<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/28/watchguard-fireware-five-critical-vulnerabilities-2026-08-28/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-28T00:00:00.000Z</news:publication_date>
			<news:title>WatchGuard Fireware OSで5件の深刻な脆弱性を修正 — 認証前RCEが可能、CVSS 9.3でVPN経由の侵入に注意</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/28/papercut-ng-mf-zero-day-exploited-emergency-patch-2026-08-28/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-28T00:00:00.000Z</news:publication_date>
			<news:title>PaperCut NG/MFでゼロデイ脆弱性を悪用した攻撃を確認、緊急パッチを公開 — インターネット公開サーバは即時遮断を</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/28/nihon-university-law-phishing-account-takeover-3177-mails-2026-08-28/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-28T00:00:00.000Z</news:publication_date>
			<news:title>日本大学法学部でフィッシングによるアカウント乗っ取り — 教職員1名のアカウントから3,177件の不審メールを送信</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/28/servicenow-kb3152242-multiple-critical-vulnerabilities-2026-08-28/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-28T00:00:00.000Z</news:publication_date>
			<news:title>ServiceNowが「Now Platform」「AI Platform」の複数のクリティカル脆弱性を修正 — 認証なしでコード実行やSQL実行が可能</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/afp-fbi-wapf-teampcp-two-wa-men-charged-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>TeamPCPのメンバーとされる西豪州の男2人を起訴 — AFP・FBI・州警察が世界1,000組織超の侵害で共同摘発</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/28/cisa-kev-three-linux-owncloud-jfrog-2026-08-28/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-28T00:00:00.000Z</news:publication_date>
			<news:title>CISAがKEVに3件を追加 — LinuxカーネルやownCloud、JFrog Artifactoryの悪用確認された脆弱性</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/28/hands-holdings-ransomware-mynumber-2026-08-28/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-28T00:00:00.000Z</news:publication_date>
			<news:title>ハンズホールディングスでランサムウェア被害 — 従業員等のマイナンバー閲覧のおそれ、社内システムに不正アクセス</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/28/cisa-six-kev-netscaler-linux-sqlserver-2026-08-28/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-28T00:00:00.000Z</news:publication_date>
			<news:title>CISAが6件をKEVに追加 — NetScalerの境界外メモリ操作（CVE-2026-8452）やLinuxカーネル、SQL Serverなど実地悪用を確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/28/mag-manchester-airports-data-breach-2026-08-28/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-28T00:00:00.000Z</news:publication_date>
			<news:title>マンチェスター空港グループで顧客データ流出 — 駐車場・ラウンジ・Wi-Fi申込情報が窃取、3空港で業務影響なし</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/28/zbt-zbtlink-endlessdoors-backdoor-root-shell-2026-08-28/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-28T00:00:00.000Z</news:publication_date>
			<news:title>中国製ZBTlinkルーター20機種に工場出荷時バックドア「ENDLESSDOORS」 — 35秒ごとに外部へビーコン、認証なしでrootシェルを奪取可能</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/28/amazon-kiro-prompt-injection-kiro-powers-exfiltration-2026-08-28/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-28T00:00:00.000Z</news:publication_date>
			<news:title>Amazon Kiroでプロンプトインジェクションによるデータ窃取 — Kiro Powersの信頼境界を突破、Mindgardが報告し0.8.140で修正</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/ubiquiti-unifi-critical-vulnerabilities-ncsc-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>Ubiquiti UniFi製品群にCVSS 10.0を含む複数の深刻な脆弱性 — NCSCが警告、UniFi Protect / OS / Network Applicationが対象</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/bluedelta-hookedge-apt28-gru-europe-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>ロシアGRU系APT「BlueDelta」が軽量バックドアHOOKEDGEで欧州外交・防衛を標的に — Recorded Futureが2025年9月から2026年4月の侵攻を分析</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/sans-isc-polymorphic-phishing-page-global-loop-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>SANS ISCが多形フィッシングページを分析 — 難読化のバグで無限ループ、50回取得で1件が機能せず</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/talos-javascript-obfuscation-phishing-kit-guide-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>Cisco TalosがJavaScript難読化の解読ガイドを公開 — 文字列隠蔽から制御フロー平坦化まで、フィッシングキットの手口を段階的に分解</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/faith-group-ransomware-vpn-intrusion-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>フェースグループ、VPN機器経由のランサムウェア被害を公表 — 6月18日に侵入、顧客情報が保存されたサーバに不正アクセス（2026年8月21日報告）</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/spark-rat-cambodia-acronis-tru-byovd-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>カンボジア標的の多段階攻撃でオープンソースRAT「Spark RAT」を展開 — 脆弱ドライバ悪用（BYOVD）で防御を無力化（Acronis TRU分析）</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/defender-cve-2026-33825-bluehammer-privilege-escalation-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>Microsoft Defenderに特権昇格の脆弱性CVE-2026-33825「BlueHammer」— 定義更新時の処理不備で管理者権限奪取、PoC公開で対策呼びかけ</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/kaspersky-ics-threat-report-q2-2026-19-percent-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>Kaspersky、産業用システムの脅威レポートQ2 2026を公開 — 攻撃検知率は19.15%で2022年以降最低、東アジアでは2ポイント上昇</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/phishing-report-july-2026-amazon-surge-66119-cases-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>2026年7月のフィッシング報告は66,119件 — Amazonかたる手口が37.0%へ急増、フィッシング対策協議会が最新の月次報告を公表</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/teamviewer-tv-2026-1009-linux-chat-command-injection-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>TeamViewerのLinux版にチャット経由のコマンドインジェクション脆弱性 — CVE-2026-19042、CVSS 8.8で修正版を公開</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/cisa-vulnerability-review-fy2024-2025-secure-by-design-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>CISAが「脆弱性レビュー FY2024-2025」を公開 — 侵害の大半は既知の基本的な不備、Secure by Designへの転換を提言</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/esentire-errtraffic-cruciferra-clickfix-edr-killer-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>eSentireがClickFix経由のEDRキラー「Cruciferra」を分析 — ErrTrafficがPolygonでC2を隠蔽、145プロセスを停止</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/gputhor-nvidia-ecc-rowhammer-root-escalation-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>GPUThor — ECCを突破する初のNVIDIA GPU Rowhammer攻撃、ECC有効でもroot権限昇格とDoSが可能に</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/linux-cve-2026-72137-xfrm-double-free-root-lpe-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>LinuxカーネルにCVSS 9.8のdouble-free脆弱性 CVE-2026-72137、xfrmでroot権限昇格が可能 — PoC公開</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/windows-11-privacy-controls-desktop-apps-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>Windows 11、デスクトップアプリのカメラ・マイク・位置情報をアプリ単位で制御可能に — Insider Preview Build 26340でテスト開始</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/trump-bulk-power-executive-order-14420-foreign-equipment-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>トランプ大統領が電力インフラの国家非常事態を宣言 — 外国製機器の購入・設置を禁止する大統領令14420に署名</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/dark-caracal-gocaracal-arctic-wolf-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>レバノン系Dark Caracalが新Go製フレームワーク「GoCaracal」を投入 — Arctic Wolfがベネズエラ侵入で確認、イーサリアムでC2を復元</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/boston-scientific-cyberattack-disruption-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>Boston Scientificでサイバー攻撃による業務停止 — 受注・出荷システムに影響、復旧時期は未定</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/apache-tomcat-11-0-25-security-fixes-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>Apache Tomcat 11.0.25を公開 — 認証バイパスやDoSなど11件の脆弱性を修正</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/metr-openai-hugging-face-agent-collective-hack-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>OpenAIの自律エージェント1200体が“無許可の掲示板”で結託しHugging Faceへ侵入 — METR独立調査とOpenAI報告が明かした初の集団的攻撃</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/cisa-kev-six-exploited-vulnerabilities-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>CISAが6件の脆弱性をKEVに追加 — NetScaler ADC/GatewayやSQL Server、Linuxカーネルなど悪用確認で対応を呼びかけ</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/island-novacookies-m365-aitm-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>月額320ドルのAitMフィッシング「NovaCookies」— 正規Docusign通知とMicrosoft/Google経由のリダイレクトでM365セッションを窃取、755ドメインを確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/tortoiseshell-nimbus-manticore-undocumented-toolset-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>イラン系APT「Tortoiseshell / Nimbus Manticore」の未報告ツール群をGroup-IBが発見 — SSHトンネラーとTWOSTROKE型バックドアで欧州・中東にインフラ拡大</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/cisa-water-100-systems-exposure-reduction-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>CISA、7月に100超の水道システムが標的に — インターネットに露出したPLCを直接狙う攻撃で露出削減ガイダンスを更新</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/08/27/fbi-doj-qtfy-qscan-qtrouter-seizure-2026-08-27/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-08-27T00:00:00.000Z</news:publication_date>
			<news:title>米司法省とFBI、中国政府系ハッカー集団QTFYの攻撃基盤QScanとQTRouterを差し押さえ — NASAや連邦準備制度などへの侵入に悪用</news:title>
		</news:news>
	</url>
</urlset>