<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/09/projectzero-maccconc-race-condition-tool-2026-09-09/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-09T00:00:00.000Z</news:publication_date>
			<news:title>Linuxカーネルのレース条件を再現可能に — Google Project Zeroがメモリアクセス追跡と遅延注入ツール「MAccConc」を公開</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/09/chrome-153-stable-230-fixes-2026-09-09/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-09T00:00:00.000Z</news:publication_date>
			<news:title>GoogleがChrome 153を公開、230件の脆弱性を修正 — WebGLやCastのCriticalを含む安定版の更新を配信</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/09/mikrotik-routeros-mikrotrick-cve-2026-67276-2026-09-09/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-09T00:00:00.000Z</news:publication_date>
			<news:title>MikroTik RouterOSに6件の重大脆弱性「MikroTrick」— 認証バイパスから設定奪取まで連鎖、SSH公開機器が標的で更新を呼びかけ</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/09/nebty-doppelcart-119k-fake-shop-network-2026-09-09/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-09T00:00:00.000Z</news:publication_date>
			<news:title>偽ショップ網「DoppelCart」が11万9000ドメインで急拡大 — 2.72%の.shopを占有し正規ブランドを無差別に複製</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/09/microsoft-september-2026-patch-tuesday-974-cves-2026-09-09/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-09T00:00:00.000Z</news:publication_date>
			<news:title>Microsoftが過去最大974件の脆弱性を修正 — 9月定例更新、2件のゼロデイは悪用確認でCISAがKEV登録</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/09/cisa-china-ai-distillation-aa26-251a-2026-09-09/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-09T00:00:00.000Z</news:publication_date>
			<news:title>米政府、中国AI企業6社による米国AIモデルへの産業規模の蒸留攻撃を警告 — NSA・CISA・FBIが共同勧告AA26-251Aを公開</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/calif-weworm-wechat-zero-click-worm-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>WeChatの着信だけでアカウントを乗っ取るゼロクリックワーム「WeWorm」を実証 — Califが3台の実機で感染連鎖を再現、Tencentはサーバ側で遮断</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/checkpoint-chatgpt-cross-account-leakage-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>ChatGPTの隔離サンドボックスにアカウントをまたぐ隠れチャネル — Check PointがGmail連携経由のデータ窃取を実証</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/google-gtig-ai-prompting-to-autonomy-agentic-threat-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>AIエージェントが資格情報を6時間で大量収穫 — Googleが“プロンプトから自律化”への転換を警告、OSS供給網とAI資産が標的に</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/freeipa-cve-2026-76578-anonymous-admin-takeover-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>FreeIPAに未認証で管理者権限を奪取される脆弱性CVE-2026-76578 — Red Hatが緊急警告、匿名LDAPで“管理者グループ”に侵入可能</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/npa-dmarc-quarantine-reject-guidance-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>警察庁がDMARCの段階的強化を呼びかけ — 郵便局に例えて「None放置」からの移行を解説</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/windows-httpsys-cve-2026-62735-privilege-escalation-poc-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>WindowsのHTTP.sysに権限昇格の脆弱性 — CVE-2026-62735、PoC公開でSYSTEM奪取のおそれ、8月更新で修正済み</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/talos-clearfake-webdav-amatera-zigcryptostealer-netsupport-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>ClearFakeがWebDAV経由でAmateraを拡散 — TalosがBNB Smart Chainを悪用する二重感染チェーンを解明</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/bengalseo-bing-seo-poisoning-mayabot-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>Bing検索を汚染しMayaBotを配布 — インド拠点のBengalSEOが10年規模で展開するSEOポイズニングと偽サポート詐欺</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/talos-clickfix-google-sheets-c2-crypto-theft-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>ClickFixがブラウザに侵入 — TalosがGoogleスプレッドシートをC2に悪用する暗号資産窃取キャンペーンを報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/python-nodestealer-spyware-upgrade-netskope-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>Python NodeStealerがスパイウェア化 — キーロガーと画面窃取、Facebook 20超APIを窃取とNetskopeが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/adobe-commerce-cve-2026-75650-apsb26-146-stylesmuggler-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>Adobe CommerceにCVSS 10.0の未認証RCE脆弱性CVE-2026-75650 — 悪用を野外で確認、ホットフィクスと認証情報の総入れ替えが必要</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/noname05716-renews-opjapan-ddos-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>親ロシア集団NoName057(16)が「#OpJapan」再開 — 8月下旬に26組織へ66件のDDoSを主張とCheck Pointが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/vietnam-apis-220m-traveler-records-exposed-kinryu-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>ベトナム関連の旅客情報2億2,000万件が露出 — Elasticsearchが既定認証情報で公開、2017〜2026年のAPISデータとKinryu Labsが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/sap-september-2026-patch-day-19-notes-cve-2026-44756-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>SAPが9月パッチデーで19件の新規ノートを公開 — CVSS 10.0のメモリ破壊CVE-2026-44756など基盤の重大脆弱性を修正</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/arcticwolf-prey0058-vishing-m365-data-extortion-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>偽ITヘルプデスクの電話が経営層を狙う — Microsoft 365のセッション窃取とデータ恐喝、Arctic Wolfが手口を詳報</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/adobe-commerce-cve-2026-75650-apsb26-146-hotfix-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>Adobe CommerceとMagentoにCVSS 10.0の脆弱性CVE-2026-75650「StyleSmuggler」 — Adobeが緊急ホットフィックスを公開、すでに悪用を確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/injecteave-electromagnetic-injection-headphone-30m-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>ヘッドホンの音声を30m先から盗聴 — 香港科技大学らの「InjectEave」、電磁注入と非線形混合で低周波漏えいを可視化（USENIX Security 2026）</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/telerik-aspnet-ajax-padding-oracle-rce-poc-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>Telerik UI for ASP.NET AJAXに認証なしRCEの連鎖、公開PoCが登場 — 推奨の暗号化キー設定が悪用の前提に</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/mathspace-metabase-breach-1079819-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>豪Mathspaceで107万人超の情報流出 — 内部分析基盤Metabaseの脆弱性を悪用、8月10日から不正アクセス</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/huntress-rogue-screenconnect-worm-vbs-campaign-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>改変ScreenConnectが新規接続先にVBScriptを自動転送 — ワーム状の拡散活動をHuntressが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/bigbear-20-phaas-microsoft365-mfa-bypass-cloudsek-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>MFAをすり抜けるフィッシング代行「BigBear 2.0」 — 461組織・5,100件超の認証情報を窃取とCloudSEKが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/peep-chromium-post-exploitation-smart-bookmarks-socradar-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>「Smart Bookmarks」を偽装したChrome／Edge乗っ取りツール「PEEP」 — 感染後の端末を裏口化、SOCRadarが解析を公表</news:title>
		</news:news>
	</url>
</urlset>