ÐÂÐÍAndroid¶ñÒâÈí¼þ½èHugging Faceƽ̨´«²¼

°ä²¼¹¦·ò 2026-01-30

1. ÐÂÐÍAndroid¶ñÒâÈí¼þ½èHugging Faceƽ̨´«²¼


1ÔÂ29ÈÕ£¬½üÆÚ£¬Ò»ÖÖÐÂÐÍAndroid¶ñÒâÈí¼þ»î¶¯±»ÆØÀûÓÃHugging Faceƽ̨×÷Ϊ´æ´¢¿â£¬´«²¼Êýǧ¸öAPKÓÐÐ§ÔØºÉ±äÌ壬רÃÅÇÔÈ¡³£ÓýðÈÚºÍÖ§¸¶·þÎñµÄÓû§Í´´¦¡£Hugging Face×÷Ϊ³ÛÃûÈËΪÖÇÄÜ¡¢NLP¼°»úе½ø½¨Ä£ÐÍÍÐ¹ÜÆ½Ì¨£¬Òò±»ÊÓΪ¡°¿ÉÐÅÆ½Ì¨¡±¶ø³£Èƹý°²È«¼ì²â£¬´ËǰÒÑÂŴα»·¸·¨·Ö×ÓÀÄÓÃÍйܶñÒâAIÄ£ÐÍ¡£Õâ´Î¹¥»÷ʼÓÚ¼Ù×°³É°²È«¹¤¾ßµÄ¡°TrustBastion¡±Í¶·ÅÆ÷ÀûÓ᣸ÃÀûÓÃͨ¹ý¿ÖÏÅʽ¸æ°×Ðû³ÆÉ豸ÒÑϰȾ£¬ÓÕµ¼Óû§×°Öá£×°Öú󣬯ä½çÃæ·ÂÕÕGoogle PlayÇ¿Ôì¸üУ¬ÊµÔòÁªÏµtrustbastion[.]com·þÎñÆ÷£¬½«Óû§³Á¶¨ÏòÖÁHugging Face´æ´¢¿âÏÂÔØ¶ñÒâAPK¡£Bitdefender×êÑз¢ÏÖ£¬ÍþвÐÐΪÕßѡȡ·þÎñÆ÷¶Ë¶à̬ÐÔ¼¼Êõ£¬Ã¿15·ÖÖÓÌìÉúÐÂÓÐÐ§ÔØºÉ±äÌåÒÔÌӱܼì²â¡£µ÷²éÆÚ¼ä£¬¸Ã´æ´¢¿â´æÔÚ29Ì죬ÀÛ¼ÆÌá½»³¬6000´Î£¬ºóËä±»¹Ø¹Ø£¬µ«¹¥»÷ÕßѸ¿ìÒÔ¡°Premium Club¡±ÐÂÃû³Æ¡¢ÐÂͼ±ê³ÁÆôÐж¯£¬±£ÁôÒ»Ñù¶ñÒâ´úÂë¡£


https://www.bleepingcomputer.com/news/security/hugging-face-abused-to-spread-thousands-of-android-malware-variants/


2. IvantiÖÒ¸æEPMM·ì϶Òѱ»ÁãÈÕ¹¥»÷ÀûÓÃ


1ÔÂ29ÈÕ£¬½üÈÕ£¬IvantiÅû¶ÆäEndpoint Manager Mobile£¨EPMM£©²úÆ·´æÔÚÁ½¸öÑϳÁÁãÈÕ·ì϶£¨CVE-2026-1281¡¢CVE-2026-1340£©£¬Òѱ»¹¥»÷ÕßÀûÓá£ÕâÁ½¸ö´úÂë×¢Èë·ì϶ÔÊÐíÔ¶³ÌδÊÚȨ¹¥»÷ÕßÔÚÊÜÓ°ÏìÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂ룬CVSSÆÀ·Ö¾ù´ï9.8£¬Êô×î¸ßΣ¼¶±ð¡£·ì϶ͨ¹ýÄÚ²¿ÀûÓ÷ַ¢ºÍAndroidÎļþ´«ÊäÖ°ÄÜ´¥·¢£¬¹¥»÷³¢ÊԻ᷵»Ø404 HTTPÏìÓ¦Â룬¶øºÏ·¨ÒªÇóͨ³£·µ»Ø200¡£Ivanti½¨ÒéÖÎÀíԱʹÓÃÕýÔò±í°×ʽÔÚApache½Ó¼ûÈÕÖ¾Öмì²â±í²¿¹¥»÷Á÷Á¿¡£³É¹¦ÀûÓ÷ì϶ºó£¬¹¥»÷Õ߿ɻñÈ¡ÖÎÀíÔ¹ØËºÅ¡¢Óû§Ãô¸ÐÐÅÏ¢£¨ÈçÐÕÃû¡¢ÓÊÏä¡¢É豸±êʶ·ûIMEI/MACµØÖ·£©¡¢µØÎ»Êý¾Ý£¨ÈôÆôÓøú×Ù£©¼°ÒÑ×°ÖÃÀûÓÃÇåµ¥£¬ÉõÖÁͨ¹ýAPI»òWeb½ÚÔį̀Åú¸ÄÉ豸ÅäÖã¨ÈçÈÏÖ¤ÉèÖã©¡£Îª¸²¸ÇÐÐ×Ù£¬¹¥»÷Õß¿ÉÄܴ۸Ļòɾ³ýÈÕÖ¾£¬Òò¶øIvantiÇ¿µ÷ÐèÓÅÏȲ鳭É豸±í²¿ÈÕÖ¾¡£IvantiÒѰ䲼RPM¾ç±¾»º½âµ±Ç°°æ±¾·ì϶£¬²¢´òËãÔÚ2026ÄêµÚÒ»¼¾¶ÈÍíЩʱ³½°ä²¼µÄ12.8.0.0°æ±¾ÖÐÓÀÔ¶½¨¸´¡£


https://www.bleepingcomputer.com/news/security/ivanti-warns-of-two-epmm-flaws-exploited-in-zero-day-attacks/


3. ¹È¸è½áºÏ½ø¹¥È«Çò×î´óסլ´úÀíÍøÂçIPIDEA


1ÔÂ29ÈÕ£¬±¾ÖÜ£¬¹È¸èÍþвµý±¨Ó××飨GTIG£©½áºÏÐÐÒµºÏ×÷ͬ°é¶ÔÈ«Çò×î´óסլ´úÀíÍøÂçÖ®Ò»IPIDEAÌáÒéרÏî½ø¹¥£¬¹Ø¹ØÆäÓòÃû²¢¹²ÏíSDKµý±¨¡£¸ÃÍøÂçÒÔ¡°¼ÓÃÜÁ÷Á¿¡¢°µ²ØIP¡±ÎªàåÍ·£¬Ðû³ÆÕ¼ÓÐ670ÍòÓû§£¬ÊµÔòͨ¹ýľÂí»¯AndroidÀûÓã¨Ç¶ÈëPacket SDKµÈ£©ºÍ¼Ù×°³ÉOneDriveSync/Windows UpdateµÄWindows¶þ½øÔìÎļþ£¬ÔÚÓû§²»ÖªÇéϽ«É豸ת»¯Îª´úÀí³ö¿Ú½Úµã£¬ÐγÉÓÉ19¼Ò¹ØÁªÆ·ÅÆ£¨Èç360 Proxy¡¢Luna Proxy¡¢Door VPNµÈ£©×é³ÉµÄͳһ½ÚÔì»ù´¡ÉèÊ©£¬ÔËÓªÕßÉí·ÝÖÁ½ñ±£ÃÜ¡£¹È¸èÅû¶£¬ÍþвÐÐΪÕßÀûÓÃIPIDEAסլ´úÀíÍøÂçÖ´ÐÐÕË»§ÊÕÊÜ¡¢ÐéαÕ˺Ŵ´½¨¡¢Æ¾Ö¤ÇÔÈ¡¡¢Ãô¸ÐÐÅϢй¶¼°DDoS¹¥»÷¡£ÆäÁ½²ãC2¼Ü¹¹ÖУ¬µÚÒ»²ãÕÆ¹ÜÅäÖÃÓ빦·òÖÎÀí£¬µÚ¶þ²ãÓÉ7400̨·þÎñÆ÷·ÖÅä´úÀí¹¤×÷²¢×ª·¢Á÷Á¿¡£GTIG¹Û²âµ½Ò»ÖÜÄÚ³¬550¸öÍþв×é֯ʹÓÃÆä³ö¿Ú½Úµã£¬»î¶¯º­¸ÇSaaSƽ̨½Ó¼û¡¢ÃÜÂëÅçÈ÷¹¥»÷¡¢½©Ê¬ÍøÂç½ÚÔì¼°»ù´¡ÉèÊ©»ìºÏ¡£´Ëǰ£¬Ë¼¿ÆTalosÒѹØÁªIPIDEAÓëVPN/SSH±©Á¦ÆÆ½â¹¥»÷¡£


https://www.bleepingcomputer.com/news/security/google-disrupts-ipidea-residential-proxy-networks-fueled-by-malware/


4. Match GroupÔâShinyHunters´¹µö¹¥»÷


1ÔÂ29ÈÕ£¬È«ÇòÔÚÏßÔ¼»á¾ÞÍ·Match Group£¨ÆìÏÂÕ¼ÓÐTinder¡¢Hinge¡¢Match.com¡¢OkCupidµÈƽ̨£©Ö¤Êµ²úÉúÍøÂ簲ȫÊÂÎñ£¬µ¼ÖÂÓû§Êý¾Ýй¶¡£Õâ´Î¹¥»÷ÓÉÍþв×éÖ¯ShinyHuntersÌáÒ飬¸Ã×é֯й¶ÁË1.7GBѹËõÎļþ£¬ÄÚº¬Ô¼1000ÍòÌõHinge¡¢MatchºÍOkCupidÓû§ÐÅÏ¢¼Í¼¼°ÄÚ²¿Îļþ¡£Match Group°µÊ¾£¬ÒÑѸ¿ìÖÕֹδ¾­ÊÚȨ½Ó¼û£¬ÔÚ±í²¿×¨¼ÒЭÖúϵ÷²éÏÔʾ£¬Î´Ð¹Â¶Óû§µÇ¼ƾ֤¡¢²ÆÕþÐÅÏ¢»ò¸öÈËͨѶ£¬½ö¡°ÓÐÏÞÊýÁ¿¡±µÄÓû§Êý¾ÝÊÜÓ°Ï죬²¢½«×ÃÇé֪ͨÓйØÓ×ÎÒ¡£Õâ´ÎÊÂÎñÊÇShinyHuntersÐÂÌáÒéµÄÓïÒôÍøÂç´¹µö£¨vishing£©»î¶¯µÄÒ»²¿ÃÅ£¬¸Ã»î¶¯Õë¶ÔOkta¡¢Microsoft¡¢GoogleµÈ°Ù¼Ò¸ß¼ÛÖµ×éÖ¯µÄµ¥µãµÇ¼£¨SSO£©ÕË»§¡£¹¥»÷ÕßʹÓô¹µöÓòÃû¡°matchinternal.com¡±ÓÕµ¼Óû§½Ó¼ûαÔìÄÚ²¿µÇ¼ÃÅ»§£¬Í¨¹ýÉç»á¹¤³Ì¹¥ÆÆOkta SSOÕË»§ºó£¬½øÒ»²½½Ó¼ûMatch GroupµÄAppsFlyerÓªÏú·ÖÎöÊ·ý¼°Google Drive¡¢DropboxÔÆ´æ´¢£¬ÇÔÈ¡Ô̺¬Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©µÄÊý¾Ý£¬µ«´ó²¿ÃÅΪ׷×ÙÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/


5. ¶í¸¥À­»ùÃ×¶ûÃæ°ü³§ÔâÍøÂç¹¥»÷Ö¹©¸øÁ´ÖжÏ


1ÔÂ29ÈÕ£¬¾Ý±¾µØÃ½Ì屨·£¬¶íÂÞ˹¸¥À­»ùÃ×¶ûÖÝ×î´óÃæ°ü³ö²úÉÌÖ®Ò»¸¥À­»ùÃ×¶ûÃæ°ü³§ÓÚÖÜÈÕÍí¼äÔâ·êÑϳÁÍøÂç¹¥»÷£¬µ¼ÖÂÆäÄÚ²¿Êý×ÖÏµÍ³È«ÃæÌ±»¾¡£Õâ´Î¹¥»÷²¨¼°°ì¹«µçÄÔ¡¢·þÎñÆ÷¡¢µç×ÓÎĵµÖÎÀí¹¤¾ß¼°¿í·ºÊ¹ÓõÄ1CÆóÒµ¹ÜÕÊϵͳ£¬Ö±½Ó³å»÷Á˶©µ¥´¦ÖÃÓëÅäËÍÁ÷³Ì£¬Ôì³É±¾µØ¾ÓÃñ¡¢ÁãÊ۵꼰Éç»á»ú¹¹µÄʳƷ¹©¸øÁÙʱÐÔǷȱ¡£Ö»¹ÜÃæ°ü³ö²ú×ÔÉíδÊÜÓ°Ï죬¹¤³§ÈÔά³ÖÂú¸ººÉÔËÐУ¬µ«Êý×Ö»¯ÏµÍ³µÄ±ÀÀ£Ê¹ºÏÍ¬ÍÆ¹ãÏÝÈë»ìÂÒ¡£´óÐÍÁãÊÛÁ¬ËøµêËäδ³öÏÖ´ó¹æÄ£»õ¼Ü¿ÕÖ㬵«ÅäËÍÎÊÌâÒÑÒý·¢Ïû·ÑÕßÓÇÓô¡£ÎªÓ¦¶ÔΣ»ú£¬¸Ã¹«Ë¾´¹Î£Æô¶¯Ó¦¼±´ëÊ©£ºËùÓа칫ÊÒÔ±¹¤×ªÎª24Ó×ʱÂÖ°àÔ죬²¢ÁÙʱ¸´Ô­ÈËΪ´¦Öö©µ¥ºÍ·¢»õ¡£È»¶ø£¬¹¤³§ÉÐδ°ä²¼Êý×Ö»¯ÏµÍ³È«Ã渴ԭµÄ¾ßÌ幦·ò±í£¬½ö¾ÍÕâ´ÎÖжÏÏòºÏ×÷ͬ°éºÍÏû·ÑÕßÖÂǸ¡£


https://therecord.media/cyberattack-russian-bread-factory-supply-disruptions


6. Aisuru/Kimwolf½©Ê¬ÍøÂç´´31.4Tbps DDoS¹¥»÷мͼ


1ÔÂ29ÈÕ£¬CloudflareÓÚÈ¥Äê12ÔÂ19ÈÕ¼ì²â²¢»º½âÁËÒ»³¡ÓÉAisuru/Kimwolf½©Ê¬ÍøÂçÌáÒéµÄ´ó¹æÄ£DDoS¹¥»÷£¬¸Ã¹¥»÷ÒÔ31.4TbpsµÄ·åÖµÁ÷Á¿ºÍÿÃë2ÒÚ´ÎÒªÇó£¨rps£©Ë¢Ðº¹Çà¼Í¼£¬±»¶¨ÃûΪ¡°Ê¥µ®Ç°Ï¦¡±Ðж¯¡£Õâ´Î¹¥»÷ÖØÒªÕë¶ÔµçÕÛ·þÎñÌṩÉÌ¡¢IT×éÖ¯¼°Cloudflare»ù´¡ÉèÊ©£¬×é³É¡°Ç°ËùδÓеĺäÕ¨¡±¡£¹¥»÷ÌØµãÏÔÖø£º³¬°ëÊý¹¥»÷³ÖÐø1-2·ÖÖÓ£¬90%µÄ·åÖµÁ÷Á¿¼¯ÖÐÓÚ1-5TbpsÇø¼ä£¬94%µÄ¹¥»÷Êý¾Ý°ü¿ìÂÊÔÚÿÃë10ÒÚÖÁ50ÒÚ¸öÖ®¼ä¡£Ö»¹Ü¹æÄ£¾Þ´ó£¬CloudflareµÄ×Ô¶¯·ÀÓùϵͳ³É¹¦À¹½Ø£¬Î´´¥·¢ÄÚ²¿¾¯±¨¡£¹¥»÷Ô´À´×Ô±»ÈëÇÖµÄÎïÁªÍøÉ豸¡¢Â·ÓÉÆ÷¼°°²×¿µçÊÓ£¬Í¹ÏÔÎïÁªÍøÉ豸ÔÚ½©Ê¬ÍøÂçÖеÄÖ÷Ìâ×÷Óá£Cloudflare»ã±¨Ö¸³ö£¬2025ÄêµÚËÄʱ¶ÈDDoS¹¥»÷»·±ÈÔö³¤31%£¬Í¬±ÈÔö³¤58%£¬Á÷Á¿³¬100MppsµÄÍøÂç²ã¹¥»÷Ôö³¤600%£¬³¬1TbpsµÄ¹¥»÷»·±ÈÔö³¤65%¡£ÖµÍ×ÌùÐĵÄÊÇ£¬³¬71.5%µÄHTTP DDoS¹¥»÷Ô´×ÔÒÑÖª½©Ê¬ÍøÂ磬͹ÏÔ½©Ê¬ÍøÂç¶ÔÍøÂ簲ȫµÄ³ÖÐøÍþв¡£


https://www.bleepingcomputer.com/news/security/aisuru-botnet-sets-new-record-with-314-tbps-ddos-attack/