<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/adobe-commerce-cve-2026-75650-apsb26-146-hotfix-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>Adobe CommerceとMagentoにCVSS 10.0の脆弱性CVE-2026-75650「StyleSmuggler」 — Adobeが緊急ホットフィックスを公開、すでに悪用を確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/telerik-aspnet-ajax-padding-oracle-rce-poc-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>Telerik UI for ASP.NET AJAXに認証なしRCEの連鎖、公開PoCが登場 — 推奨の暗号化キー設定が悪用の前提に</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/mathspace-metabase-breach-1079819-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>豪Mathspaceで107万人超の情報流出 — 内部分析基盤Metabaseの脆弱性を悪用、8月10日から不正アクセス</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/huntress-rogue-screenconnect-worm-vbs-campaign-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>改変ScreenConnectが新規接続先にVBScriptを自動転送 — ワーム状の拡散活動をHuntressが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/bigbear-20-phaas-microsoft365-mfa-bypass-cloudsek-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>MFAをすり抜けるフィッシング代行「BigBear 2.0」 — 461組織・5,100件超の認証情報を窃取とCloudSEKが報告</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/08/peep-chromium-post-exploitation-smart-bookmarks-socradar-2026-09-08/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-08T00:00:00.000Z</news:publication_date>
			<news:title>「Smart Bookmarks」を偽装したChrome／Edge乗っ取りツール「PEEP」 — 感染後の端末を裏口化、SOCRadarが解析を公表</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/nightmare-eclipse-avast-nvidia-zero-day-poc-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>AvastとNVIDIAのゼロデイと称するPoCが公開 — 主張内容と未確認事項を整理</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/f5-bigip-apm-php-rootkit-sophos-poisonedrefresh-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>ディスクに残らないWebシェル — F5 BIG-IP APMを狙うPHPルートキットをSophosが解析</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/connectwise-screenconnect-file-transfer-advisory-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>ConnectWiseがScreenConnectのファイル転送に関する問題を公表 — 修正版は週内公開予定、当面は転送権限の無効化で緩和を</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/linux-kernel-71-eol-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>Linuxカーネル7.1系がEOLに — 7.1.13が最終版、現行stableは7.2系へ</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/ando-hazama-meishi-breach-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>安藤ハザマ、偽の警察官にだまされ名刺情報約5,000件が流出 — 管理システムから取得しメール送信</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/voising-bi-tool-unauthorized-access-data-leak-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>VOISINGのBIツールに不正アクセス — 全サービスの顧客情報が漏えい、クレカ・パスワードは対象外</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/nable-ncentral-cve-2026-86218-preauth-rce-hf4-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>N-able N-centralにCVSS 10.0の認証前RCEゼロデイCVE-2026-86218 — Hotfix 4を公開、実攻撃の報告も</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/exchange-online-throttle-block-outdated-2016-2019-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>Exchange Onlineが旧版Exchange 2016／2019からのメールを制限・遮断へ — 2025年10月更新が最低条件、9月第2週から適用</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/mikrotrick-cert-poland-routeros-exploitation-ioc-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>「MikroTrick」— CERT PolskaがRouterOSの6件の脆弱性を公開、SSH経由の実際の悪用と侵害の痕跡を確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/logicvein-fourth-report-darkweb-leak-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>ロジックベインがランサムウェア被害の第4報を公表 — ダークウェブに1万7559人分の情報掲載を確認</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/tk-toka-ransomware-unauthorized-access-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>T&amp;K TOKAがランサムウェア被害を公表 — 一部業務を停止、警察と連携し原因・影響範囲を調査</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/jipdec-2025-incident-report-10633-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>Pマーク付与事業者の事故報告は10,633件に増加 — 4割近くが速報要件に該当、誤配達・誤送信で全体の約6割</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/mitsui-fudosan-unauthorized-access-55000-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>三井不動産、資格情報の不正利用で最大5.5万件の情報漏えい可能性 — 役職員1.9万件・社外関係者3.6万件</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/npa-passkey-adoption-letter-vol12-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>警察庁「パスワードだけの認証はもう限界」 — 自社サービスへのパスキー導入検討を呼びかけ</news:title>
		</news:news>
	</url>
	<url>
		<loc>https://cyber.nexsight.co/articles/2026/09/07/roundcube-1-6-19-1-7-4-security-update-2026-09-07/</loc>
		<news:news>
			<news:publication>
				<news:name>NEXSIGHT CYBER WIRE</news:name>
				<news:language>ja</news:language>
			</news:publication>
			<news:publication_date>2026-09-07T00:00:00.000Z</news:publication_date>
			<news:title>Roundcubeが1.6.19と1.7.4を公開、12件の脆弱性を修正 — ゼロクリックのXSSやSSRF回避に対処</news:title>
		</news:news>
	</url>
</urlset>