2.0」 — 461組織・5,100件超の認証情報を窃取とCloudSEKが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/peep-chromium-post-exploitation-smart-bookmarks-socradar-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>「Smart Bookmarks」を偽装したChrome／Edge乗っ取りツール「PEEP」 — 感染後の端末を裏口化、SOCRadarが解析を公表</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/nightmare-eclipse-avast-nvidia-zero-day-poc-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>AvastとNVIDIAのゼロデイと称するPoCが公開 — 主張内容と未確認事項を整理</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/f5-bigip-apm-php-rootkit-sophos-poisonedrefresh-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>ディスクに残らないWebシェル — F5 BIG-IP APMを狙うPHPルートキットをSophosが解析</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/connectwise-screenconnect-file-transfer-advisory-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>ConnectWiseがScreenConnectのファイル転送に関する問題を公表 — 修正版は週内公開予定、当面は転送権限の無効化で緩和を</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/linux-kernel-71-eol-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>Linuxカーネル7.1系がEOLに — 7.1.13が最終版、現行stableは7.2系へ</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/ando-hazama-meishi-breach-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>安藤ハザマ、偽の警察官にだまされ名刺情報約5,000件が流出 — 管理システムから取得しメール送信</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/voising-bi-tool-unauthorized-access-data-leak-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>VOISINGのBIツールに不正アクセス — 全サービスの顧客情報が漏えい、クレカ・パスワードは対象外</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/nable-ncentral-cve-2026-86218-preauth-rce-hf4-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>N-able N-centralにCVSS 10.0の認証前RCEゼロデイCVE-2026-86218 — Hotfix 4を公開、実攻撃の報告も</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/exchange-online-throttle-block-outdated-2016-2019-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>Exchange Onlineが旧版Exchange 2016／2019からのメールを制限・遮断へ — 2025年10月更新が最低条件、9月第2週から適用</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/mikrotrick-cert-poland-routeros-exploitation-ioc-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>「MikroTrick」— CERT PolskaがRouterOSの6件の脆弱性を公開、SSH経由の実際の悪用と侵害の痕跡を確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/logicvein-fourth-report-darkweb-leak-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>ロジックベインがランサムウェア被害の第4報を公表 — ダークウェブに1万7559人分の情報掲載を確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/tk-toka-ransomware-unauthorized-access-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>T&amp;K TOKAがランサムウェア被害を公表 — 一部業務を停止、警察と連携し原因・影響範囲を調査</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/jipdec-2025-incident-report-10633-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>Pマーク付与事業者の事故報告は10,633件に増加 — 4割近くが速報要件に該当、誤配達・誤送信で全体の約6割</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/mitsui-fudosan-unauthorized-access-55000-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>三井不動産、資格情報の不正利用で最大5.5万件の情報漏えい可能性 — 役職員1.9万件・社外関係者3.6万件</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/npa-passkey-adoption-letter-vol12-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>警察庁「パスワードだけの認証はもう限界」 — 自社サービスへのパスキー導入検討を呼びかけ</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/roundcube-1-6-19-1-7-4-security-update-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>Roundcubeが1.6.19と1.7.4を公開、12件の脆弱性を修正 — ゼロクリックのXSSやSSRF回避に対処</news:title>
		</news:news>
	</url>
</urlset>