<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://cybernow.co.il/article/what-is-session-hijacking</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T10:11:19Z</news:publication_date>
      <news:title>מה זה חטיפת session, ולמה הסיסמה והאימות הדו-שלבי לא עצרו את זה?</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/unit42-agentcore-harness-shell-tool-proc-mem-jwt-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T08:15:36Z</news:publication_date>
      <news:title>פנייה אחת לתמיכה, והסוכן קרא את ה-token מהזיכרון של התהליך שהריץ אותו: מה מצאה Unit 42 ב-AWS AgentCore</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/codex-sandbox-escape-overpatch-heapjack-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T05:18:12Z</news:publication_date>
      <news:title>פתחתם מאגר קוד של מישהו אחר ושאלתם עליו שאלה, והוא כבר מריץ פקודות אצלכם: שתי בריחות מהארגז של Codex</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/wordpress-click2shell-forced-theme-install-7-1-1-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T05:18:12Z</news:publication_date>
      <news:title>מנהל האתר לוחץ על קישור, ובאתר מותקנת לבד ערכת עיצוב: מה תוקן בוורדפרס 7.1.1</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/windows-defender-false-turned-off-alert-fixed-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T15:18:35Z</news:publication_date>
      <news:title>ההתראה הודיעה שההגנה כבויה, וההגנה פעלה כרגיל: מיקרוסופט תיקנה את הבאג ב-Defender</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/talking-tilly-ai-actress-face-scan-age-check-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T15:18:35Z</news:publication_date>
      <news:title>סריקת פנים לפני השיחה, ומעקב אחרי מצב הרוח תוך כדי: מה מבקש שירות השיחות עם השחקנית שנוצרה ב-AI</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/tradertraitor-terraform-lockfile-macos-backdoors-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T14:14:35Z</news:publication_date>
      <news:title>terraform init על משימת בית מראיון עבודה, ושתי דלתות אחוריות על המק: TraderTraitor מגיעה גם למי שלא נוגע בקריפטו</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/cvss-vm2-34-cves-sandbox-escape-wave</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T10:15:07Z</news:publication_date>
      <news:title>34 רשומות CVE ב-vm2 תוך יומיים, 12 מהן בציון 10, והתיקונים כבר היו שם</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/crowdsec-tanstack-supply-chain-forensics-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T08:14:08Z</news:publication_date>
      <news:title>הקוד נגנב במאי, והארכיון עלה לפורום בספטמבר: מה גילתה CrowdSec על 170 המאגרים הפרטיים שלה</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/openai-forum-sso-account-takeover-hacktron-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T05:16:54Z</news:publication_date>
      <news:title>העלו תמונה אחת לפורום התמיכה, ומשם הגיעו לחשבונות של עובדי OpenAI</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/revolut-fake-government-data-request-leak-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-20T05:16:54Z</news:publication_date>
      <news:title>בקשת המידע הגיעה מדומיין ממשלתי אמיתי, ורבולוט שלחה דרכונים וסלפי אימות של לקוחות</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/shinyhunters-defaced-clop-leak-site-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-19T15:18:27Z</news:publication_date>
      <news:title>&quot;אולי אל תאיימו עלינו בפעם הבאה&quot;: קבוצת סחיטה פרצה לאתר ההדלפות של כופרת Clop ומאיימת לסחוט אותה</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cybernow.co.il/article/gemini-irregular-test-breached-real-companies-2026-09</loc>
    <news:news>
      <news:publication>
        <news:name>CyberNow</news:name>
        <news:language>he</news:language>
      </news:publication>
      <news:publication_date>2026-09-19T15:18:27Z</news:publication_date>
      <news:title>המודל היה אמור לתקוף חברות מומצאות, ואז ניחש סיסמה של חברה אמיתית: גוגל מאשרת שג'מיני פרץ לשלוש חברות</news:title>
    </news:news>
  </url>
</urlset>
