ÐÂÐÍAndroid¶ñÒâÈí¼þ½èHugging Faceƽ̨´«²¼

°ä²¼¹¦·ò 2026-01-30

1. ÐÂÐÍAndroid¶ñÒâÈí¼þ½èHugging Faceƽ̨´«²¼


1ÔÂ29ÈÕ £¬½üÆÚ £¬Ò»ÖÖÐÂÐÍAndroid¶ñÒâÈí¼þ»î¶¯±»ÆØÀûÓÃHugging Faceƽ̨×÷Ϊ´æ´¢¿â £¬´«²¼Êýǧ¸öAPKÓÐÐ§ÔØºÉ±äÌå £¬×¨ÃÅÇÔÈ¡³£ÓýðÈÚºÍÖ§¸¶·þÎñµÄÓû§Í´´¦¡£Hugging Face×÷Ϊ³ÛÃûÈËΪÖÇÄÜ¡¢NLP¼°»úе½ø½¨Ä£ÐÍÍÐ¹ÜÆ½Ì¨ £¬Òò±»ÊÓΪ¡°¿ÉÐÅÆ½Ì¨¡±¶ø³£Èƹý°²È«¼ì²â £¬´ËǰÒÑÂŴα»·¸·¨·Ö×ÓÀÄÓÃÍйܶñÒâAIÄ£ÐÍ¡£Õâ´Î¹¥»÷ʼÓÚ¼Ù×°³É°²È«¹¤¾ßµÄ¡°TrustBastion¡±Í¶·ÅÆ÷ÀûÓ᣸ÃÀûÓÃͨ¹ý¿ÖÏÅʽ¸æ°×Ðû³ÆÉ豸ÒÑϰȾ £¬ÓÕµ¼Óû§×°Öá£×°Öúó £¬Æä½çÃæ·ÂÕÕGoogle PlayÇ¿Ôì¸üР£¬ÊµÔòÁªÏµtrustbastion[.]com·þÎñÆ÷ £¬½«Óû§³Á¶¨ÏòÖÁHugging Face´æ´¢¿âÏÂÔØ¶ñÒâAPK¡£Bitdefender×êÑз¢ÏÖ £¬ÍþвÐÐΪÕßѡȡ·þÎñÆ÷¶Ë¶à̬ÐÔ¼¼Êõ £¬Ã¿15·ÖÖÓÌìÉúÐÂÓÐÐ§ÔØºÉ±äÌåÒÔÌӱܼì²â¡£µ÷²éÆÚ¼ä £¬¸Ã´æ´¢¿â´æÔÚ29Ìì £¬ÀÛ¼ÆÌá½»³¬6000´Î £¬ºóËä±»¹Ø¹Ø £¬µ«¹¥»÷ÕßѸËÙÒÔ¡°Premium Club¡±ÐÂÃû³Æ¡¢ÐÂͼ±ê³ÁÆôÐж¯ £¬±£ÁôÒ»Ñù¶ñÒâ´úÂë¡£


https://www.bleepingcomputer.com/news/security/hugging-face-abused-to-spread-thousands-of-android-malware-variants/


2. IvantiÖÒ¸æEPMM·ì϶Òѱ»ÁãÈÕ¹¥»÷ÀûÓÃ


1ÔÂ29ÈÕ £¬½üÈÕ £¬IvantiÅû¶ÆäEndpoint Manager Mobile£¨EPMM£©²úÆ·´æÔÚÁ½¸öÑϳÁÁãÈÕ·ì϶£¨CVE-2026-1281¡¢CVE-2026-1340£© £¬Òѱ»¹¥»÷ÕßÀûÓá£ÕâÁ½¸ö´úÂë×¢Èë·ì϶ÔÊÐíÔ¶³ÌδÊÚȨ¹¥»÷ÕßÔÚÊÜÓ°ÏìÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë £¬CVSSÆÀ·Ö¾ù´ï9.8 £¬Êô×î¸ßΣ¼¶±ð¡£·ì϶ͨ¹ýÄÚ²¿ÀûÓ÷ַ¢ºÍAndroidÎļþ´«ÊäÖ°ÄÜ´¥·¢ £¬¹¥»÷³¢ÊԻ᷵»Ø404 HTTPÏìÓ¦Âë £¬¶øºÏ·¨ÒªÇóͨ³£·µ»Ø200¡£Ivanti½¨ÒéÖÎÀíԱʹÓÃÕýÔò±í°×ʽÔÚApache½Ó¼ûÈÕÖ¾Öмì²â±í²¿¹¥»÷Á÷Á¿¡£³É¹¦ÀûÓ÷ì϶ºó £¬¹¥»÷Õ߿ɻñÈ¡ÖÎÀíÔ¹ØËºÅ¡¢Óû§Ãô¸ÐÐÅÏ¢£¨ÈçÐÕÃû¡¢ÓÊÏä¡¢É豸±êʶ·ûIMEI/MACµØÖ·£©¡¢µØÎ»Êý¾Ý£¨ÈôÆôÓøú×Ù£©¼°ÒÑ×°ÖÃÀûÓÃÇåµ¥ £¬ÉõÖÁͨ¹ýAPI»òWeb½ÚÔį̀Åú¸ÄÉ豸ÅäÖã¨ÈçÈÏÖ¤ÉèÖã©¡£Îª¸²¸ÇÐÐ×Ù £¬¹¥»÷Õß¿ÉÄܴ۸Ļòɾ³ýÈÕÖ¾ £¬Òò¶øIvantiÇ¿µ÷ÐèÓÅÏȲ鳭É豸±í²¿ÈÕÖ¾¡£IvantiÒѰ䲼RPM¾ç±¾»º½âµ±Ç°°æ±¾·ì϶ £¬²¢´òËãÔÚ2026ÄêµÚÒ»¼¾¶ÈÍíЩʱ³½°ä²¼µÄ12.8.0.0°æ±¾ÖÐÓÀÔ¶½¨¸´¡£


https://www.bleepingcomputer.com/news/security/ivanti-warns-of-two-epmm-flaws-exploited-in-zero-day-attacks/


3. ¹È¸è½áºÏ½ø¹¥È«Çò×î´óסլ´úÀíÍøÂçIPIDEA


1ÔÂ29ÈÕ £¬±¾ÖÜ £¬¹È¸èÍþвµý±¨Ó××飨GTIG£©½áºÏÐÐÒµºÏ×÷ͬ°é¶ÔÈ«Çò×î´óסլ´úÀíÍøÂçÖ®Ò»IPIDEAÌáÒéרÏî½ø¹¥ £¬¹Ø¹ØÆäÓòÃû²¢¹²ÏíSDKµý±¨¡£¸ÃÍøÂçÒÔ¡°¼ÓÃÜÁ÷Á¿¡¢°µ²ØIP¡±ÎªàåÍ· £¬Ðû³ÆÕ¼ÓÐ670ÍòÓû§ £¬ÊµÔòͨ¹ýľÂí»¯AndroidÀûÓã¨Ç¶ÈëPacket SDKµÈ£©ºÍ¼Ù×°³ÉOneDriveSync/Windows UpdateµÄWindows¶þ½øÔìÎļþ £¬ÔÚÓû§²»ÖªÇéϽ«É豸ת»¯Îª´úÀí³ö¿Ú½Úµã £¬ÐγÉÓÉ19¼Ò¹ØÁªÆ·ÅÆ£¨Èç360 Proxy¡¢Luna Proxy¡¢Door VPNµÈ£©×é³ÉµÄͳһ½ÚÔì»ù´¡ÉèÊ© £¬ÔËÓªÕßÉí·ÝÖÁ½ñ±£ÃÜ¡£¹È¸èÅû¶ £¬ÍþвÐÐΪÕßÀûÓÃIPIDEAסլ´úÀíÍøÂçÖ´ÐÐÕË»§ÊÕÊÜ¡¢ÐéαÕ˺Ŵ´½¨¡¢Æ¾Ö¤ÇÔÈ¡¡¢Ãô¸ÐÐÅϢй¶¼°DDoS¹¥»÷¡£ÆäÁ½²ãC2¼Ü¹¹ÖÐ £¬µÚÒ»²ãÕÆ¹ÜÅäÖÃÓ빦·òÖÎÀí £¬µÚ¶þ²ãÓÉ7400̨·þÎñÆ÷·ÖÅä´úÀí¹¤×÷²¢×ª·¢Á÷Á¿¡£GTIG¹Û²âµ½Ò»ÖÜÄÚ³¬550¸öÍþв×é֯ʹÓÃÆä³ö¿Ú½Úµã £¬»î¶¯º­¸ÇSaaSƽ̨½Ó¼û¡¢ÃÜÂëÅçÈ÷¹¥»÷¡¢½©Ê¬ÍøÂç½ÚÔì¼°»ù´¡ÉèÊ©»ìºÏ¡£´Ëǰ £¬Ë¼¿ÆTalosÒѹØÁªIPIDEAÓëVPN/SSH±©Á¦ÆÆ½â¹¥»÷¡£


https://www.bleepingcomputer.com/news/security/google-disrupts-ipidea-residential-proxy-networks-fueled-by-malware/


4. Match GroupÔâShinyHunters´¹µö¹¥»÷


1ÔÂ29ÈÕ £¬È«ÇòÔÚÏßÔ¼»á¾ÞÍ·Match Group£¨ÆìÏÂÕ¼ÓÐTinder¡¢Hinge¡¢Match.com¡¢OkCupidµÈƽ̨£©Ö¤Êµ²úÉúÍøÂ簲ȫÊÂÎñ £¬µ¼ÖÂÓû§Êý¾Ýй¶¡£Õâ´Î¹¥»÷ÓÉÍþв×éÖ¯ShinyHuntersÌáÒé £¬¸Ã×é֯й¶ÁË1.7GBѹËõÎļþ £¬ÄÚº¬Ô¼1000ÍòÌõHinge¡¢MatchºÍOkCupidÓû§ÐÅÏ¢¼Í¼¼°ÄÚ²¿Îļþ¡£Match Group°µÊ¾ £¬ÒÑѸËÙÖÕֹδ¾­ÊÚȨ½Ó¼û £¬ÔÚ±í²¿×¨¼ÒЭÖúϵ÷²éÏÔʾ £¬Î´Ð¹Â¶Óû§µÇ¼ƾ֤¡¢²ÆÕþÐÅÏ¢»ò¸öÈËͨѶ £¬½ö¡°ÓÐÏÞÊýÁ¿¡±µÄÓû§Êý¾ÝÊÜÓ°Ïì £¬²¢½«×ÃÇé֪ͨÓйØÓ×ÎÒ¡£Õâ´ÎÊÂÎñÊÇShinyHuntersÐÂÌáÒéµÄÓïÒôÍøÂç´¹µö£¨vishing£©»î¶¯µÄÒ»²¿ÃÅ £¬¸Ã»î¶¯Õë¶ÔOkta¡¢Microsoft¡¢GoogleµÈ°Ù¼Ò¸ß¼ÛÖµ×éÖ¯µÄµ¥µãµÇ¼£¨SSO£©ÕË»§¡£¹¥»÷ÕßʹÓô¹µöÓòÃû¡°matchinternal.com¡±ÓÕµ¼Óû§½Ó¼ûαÔìÄÚ²¿µÇ¼ÃÅ»§ £¬Í¨¹ýÉç»á¹¤³Ì¹¥ÆÆOkta SSOÕË»§ºó £¬½øÒ»²½½Ó¼ûMatch GroupµÄAppsFlyerÓªÏú·ÖÎöÊ·ý¼°Google Drive¡¢DropboxÔÆ´æ´¢ £¬ÇÔÈ¡Ô̺¬Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©µÄÊý¾Ý £¬µ«´ó²¿ÃÅΪ׷×ÙÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/


5. ¶í¸¥À­»ùÃ×¶ûÃæ°ü³§ÔâÍøÂç¹¥»÷Ö¹©¸øÁ´ÖжÏ


1ÔÂ29ÈÕ £¬¾Ý±¾µØÃ½Ì屨· £¬¶íÂÞ˹¸¥À­»ùÃ×¶ûÖÝ×î´óÃæ°ü³ö²úÉÌÖ®Ò»¸¥À­»ùÃ×¶ûÃæ°ü³§ÓÚÖÜÈÕÍí¼äÔâ·êÑϳÁÍøÂç¹¥»÷ £¬µ¼ÖÂÆäÄÚ²¿Êý×ÖÏµÍ³È«ÃæÌ±»¾¡£Õâ´Î¹¥»÷²¨¼°°ì¹«µçÄÔ¡¢·þÎñÆ÷¡¢µç×ÓÎĵµÖÎÀí¹¤¾ß¼°¿í·ºÊ¹ÓõÄ1CÆóÒµ¹ÜÕÊϵͳ £¬Ö±½Ó³å»÷Á˶©µ¥´¦ÖÃÓëÅäËÍÁ÷³Ì £¬Ôì³É±¾µØ¾ÓÃñ¡¢ÁãÊ۵꼰Éç»á»ú¹¹µÄʳƷ¹©¸øÁÙʱÐÔǷȱ¡£Ö»¹ÜÃæ°ü³ö²ú×ÔÉíδÊÜÓ°Ïì £¬¹¤³§ÈÔά³ÖÂú¸ººÉÔËÐÐ £¬µ«Êý×Ö»¯ÏµÍ³µÄ±ÀÀ£Ê¹ºÏÍ¬ÍÆ¹ãÏÝÈë»ìÂÒ¡£´óÐÍÁãÊÛÁ¬ËøµêËäδ³öÏÖ´ó¹æÄ£»õ¼Ü¿ÕÖà £¬µ«ÅäËÍÎÊÌâÒÑÒý·¢Ïû·ÑÕßÓÇÓô¡£ÎªÓ¦¶ÔΣ»ú £¬¸Ã¹«Ë¾´¹Î£Æô¶¯Ó¦¼±´ëÊ©£ºËùÓа칫ÊÒÔ±¹¤×ªÎª24Ó×ʱÂÖ°àÔì £¬²¢ÁÙʱ¸´Ô­ÈËΪ´¦Öö©µ¥ºÍ·¢»õ¡£È»¶ø £¬¹¤³§ÉÐδ°ä²¼Êý×Ö»¯ÏµÍ³È«Ã渴ԭµÄ¾ßÌ幦·ò±í £¬½ö¾ÍÕâ´ÎÖжÏÏòºÏ×÷ͬ°éºÍÏû·ÑÕßÖÂǸ¡£


https://therecord.media/cyberattack-russian-bread-factory-supply-disruptions


6. Aisuru/Kimwolf½©Ê¬ÍøÂç´´31.4Tbps DDoS¹¥»÷мͼ


1ÔÂ29ÈÕ £¬CloudflareÓÚÈ¥Äê12ÔÂ19ÈÕ¼ì²â²¢»º½âÁËÒ»³¡ÓÉAisuru/Kimwolf½©Ê¬ÍøÂçÌáÒéµÄ´ó¹æÄ£DDoS¹¥»÷ £¬¸Ã¹¥»÷ÒÔ31.4TbpsµÄ·åÖµÁ÷Á¿ºÍÿÃë2ÒÚ´ÎÒªÇó£¨rps£©Ë¢Ðº¹Çà¼Í¼ £¬±»¶¨ÃûΪ¡°Ê¥µ®Ç°Ï¦¡±Ðж¯¡£Õâ´Î¹¥»÷ÖØÒªÕë¶ÔµçÕÛ·þÎñÌṩÉÌ¡¢IT×éÖ¯¼°Cloudflare»ù´¡ÉèÊ© £¬×é³É¡°Ç°ËùδÓеĺäÕ¨¡±¡£¹¥»÷ÌØµãÏÔÖø£º³¬°ëÊý¹¥»÷³ÖÐø1-2·ÖÖÓ £¬90%µÄ·åÖµÁ÷Á¿¼¯ÖÐÓÚ1-5TbpsÇø¼ä £¬94%µÄ¹¥»÷Êý¾Ý°üËÙ¶ÈÔÚÿÃë10ÒÚÖÁ50ÒÚ¸öÖ®¼ä¡£Ö»¹Ü¹æÄ£¾Þ´ó £¬CloudflareµÄ×Ô¶¯·ÀÓùϵͳ³É¹¦À¹½Ø £¬Î´´¥·¢ÄÚ²¿¾¯±¨¡£¹¥»÷Ô´À´×Ô±»ÈëÇÖµÄÎïÁªÍøÉ豸¡¢Â·ÓÉÆ÷¼°°²×¿µçÊÓ £¬Í¹ÏÔÎïÁªÍøÉ豸ÔÚ½©Ê¬ÍøÂçÖеÄÖ÷Ìâ×÷Óá£Cloudflare»ã±¨Ö¸³ö £¬2025ÄêµÚËÄʱ¶ÈDDoS¹¥»÷»·±ÈÔö³¤31% £¬Í¬±ÈÔö³¤58% £¬Á÷Á¿³¬100MppsµÄÍøÂç²ã¹¥»÷Ôö³¤600% £¬³¬1TbpsµÄ¹¥»÷»·±ÈÔö³¤65%¡£ÖµÍ×ÌùÐĵÄÊÇ £¬³¬71.5%µÄHTTP DDoS¹¥»÷Ô´×ÔÒÑÖª½©Ê¬ÍøÂç £¬Í¹ÏÔ½©Ê¬ÍøÂç¶ÔÍøÂ簲ȫµÄ³ÖÐøÍþв¡£


https://www.bleepingcomputer.com/news/security/aisuru-botnet-sets-new-record-with-314-tbps-ddos-attack/