<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"><url><loc>https://kkm-mako.com/blog/articles/cacti-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T22:51:53+00:00</news:publication_date><news:title>ネットワーク監視ツールCactiに認証なしでデータベースを抜かれる脆弱性、CVE-2026-39893、v1.2.31へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/rocketchat-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-24T21:51:34+00:00</news:publication_date><news:title>Three Unauthenticated Takeover Flaws in Team Chat Rocket.Chat (CVE-2026-45688 and More) — Update Now</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/rocketchat-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T21:51:17+00:00</news:publication_date><news:title>社内チャット基盤Rocket.Chatに認証なしで乗っ取りの脆弱性3件、CVE-2026-45688ほか最新版へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/gogs-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-24T21:50:21+00:00</news:publication_date><news:title>Six Flaws in Self-Hosted Git Service Gogs, Unauthenticated Takeover (CVE-2026-52813 and More) — Update to v0.14.3</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/gogs-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T21:50:04+00:00</news:publication_date><news:title>セルフホスト型Git『Gogs』に脆弱性6件、認証なしで乗っ取り可能、CVE-2026-52813ほかv0.14.3へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/mastodon-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-24T20:46:39+00:00</news:publication_date><news:title>SSRF Flaw in Mastodon Lets the Server Be Abused to Reach Cloud Secrets (CVE-2026-47389) — Update Now</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/mastodon-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T20:46:22+00:00</news:publication_date><news:title>分散型SNS Mastodonにサーバーを踏み台にされる脆弱性、クラウドの鍵が盗まれる恐れ、CVE-2026-47389、修正版へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/jellyfin-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-24T19:54:21+00:00</news:publication_date><news:title>Two File-Write Flaws in Self-Hosted Media Server Jellyfin (CVE-2026-48793 and More) — Update to v10.11.10</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/jellyfin-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T19:54:04+00:00</news:publication_date><news:title>自宅メディアサーバーJellyfinに脆弱性2件、ファイル書き換えの恐れ、CVE-2026-48793ほかv10.11.10へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/ghost-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-24T19:53:10+00:00</news:publication_date><news:title>Cache-Poisoning Takeover Flaw in Publishing Platform Ghost (CVE-2026-53943) — Update to v6.37.0</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/ghost-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T19:52:51+00:00</news:publication_date><news:title>ブログ作成ツールGhostにキャッシュ汚染で乗っ取りの脆弱性、CVE-2026-53943、v6.37.0へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/rclone-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-24T19:51:54+00:00</news:publication_date><news:title>Unauthenticated Remote Takeover Flaw in Cloud Sync Tool Rclone (CVE-2026-49980) — Update to v1.74.3</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/rclone-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T19:51:38+00:00</news:publication_date><news:title>クラウド保存ツールRcloneに認証なしで遠隔操作される脆弱性、CVE-2026-49980、v1.74.3へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/warp-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-24T18:47:41+00:00</news:publication_date><news:title>Four Flaws in AI Agent Terminal Warp (CVE-2026-48704 and More) — Update to the Latest Build</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/warp-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T18:47:24+00:00</news:publication_date><news:title>AIエージェント搭載ターミナルWarpに脆弱性4件、開いただけでコマンド実行の恐れ、CVE-2026-48704ほか最新版へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/feast-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-24T16:48:15+00:00</news:publication_date><news:title>Unauthenticated Server Takeover Flaw in ML Feature Store Feast (CVE-2026-56121) — Update to v0.63.0</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/feast-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T16:47:57+00:00</news:publication_date><news:title>AIの学習データ基盤Feastに認証なしでサーバー乗っ取りの脆弱性、CVE-2026-56121、v0.63.0へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/capgo-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-24T14:51:10+00:00</news:publication_date><news:title>Many Flaws in Capacitor Live-Update Service Capgo (CVE-2026-56237 and More) — Update to v12.128.2 Now</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/capgo-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T14:50:54+00:00</news:publication_date><news:title>スマホアプリ即時更新サービスCapgoに脆弱性多数、アカウント乗っ取りの恐れ、CVE-2026-56237、v12.128.2へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/ultimate-member-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-24T09:13:54+00:00</news:publication_date><news:title>Admin Takeover Flaw in WordPress 'Ultimate Member' (CVE-2026-7761) — Update to v2.12.0 Now</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/ultimate-member-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T09:13:36+00:00</news:publication_date><news:title>WordPress『Ultimate Member』に管理者乗っ取りの脆弱性、CVE-2026-7761、最新版2.12.0へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/geovision-gvio-box-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-24T06:17:46+00:00</news:publication_date><news:title>8 Takeover Flaws in GeoVision GV-I/O Box 4E (CVE-2026-12485 and more) — Update to v2.12 Now</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/geovision-gvio-box-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T06:17:28+00:00</news:publication_date><news:title>GeoVision防犯機器に乗っ取りの脆弱性8件、CVE-2026-12485ほか、修正版v2.12へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/style-dictionary-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-24T02:46:27+00:00</news:publication_date><news:title>Style Dictionary flaw CVE-2026-54639: a crafted token can poison your build — update to 5.4.4</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/style-dictionary-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T02:46:08+00:00</news:publication_date><news:title>Style Dictionaryにビルド汚染の脆弱性 CVE-2026-54639、5.4.4へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/moneyforward-security-incidents/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-24T01:18:26+00:00</news:publication_date><news:title>Money Forward: ~62,901 records may have leaked — personal data left on GitHub</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/moneyforward-security-incidents/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-24T01:18:08+00:00</news:publication_date><news:title>マネーフォワード6.3万人分の情報流出、原因はGitHubに置いた個人情報</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/sakana-ai-fugu-explained/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-23T13:27:13+00:00</news:publication_date><news:title>What Is Sakana AI's "Fugu"? The Japanese AI That Bundles Other AIs</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/sakana-ai-fugu-explained/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-23T13:26:55+00:00</news:publication_date><news:title>Sakana AIの新AI「Fugu」とは、複数のAIを束ねる日本の実力</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/manageengine-ad360-sso-account-takeover-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-23T10:15:24+00:00</news:publication_date><news:title>ManageEngine AD360 Account Takeover (CVE-2026-11374): Update Now</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/manageengine-ad360-sso-account-takeover-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-23T10:15:06+00:00</news:publication_date><news:title>企業のID管理ManageEngineに乗っ取りの欠陥 CVE-2026-11374、更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/kddi-isp-mail-breach/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-23T08:24:33+00:00</news:publication_date><news:title>KDDI: 14.22M Emails &amp; Passwords Possibly Leaked at @nifty, BIGLOBE</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/kddi-isp-mail-breach/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-23T08:24:16+00:00</news:publication_date><news:title>KDDIのメール1422万件漏えいか、@niftyやBIGLOBEも パスワード変更を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/expr-eval-code-injection-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-23T06:19:57+00:00</news:publication_date><news:title>expr-eval Code Injection via toJSFunction (CVE-2026-12866, CVSS 9.8): Never Pass Untrusted Input, Move to expr-eval-fork</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/expr-eval-code-injection-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-23T06:19:39+00:00</news:publication_date><news:title>計算用JS部品expr-evalにコード実行の欠陥 CVE-2026-12866、入力に注意</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/faststone-image-viewer-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-23T02:20:16+00:00</news:publication_date><news:title>Unpatched Code-Execution Flaws in FastStone Image Viewer: CVE-2026-30040 / 30041 — No Fix Yet</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/faststone-image-viewer-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-23T02:19:59+00:00</news:publication_date><news:title>画像ソフトFastStoneに未修正の脆弱性 CVE-2026-30040、開く前に注意</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/windows-bitlocker-winre-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-23T02:18:59+00:00</news:publication_date><news:title>Windows BitLocker Bypassed in Minutes via WinRE: CVE-2026-45585 (YellowKey) — Apply the June Update</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/windows-bitlocker-winre-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-23T02:18:42+00:00</news:publication_date><news:title>WindowsのBitLocker暗号化を突破できる欠陥 CVE-2026-45585、更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/vllm-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-23T00:18:57+00:00</news:publication_date><news:title>Two vLLM Flaws: API-Key Bypass (CVE-2026-48746, CVSS 9.1) &amp; Dependency Confusion (CVE-2026-54232) — Update to 0.22.1</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/vllm-cve/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-23T00:18:37+00:00</news:publication_date><news:title>AI基盤vLLMにAPIキー回避の欠陥 CVE-2026-48746ほか、0.22.1へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/crawl4ai-cve-2026-56266/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-22T23:15:19+00:00</news:publication_date><news:title>Unauthenticated SSRF in Crawl4AI: CVE-2026-56266 (CVSS 8.6/9.2) — Update to 0.8.7</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/crawl4ai-cve-2026-56266/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-22T23:14:59+00:00</news:publication_date><news:title>AIクローラーCrawl4AIに認証不要の重大欠陥 CVE-2026-56266、0.8.7へ</news:title></news:news></url></urlset>