<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://cybernow.co.il/article/eviltokens-device-code-phishing-takedown-arrests-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T05:17:44Z</news:publication_date>
      <news:title>הקוד שביקשו מכם להקליד היה של התוקף: מיקרוסופט השביתה את EvilTokens, השירות שפרץ 12 אלף תיבות דואר</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/checkpoint-zero-day-management-spark-vpn-exploitation-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T05:17:44Z</news:publication_date>
      <news:title>בלי שם משתמש ובלי סיסמה, והשרת מריץ את הסקריפט: צ'ק פוינט חושפת חולשת יום-אפס בשרתי הניהול ומאשרת גל תקיפות על לקוחות Spark</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/fake-ai-subscription-sites-starter-kit-google-signin-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T15:18:24Z</news:publication_date>
      <news:title>האתר מהוקצע, ההתחברות דרך גוגל אמיתית, והמנוי עולה 2,000 דולר לשנה: כך נבנו יותר ממאה אתרי AI מזויפים מאותה ערכה</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/meta-muse-mac-dictation-endpoint-local-zeroday-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T15:18:24Z</news:publication_date>
      <news:title>ההכתבה נשלחת לשרת שהתוקף בחר: החולשה ב-Muse, הסוכן החדש של מטא, הופכת אותו לדלת אחורית במק</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/chainscript-nodejs-rat-polygon-contract-c2-resolver-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T14:12:12Z</news:publication_date>
      <news:title>כתובת השרת לא נמצאת בתוך הנוזקה אלא בחוזה חכם על Polygon: כך מחליפה ChainScript תשתית בלי לעדכן אף מכשיר</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/cvss-erlang-otp-tls13-unsolicited-psk-impersonation</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T10:20:41Z</news:publication_date>
      <news:title>ssl:connect החזיר {ok, Socket} מול שרת בלי תעודה בכלל: החולשה בציון 9.3 בלקוח ה-TLS 1.3 של Erlang/OTP</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/volexity-uta0565-cleangulp-fake-news-sites-chrome-windows-0day-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T08:13:30Z</news:publication_date>
      <news:title>האתר הציג את הכתבות האמיתיות של המכון, ורכיב נסתר בגודל אפס פיקסלים הריץ שרשרת ניצול: UTA0565 והנוזקה CLEANGULP</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/bigcommerce-ribon-app-storefront-script-injection-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T05:13:03Z</news:publication_date>
      <news:title>התוסף שהחנות התקינה נפרץ, והפרטים של מי שקנה בה יצאו החוצה: כך דלפו שמות, טלפונים וכתובות משלוח מחנויות BigCommerce</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/google-dpc-403m-fine-location-history-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T05:13:03Z</news:publication_date>
      <news:title>הרגולטור האירי קנס את גוגל ב-403 מיליון אירו על נתוני מיקום: שלוש ההגדרות שנבדקו נמצאות גם בטלפון שלכם</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/taskstomp-scheduled-tasks-document-theft-backdoor-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T15:17:48Z</news:publication_date>
      <news:title>הקובץ נחת על שולחן העבודה, ומאז כל מסמך חדש במחשב נשלח החוצה: כך מתחבאת TASK#STOMP מאחורי שמות של שירותי Windows</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/microsoft-entra-sms-voice-retirement-passkeys-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T15:17:48Z</news:publication_date>
      <news:title>הקוד שמגיע ב-SMS מפסיק לפתוח את חשבון העבודה: מיקרוסופט קבעה את 1 בפברואר 2027 כסוף האימות הטלפוני</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/aws-compromised-key-quarantine-policy-unit42-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T14:13:11Z</news:publication_date>
      <news:title>המפתח עלה ל-GitHub, ועשר שניות אחר כך AWS כבר צירפה לחשבון רשימת חסימות: מה AWSCompromisedKeyQuarantine באמת עוצרת</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/what-is-session-hijacking</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T10:11:19Z</news:publication_date>
      <news:title>מה זה חטיפת session, ולמה הסיסמה והאימות הדו-שלבי לא עצרו את זה?</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/unit42-agentcore-harness-shell-tool-proc-mem-jwt-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T08:15:36Z</news:publication_date>
      <news:title>פנייה אחת לתמיכה, והסוכן קרא את ה-token מהזיכרון של התהליך שהריץ אותו: מה מצאה Unit 42 ב-AWS AgentCore</news:title>
    </news:news>
  </url>
</urlset>
