<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/11/gss-unauthorized-access-personal-data-246k-2026-09-11/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-11T00:00:00.000Z</news:publication_date>
			<news:title>デジタル庁が政府共通環境GSSへの不正アクセスを公表 — 職員ら約24.6万件の個人情報が流出した可能性</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/11/mantax-otax-android-ransomware-spyware-zimperium-2026-09-11/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-11T00:00:00.000Z</news:publication_date>
			<news:title>ランサムウェアとスパイウェアを一体化したAndroidマルウェア「Mantax Otax」 — 画面監視と嫌がらせ機能で二重恐喝</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/11/gmo-flatt-supply-chain-threat-report-2026-2026-09-11/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-11T00:00:00.000Z</news:publication_date>
			<news:title>悪性パッケージ「ゼロ」の日は181日間で一度もなし — GMO Flattがサプライチェーン脅威レポート2026を公開、約3.1万件を検出</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/11/puzzlemask-covert-ai-attack-vector-checkpoint-2026-09-11/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-11T00:00:00.000Z</news:publication_date>
			<news:title>平易な文章でAIの安全点検をすり抜ける攻撃手法「PuzzleMask」 — Check Pointが報告、検証では9割超で標的モデルが作動</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/11/google-play-early-access-deceptive-apps-bitdefender-2026-09-11/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-11T00:00:00.000Z</news:publication_date>
			<news:title>Google Playの「早期アクセス」を悪用した数千の偽装アプリ — レビュー不可を突き金銭や報酬をうたう、Bitdefenderが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/11/papercut-ai-orchestrated-campaign-greynoise-blackpoint-2026-09-11/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-11T00:00:00.000Z</news:publication_date>
			<news:title>PaperCutの脆弱性を突き数百のAIエージェントが440件超に侵入 — BlackpointとGreyNoiseが報告、日本でも2件確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/11/surfshark-internal-test-server-breach-disclosure-2026-09-11/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-11T00:00:00.000Z</news:publication_date>
			<news:title>Surfsharkが内部テストサーバへの不正アクセスを公表 — 設定ミスでインターネットに公開、利用者データへの影響はなし</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/11/anthropic-threat-report-september-2026-ai-uplift-2026-09-11/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-11T00:00:00.000Z</news:publication_date>
			<news:title>AnthropicがAI悪用レポートを公開 — ロシア系諜報組織と中国の学生集団がClaudeで国家級サイバー攻撃を展開</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/11/conti-ransomware-lytvynenko-sentenced-four-years-2026-09-11/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-11T00:00:00.000Z</news:publication_date>
			<news:title>Contiランサムウェア関与のウクライナ人に懲役4年の判決 — 米司法省、12社への直接関与と1.5億ドルの被害を指摘</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/11/microsoft-ai-executive-impersonation-invoice-fraud-2026-09-11/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-11T00:00:00.000Z</news:publication_date>
			<news:title>MicrosoftがAI支援の経営幹部なりすまし請求書詐欺を報告 — 3日間で100万通超、約5万ドルの送金を要求</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/gigabud-vwork-work-profile-evasion-groupib-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>GigabudがAndroidの業務隔離領域を悪用 — 偽銀行アプリを複製して検知を回避、Group-IBが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/trezor-email-provider-breach-official-domain-phishing-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>正規ドメインから届く偽の脆弱性警告 — Trezorがメール配信事業者侵害によるフィッシングを公表</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/noma-workflow-identity-hijacking-ai-authorization-flaw-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>「お願いするだけ」で社内メールを読み出す — NomaがAIワークフローの認可欠陥「Workflow Identity Hijacking」を報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/cisa-watchguard-firebox-ransomware-cve-2025-14733-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>CISAがWatchGuard Firebox CVE-2025-14733のランサムウェア悪用を確認 — VPN経由の認証なしRCE、侵害の痕跡確認と更新を</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/veradigm-vendor-api-breach-sec-8k-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>医療ITのVeradigmが患者データ侵害を開示 — 委託先の認証情報からAPI経由で個人情報を複製</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/adapthealth-cyberattack-41-million-patients-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>米AdaptHealthで410万人超の患者情報が流出 — 6月5日の攻撃を8月に確定、社会保障番号や金融情報は含まず</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/unit42-spiffe-spire-svid-spoofing-spooffe-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>攻撃者がノードのroot奪取で同居ワークロードの身分証を偽造 — Unit 42がSPIFFE/SPIREのなりすまし実証と検証ツール「Spooffe」を公開</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/anthropic-claude-opus46-fourth-incident-alignment-assessment-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>Anthropicが4件目のAIエージェントによる実システム侵入を公表 — シミュレーションと誤認したClaudeが外部へ越境</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/wiz-litellm-sk1234-default-key-auth-bypass-rce-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>公開LiteLLMの約1割が初期設定の管理鍵「sk-1234」を受け入れ — Wizが認証バイパスからクラウド侵害への連鎖を報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/eu-cyber-resilience-act-reporting-obligations-sep11-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>EUサイバーレジリエンス法の報告義務が9月11日に発効 — 製造者に24時間以内の通知を義務付け</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/kimsuky-ai-agent-opencode-lnk-github-pat-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>北朝鮮系KimsukyがAIエージェント「opencode」で偽文書を大量生成 — GeniansがLNK13件の手口を分析</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/ftc-withdraws-health-breach-policy-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>米FTCがヘルスアプリ向け侵害通知の旧指針を撤回 — 2021年政策声明を取り消し、2024年規則で代替</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/prey0058-microsoft365-vishing-aitm-extortion-arcticwolf-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>Microsoft 365を狙う音声フィッシングPREY-0058が急増 — Arctic WolfがAiTMと住居用プロキシを悪用したクラウド恐喝を警告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/proxmox-ve7-scans-surge-sans-isc-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>サポート終了のProxmox VE 7を狙うスキャンが急増、SANSが観測 — ポート8006への総当たりに注意</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/checkpoint-quantum-gateway-vpn-rce-cve-2026-85102-85103-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>Check PointのVPNに認証なしRCEの重大脆弱性2件、CVSS 9.8 — 修正版へ更新を</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/paloaltonetworks-panos-cve-2026-0310-buffer-overflow-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>Palo Alto NetworksがPAN-OSの深刻な脆弱性CVE-2026-0310を修正 — PAシリーズでルート権限の任意コード実行、VMシリーズはDoSに</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/talos-fmc-active-exploitation-three-clusters-sandworm-qilin-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>Cisco Secure FMCの脆弱性を国家支援APTとランサムウェアが相次ぎ悪用 — TalosがSandworm重なる3つの侵入クラスターを報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/xinbi-guarantee-treasury-ofac-sanctions-doj-seizure-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>米財務省が詐欺闇市場Xinbi Guaranteeを制裁、司法省がインフラ押収 — 240億ドル規模の犯罪基盤を解体</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/cisa-kev-four-vulns-fortinet-citrix-chrome-cisco-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>CISAが4件の悪用確認脆弱性をKEVに登録 — Fortinet、Citrix、Chrome V8、シスコFMCに直ちに対応を</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/okta-infostealer-ai-tokens-jwt-api-key-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>盗まれたAIトークンで“ログインせずにログイン” — Oktaがインフォスティーラー5,871台のログから555件のAI認証トークンを確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/10/microsoft-passkey-social-engineering-aitm-devicecode-2026-09-10/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-10T00:00:00.000Z</news:publication_date>
			<news:title>パスキーを口実にMFAを乗っ取る手口が拡大 — Microsoftが語るAiTMとデバイスコード悪用のクラウド侵害</news:title>
		</news:news>
	</url>
</urlset>