<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/05/hpe-aos-cx-cve-2026-73749-critical-rce-2026-09-05/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-05T00:00:00.000Z</news:publication_date>
			<news:title>HPEのArubaOS-CXに認証不要のRCEなど34件のCVE — CVSS 9.8のCVE-2026-73749を含む修正版を公開、実悪用は未確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/05/sra-aitm-phishing-healthcare-chained-accounts-2026-09-05/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-05T00:00:00.000Z</news:publication_date>
			<news:title>医療・医系大学を連鎖感染するAiTMフィッシング — 侵害アカウントが90超の.eduドメインへ13分で拡散、SRAが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/05/netscaler-cve-2026-19490-exploitation-observed-previdian-2026-09-05/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-05T00:00:00.000Z</news:publication_date>
			<news:title>NetScalerの認証回避CVE-2026-19490に実環境での悪用試行 — 脆弱性情報のPrevidianがセンサーで観測、PoC公開の翌日から</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/05/serbia-spyware-wave-share-novispy-2026-09-05/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-05T00:00:00.000Z</news:publication_date>
			<news:title>セルビアで過去最大規模のスパイウェア標的化 — 学生・野党議員ら14人以上にPegasusと新型NoviSpyとSHAREが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/05/tplink-archer-ax55-vulnerabilities-easymesh-2026-09-05/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-05T00:00:00.000Z</news:publication_date>
			<news:title>TP-Link Archer AX55 v4に2件の脆弱性 — EasyMeshのバッファオーバーフローでRCEの恐れ、修正ファームウェアを公開</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/05/openai-daybreak-frontline-defenders-1b-critical-infrastructure-2026-09-05/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-05T00:00:00.000Z</news:publication_date>
			<news:title>OpenAIが重要インフラの防御側へ10億ドル支援 — 「Daybreak for Frontline Defenders」を発表</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/05/gentlemen-ransomware-gold-sherwood-affiliate-playbook-2026-09-05/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-05T00:00:00.000Z</news:publication_date>
			<news:title>「The Gentlemen」ランサムウェアが侵入から24時間以内に暗号化 — GOLD SHERWOODのアフィリエイト手順書をSophos CTUが解明</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/05/rapid7-dprk-ted-backdoor-curlrat-south-korea-2026-09-05/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-05T00:00:00.000Z</news:publication_date>
			<news:title>北朝鮮系APTが韓国の自動車・メディア業界を標的に長期潜伏 — HAProxy内蔵の「Ted」バックドアとcurlRATをRapid7が報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/05/super-forms-cve-2026-14894-file-upload-exploited-2026-09-05/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-05T00:00:00.000Z</news:publication_date>
			<news:title>WordPress用Super Formsの重大欠陥を攻撃者が積極的に悪用 — 未認証でWebシェル設置、25万件超を遮断とWordfenceが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/g7-post-quantum-call-to-action-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>G7が耐量子暗号への移行を要請 — 「遠い将来」から「今動くべき脅威」へ、5つの優先分野を提示</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/postgreshell-cve-2026-6471-replication-rce-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>PostgreSQLに12年間潜んだ重大欠陥「PostGREShell」 — 低権限の複製アカウントからRCE・管理者昇格・持続的バックドアへ</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/huggingface-transformers-vu456290-cache-write-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>Hugging Face Transformersに同意確認前の不正キャッシュ書き込み — CVE-2026-80047、修正版は未提供</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/toyghouls-new-backdoors-hivemq-element-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>Toy Ghoulsが自作バックドアで正規サービスをC2に悪用 — MQTTブローカーとElement経由で遠隔操作</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/link11-european-ddos-h1-2026-record-bandwidth-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>DDoSは「件数減・威力増」へ — 欧州で帯域2.3Tbpsの史上最大を記録、スーパーボットネットがけん引とLink11が報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/datadog-aws-root-password-spraying-150-orgs-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>AWSのルートユーザーを狙うパスワードスプレー、150超の組織に — 正規メールアドレスの事前把握を示唆、Datadogが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/tottori-radiation-monitoring-ransomware-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>鳥取県の環境放射線モニタリングシステムがランサムウェア被害 — 主サーバ停止も副サーバで監視継続、個人情報の流出なし</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/anyrun-rmm-phishing-46-countries-vercel-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>正規のリモート管理ツールを悪用するフィッシングが46か国に拡大 — 45％が米国、使い捨てVercel基盤をANY.RUNが分析</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/proofpoint-ta488-zimbra-half-click-zimreaper-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>ロシア系TA488がZimbraのゼロデイを5か月悪用 — メールを開くだけで発火する「ハーフクリック」と窃取型マルウェアZimReaperをProofpointが分析</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/nihon-kotsu-malware-breach-file-exfiltration-4th-report-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>日本交通、マルウェア感染の不正アクセスで保有ファイルの一部流出を確認 — 7月11日未明に発生、第4報で公表</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/reliaquest-gryxa-ai-built-toolkit-watches-remediation-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>AIが作った攻撃基盤が防御者の駆除を「観察」する — ReliaQuestがツールキット「Gryxa」を分析、管理画面に324台を確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/sonicwall-nsm-onprem-multiple-vulnerabilities-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>SonicWall NSM On-Premに複数の脆弱性 — 認証済みコマンドインジェクションなど3件、CVSS 9.1、修正版4.3.1-R4を公開</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/gen-phantom-deal-fake-ma-fraud-forged-nda-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>「NDAそのものがペイロードだった」— Genを標的にした偽M&amp;A詐欺「Phantom Deal」、偽の役員と偽PwC担当者が62万ユーロ超の送金を要求</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/all-in-one-wp-migration-cve-2026-19949-sqli-rce-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>WordPress移行プラグインにSQLインジェクション（CVE-2026-19949） — 500万超サイトに影響、復元操作時の秘密鍵窃取からRCEのおそれ、7.110で修正済み</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/cnil-hopital-prive-loire-500k-sanction-gdpr-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>仏CNILが私立病院に制裁金50万ユーロ — 72万人超の診療データ漏えい、VPNなし・多要素認証なし・検知なしの三重の不備を認定</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/brazetsu-exilware-iab-marketplace-groupib-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>ブラジルの脅威アクター「Exilware」がPython製マルウェア「BraZetsu」で侵入アクセスを商品化 — Group-IBが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/thomson-reuters-c-track-breach-court-records-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>Thomson Reutersの裁判所管理システム「C-Track」が侵害、SSNや秘匿記録を含む裁判記録に影響 — 米国の20超の裁判所が対象</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/g7-post-quantum-call-to-action-cisa-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>G7が耐量子暗号への移行を共同で呼びかけ、CISAが行動文書を公開 — 5つの優先事項を提示</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/coder-registry-compromise-malicious-terraform-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>Coderのモジュールレジストリが侵害、不正なTerraformモジュールで認証情報を窃取 — 8月31日の約14時間に配信</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/chrome-152-zero-day-cve-2026-85046-v8-exploit-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>Chrome 152にゼロデイ脆弱性CVE-2026-85046 — V8の型取り違え、悪用をGoogleが確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/04/microsoft-ascii-smuggling-phishing-evasion-unicode-tags-2026-09-04/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-04T00:00:00.000Z</news:publication_date>
			<news:title>AIのプロンプト注入から転用 — 見えないUnicode文字で検出をすり抜けるフィッシングをMicrosoftが分析</news:title>
		</news:news>
	</url>
</urlset>