ÐÂÐÍAndroid¶ñÒâÈí¼þ½èHugging Faceƽ̨´«²¼

°ä²¼¹¦·ò 2026-01-30

1. ÐÂÐÍAndroid¶ñÒâÈí¼þ½èHugging Faceƽ̨´«²¼


1ÔÂ29ÈÕ£¬½üÆÚ£¬Ò»ÖÖÐÂÐÍAndroid¶ñÒâÈí¼þ»î¶¯±»ÆØÀûÓÃHugging Faceƽ̨×÷Ϊ´æ´¢¿â£¬´«²¼Êýǧ¸öAPKÓÐÐ§ÔØºÉ±äÌ壬רÃÅÇÔÈ¡³£ÓýðÈÚºÍÖ§¸¶·þÎñµÄÓû§Í´´¦¡£¡£¡£Hugging Face×÷Ϊ³ÛÃûÈËΪÖÇÄÜ¡¢¡¢¡¢NLP¼°»úеѧϰģÐÍÍÐ¹ÜÆ½Ì¨£¬Òò±»ÊÓΪ¡°¿ÉÐÅÆ½Ì¨¡±¶ø³£Èƹý°²È«¼ì²â£¬´ËǰÒÑÂŴα»·¸·¨·Ö×ÓÀÄÓÃÍйܶñÒâAIÄ£ÐÍ¡£¡£¡£Õâ´Î¹¥»÷ʼÓÚ¼Ù×°³É°²È«¹¤¾ßµÄ¡°TrustBastion¡±Í¶·ÅÆ÷ÀûÓᣡ£¡£¸ÃÀûÓÃͨ¹ý¿ÖÏÅʽ¸æ°×Ðû³ÆÉ豸ÒÑϰȾ£¬ÓÕµ¼Óû§×°Öᣡ£¡£×°ÖÃºó£¬Æä½çÃæ·ÂÕÕGoogle PlayÇ¿ÖÆ¸üУ¬ÊµÔòÁªÏµtrustbastion[.]com·þÎñÆ÷£¬½«Óû§Öض¨ÏòÖÁHugging Face´æ´¢¿âÏÂÔØ¶ñÒâAPK¡£¡£¡£Bitdefender×êÑз¢ÏÖ£¬ÍþвÐÐΪÕßѡȡ·þÎñÆ÷¶Ë¶à̬ÐÔ¼¼Êõ£¬Ã¿15·ÖÖÓÌìÉúÐÂÓÐÐ§ÔØºÉ±äÌåÒÔÌӱܼì²â¡£¡£¡£µ÷²éÆÚ¼ä£¬¸Ã´æ´¢¿â´æÔÚ29Ì죬ÀÛ¼ÆÌá½»³¬6000´Î£¬ºóËä±»¹Ø±Õ£¬µ«¹¥»÷ÕßѸËÙÒÔ¡°Premium Club¡±ÐÂÃû³Æ¡¢¡¢¡¢ÐÂͼ±êÖØÆôÐж¯£¬±£ÁôÒ»Ñù¶ñÒâ´úÂë¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hugging-face-abused-to-spread-thousands-of-android-malware-variants/


2. IvantiÖÒ¸æEPMM·ì϶Òѱ»ÁãÈÕ¹¥»÷ÀûÓÃ


1ÔÂ29ÈÕ£¬½üÈÕ£¬IvantiÅû¶ÆäEndpoint Manager Mobile£¨EPMM£©²úÆ·´æÔÚÁ½¸öÑÏÖØÁãÈÕ·ì϶£¨CVE-2026-1281¡¢¡¢¡¢CVE-2026-1340£©£¬Òѱ»¹¥»÷ÕßÀûÓᣡ£¡£ÕâÁ½¸ö´úÂë×¢Èë·ì϶ÔÊÐíÔ¶³ÌδÊÚȨ¹¥»÷ÕßÔÚÊÜÓ°ÏìÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂ룬CVSSÆÀ·Ö¾ù´ï9.8£¬Êô×î¸ßΣ¼¶±ð¡£¡£¡£·ì϶ͨ¹ýÄÚ²¿ÀûÓ÷ַ¢ºÍAndroidÎļþ´«ÊäÖ°ÄÜ´¥·¢£¬¹¥»÷³¢ÊԻ᷵»Ø404 HTTPÏìÓ¦Â룬¶øºÏ·¨ÒªÇóͨ³£·µ»Ø200¡£¡£¡£Ivanti½¨ÒéÖÎÀíԱʹÓÃÕýÔò±í°×ʽÔÚApache½Ó¼ûÈÕÖ¾Öмì²âÍⲿ¹¥»÷Á÷Á¿¡£¡£¡£³É¹¦ÀûÓ÷ì϶ºó£¬¹¥»÷Õ߿ɻñÈ¡ÖÎÀíÔ±Õ˺Å¡¢¡¢¡¢Óû§Ãô¸ÐÐÅÏ¢£¨ÈçÐÕÃû¡¢¡¢¡¢ÓÊÏä¡¢¡¢¡¢É豸±êʶ·ûIMEI/MACµØÖ·£©¡¢¡¢¡¢µØÎ»Êý¾Ý£¨ÈôÆôÓøú×Ù£©¼°ÒÑ×°ÖÃÀûÓÃÇåµ¥£¬ÉõÖÁͨ¹ýAPI»òWeb½ÚÖÆÌ¨Åú¸ÄÉ豸ÅäÖã¨ÈçÈÏÖ¤ÉèÖã©¡£¡£¡£Îª¸²¸ÇÐÐ×Ù£¬¹¥»÷Õß¿ÉÄܴ۸Ļòɾ³ýÈÕÖ¾£¬Òò¶øIvantiÇ¿µ÷ÐèÓÅÏȲ鳭É豸ÍⲿÈÕÖ¾¡£¡£¡£IvantiÒѰ䲼RPM¾ç±¾»º½âµ±Ç°°æ±¾·ì϶£¬²¢´òËãÔÚ2026ÄêµÚÒ»¼¾¶ÈÍíЩʱ³½°ä²¼µÄ12.8.0.0°æ±¾ÖÐÓÀÔ¶ÐÞ¸´¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ivanti-warns-of-two-epmm-flaws-exploited-in-zero-day-attacks/


3. ¹È¸è½áºÏ½ø¹¥È«Çò×î´óסլ´úÀíÍøÂçIPIDEA


1ÔÂ29ÈÕ£¬±¾ÖÜ£¬¹È¸èÍþвµý±¨Ð¡×飨GTIG£©½áºÏÐÐÒµºÏ×÷ͬ°é¶ÔÈ«Çò×î´óסլ´úÀíÍøÂçÖ®Ò»IPIDEAÌáÒéרÏî½ø¹¥£¬¹Ø±ÕÆäÓòÃû²¢¹²ÏíSDKµý±¨¡£¡£¡£¸ÃÍøÂçÒÔ¡°¼ÓÃÜÁ÷Á¿¡¢¡¢¡¢°µ²ØIP¡±ÎªàåÍ·£¬Ðû³ÆÕ¼ÓÐ670ÍòÓû§£¬ÊµÔòͨ¹ýľÂí»¯AndroidÀûÓã¨Ç¶ÈëPacket SDKµÈ£©ºÍ¼Ù×°³ÉOneDriveSync/Windows UpdateµÄWindows¶þ½øÖÆÎļþ£¬ÔÚÓû§²»ÖªÇéϽ«É豸ת»¯Îª´úÀí³ö¿Ú½Úµã£¬ÐγÉÓÉ19¼Ò¹ØÁªÆ·ÅÆ£¨Èç360 Proxy¡¢¡¢¡¢Luna Proxy¡¢¡¢¡¢Door VPNµÈ£©×é³ÉµÄͳһ½ÚÖÆ»ù´¡ÉèÊ©£¬ÔËÓªÕßÉí·ÝÖÁ½ñ±£ÃÜ¡£¡£¡£¹È¸èÅû¶£¬ÍþвÐÐΪÕßÀûÓÃIPIDEAסլ´úÀíÍøÂçÖ´ÐÐÕË»§ÊÕÊÜ¡¢¡¢¡¢ÐéαÕ˺Ŵ´½¨¡¢¡¢¡¢Æ¾Ö¤ÇÔÈ¡¡¢¡¢¡¢Ãô¸ÐÐÅϢй¶¼°DDoS¹¥»÷¡£¡£¡£ÆäÁ½²ãC2¼Ü¹¹ÖУ¬µÚÒ»²ãÕÆ¹ÜÅäÖÃÓ빦·òÖÎÀí£¬µÚ¶þ²ãÓÉ7400̨·þÎñÆ÷·ÖÅä´úÀí¹¤×÷²¢×ª·¢Á÷Á¿¡£¡£¡£GTIG¹Û²âµ½Ò»ÖÜÄÚ³¬550¸öÍþв×é֯ʹÓÃÆä³ö¿Ú½Úµã£¬»î¶¯º­¸ÇSaaSƽ̨½Ó¼û¡¢¡¢¡¢ÃÜÂëÅçÈ÷¹¥»÷¡¢¡¢¡¢½©Ê¬ÍøÂç½ÚÖÆ¼°»ù´¡ÉèÊ©»ìºÏ¡£¡£¡£´Ëǰ£¬Ë¼¿ÆTalosÒѹØÁªIPIDEAÓëVPN/SSH±©Á¦ÆÆ½â¹¥»÷¡£¡£¡£


https://www.bleepingcomputer.com/news/security/google-disrupts-ipidea-residential-proxy-networks-fueled-by-malware/


4. Match GroupÔâShinyHunters´¹µö¹¥»÷


1ÔÂ29ÈÕ£¬È«ÇòÔÚÏßÔ¼»á¾ÞÍ·Match Group£¨ÆìÏÂÕ¼ÓÐTinder¡¢¡¢¡¢Hinge¡¢¡¢¡¢Match.com¡¢¡¢¡¢OkCupidµÈƽ̨£©Ö¤Êµ²úÉúÍøÂ簲ȫÊÂÎñ£¬µ¼ÖÂÓû§Êý¾Ýй¶¡£¡£¡£Õâ´Î¹¥»÷ÓÉÍþв×éÖ¯ShinyHuntersÌáÒ飬¸Ã×é֯й¶ÁË1.7GBѹËõÎļþ£¬ÄÚº¬Ô¼1000ÍòÌõHinge¡¢¡¢¡¢MatchºÍOkCupidÓû§ÐÅÏ¢¼Í¼¼°ÄÚ²¿Îļþ¡£¡£¡£Match Group°µÊ¾£¬ÒÑѸËÙÖÕֹδ¾­ÊÚȨ½Ó¼û£¬ÔÚÍⲿר¼ÒЭÖúϵ÷²éÏÔʾ£¬Î´Ð¹Â¶Óû§µÇ¼ƾ֤¡¢¡¢¡¢²ÆÕþÐÅÏ¢»ò¸öÈËͨѶ£¬½ö¡°ÓÐÏÞÊýÁ¿¡±µÄÓû§Êý¾ÝÊÜÓ°Ï죬²¢½«×ÃÇé֪ͨÓйØÐ¡ÎÒ¡£¡£¡£Õâ´ÎÊÂÎñÊÇShinyHuntersÐÂÌáÒéµÄÓïÒôÍøÂç´¹µö£¨vishing£©»î¶¯µÄÒ»²¿ÃÅ£¬¸Ã»î¶¯Õë¶ÔOkta¡¢¡¢¡¢Microsoft¡¢¡¢¡¢GoogleµÈ°Ù¼Ò¸ß¼ÛÖµ×éÖ¯µÄµ¥µãµÇ¼£¨SSO£©ÕË»§¡£¡£¡£¹¥»÷ÕßʹÓô¹µöÓòÃû¡°matchinternal.com¡±ÓÕµ¼Óû§½Ó¼ûαÔìÄÚ²¿µÇ¼ÃÅ»§£¬Í¨¹ýÉç»á¹¤³Ì¹¥ÆÆOkta SSOÕË»§ºó£¬½øÒ»²½½Ó¼ûMatch GroupµÄAppsFlyerÓªÏú·ÖÎöʵÀý¼°Google Drive¡¢¡¢¡¢DropboxÔÆ´æ´¢£¬ÇÔÈ¡Ô̺¬Ð¡ÎÒÉí·ÝÐÅÏ¢£¨PII£©µÄÊý¾Ý£¬µ«´ó²¿ÃÅΪ׷×ÙÐÅÏ¢¡£¡£¡£


https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/


5. ¶í¸¥À­»ùÃ×¶ûÃæ°ü³§ÔâÍøÂç¹¥»÷Ö¹©¸øÁ´ÖжÏ


1ÔÂ29ÈÕ£¬¾Ý±¾µØÃ½Ì屨µÀ£¬¶íÂÞ˹¸¥À­»ùÃ×¶ûÖÝ×î´óÃæ°ü³ö²úÉÌÖ®Ò»¸¥À­»ùÃ×¶ûÃæ°ü³§ÓÚÖÜÈÕÍí¼äÔâ·êÑÏÖØÍøÂç¹¥»÷£¬µ¼ÖÂÆäÄÚ²¿Êý×ÖÏµÍ³È«ÃæÌ±»¾¡£¡£¡£Õâ´Î¹¥»÷²¨¼°°ì¹«µçÄÔ¡¢¡¢¡¢·þÎñÆ÷¡¢¡¢¡¢µç×ÓÎĵµÖÎÀí¹¤¾ß¼°¿í·ºÊ¹ÓõÄ1CÆóÒµ¹ÜÕÊϵͳ£¬Ö±½Ó³å»÷Á˶©µ¥´¦ÖÃÓëÅäËÍÁ÷³Ì£¬Ôì³É±¾µØ¾ÓÃñ¡¢¡¢¡¢ÁãÊ۵꼰Éç»á»ú¹¹µÄʳƷ¹©¸øÁÙʱÐÔǷȱ¡£¡£¡£Ö»¹ÜÃæ°ü³ö²ú×ÔÉíδÊÜÓ°Ï죬¹¤³§ÈÔά³ÖÂú¸ººÉÔËÐУ¬µ«Êý×Ö»¯ÏµÍ³µÄ±ÀÀ£Ê¹ºÏÍ¬ÍÆ¹ãÏÝÈë»ìÂÒ¡£¡£¡£´óÐÍÁãÊÛÁ¬ËøµêËäδ³öÏÖ´ó¹æÄ £»£»õ¼Ü¿ÕÖ㬵«ÅäËÍÎÊÌâÒÑÒý·¢Ïû·ÑÕßÓÇÓô¡£¡£¡£ÎªÓ¦¶ÔÎ £»£»ú£¬¸Ã¹«Ë¾´¹Î£Æô¶¯Ó¦¼±´ëÊ©£º£ºËùÓа칫ÊÒÔ±¹¤×ªÎª24СʱÂÖ°àÖÆ£¬²¢ÁÙʱ¸´Ô­ÈËΪ´¦Öö©µ¥ºÍ·¢»õ¡£¡£¡£È»¶ø£¬¹¤³§ÉÐδ°ä²¼Êý×Ö»¯ÏµÍ³È«Ã渴ԭµÄ¾ßÌ幦·ò±í£¬½ö¾ÍÕâ´ÎÖжÏÏòºÏ×÷ͬ°éºÍÏû·ÑÕßÖÂǸ¡£¡£¡£


https://therecord.media/cyberattack-russian-bread-factory-supply-disruptions


6. Aisuru/Kimwolf½©Ê¬ÍøÂç´´31.4Tbps DDoS¹¥»÷мͼ


1ÔÂ29ÈÕ£¬CloudflareÓÚÈ¥Äê12ÔÂ19ÈÕ¼ì²â²¢»º½âÁËÒ»³¡ÓÉAisuru/Kimwolf½©Ê¬ÍøÂçÌáÒéµÄ´ó¹æÄ£DDoS¹¥»÷£¬¸Ã¹¥»÷ÒÔ31.4TbpsµÄ·åÖµÁ÷Á¿ºÍÿÃë2ÒÚ´ÎÒªÇó£¨rps£©Ë¢Ðº¹Çà¼Í¼£¬±»¶¨ÃûΪ¡°Ê¥µ®Ç°Ï¦¡±Ðж¯¡£¡£¡£Õâ´Î¹¥»÷ÖØÒªÕë¶ÔµçÕÛ·þÎñÌṩÉÌ¡¢¡¢¡¢IT×éÖ¯¼°Cloudflare»ù´¡ÉèÊ©£¬×é³É¡°Ç°ËùδÓеĺäÕ¨¡±¡£¡£¡£¹¥»÷ÌØµãÏÔÖø£º£º³¬°ëÊý¹¥»÷³ÖÐø1-2·ÖÖÓ£¬90%µÄ·åÖµÁ÷Á¿¼¯ÖÐÓÚ1-5TbpsÇø¼ä£¬94%µÄ¹¥»÷Êý¾Ý°üËÙ¶ÈÔÚÿÃë10ÒÚÖÁ50ÒÚ¸öÖ®¼ä¡£¡£¡£Ö»¹Ü¹æÄ£¾Þ´ó£¬CloudflareµÄ×Ô¶¯·ÀÓùϵͳ³É¹¦À¹½Ø£¬Î´´¥·¢ÄÚ²¿¾¯±¨¡£¡£¡£¹¥»÷Ô´À´×Ô±»ÈëÇÖµÄÎïÁªÍøÉ豸¡¢¡¢¡¢Â·ÓÉÆ÷¼°°²×¿µçÊÓ£¬Í¹ÏÔÎïÁªÍøÉ豸ÔÚ½©Ê¬ÍøÂçÖеÄÖ÷Ìâ×÷Óᣡ£¡£Cloudflare»ã±¨Ö¸³ö£¬2025ÄêµÚËÄʱ¶ÈDDoS¹¥»÷»·±ÈÔö³¤31%£¬Í¬±ÈÔö³¤58%£¬Á÷Á¿³¬100MppsµÄÍøÂç²ã¹¥»÷Ôö³¤600%£¬³¬1TbpsµÄ¹¥»÷»·±ÈÔö³¤65%¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬³¬71.5%µÄHTTP DDoS¹¥»÷Ô´×ÔÒÑÖª½©Ê¬ÍøÂ磬͹ÏÔ½©Ê¬ÍøÂç¶ÔÍøÂ簲ȫµÄ³ÖÐøÍþв¡£¡£¡£


https://www.bleepingcomputer.com/news/security/aisuru-botnet-sets-new-record-with-314-tbps-ddos-attack/