Your Followed Topics

Top 2 notepad++ News Today

#1
Notepad++ says Chinese government hackers hijacked its software updates for months | TechCrunch
#1 out of 22.0M est. views10.36%
technology20h ago

Notepad++ says Chinese government hackers hijacked its software updates for months | TechCrunch

https://techcrunch.com/2026/02/02/notepad-says-chinese-government-hackers-hijacked-its-software-updates-for-months/https://www.tomshardware.com/tech-industry/cyber-security/notepad-update-server-hijacked-in-targeted-attackshttps://www.techradar.com/pro/security/notepad-hit-by-suspected-chinese-state-sponsored-hackers-heres-what-we-know-so-far
Techcrunch.com and 3 more
  • Notepad++ expanded defenses by requiring both the download signature and certificate validation, and by signing the update server responses to thwart tainted updates.
  • Direct downloads from the official Notepad++ site largely avoided the impact, highlighting the risk was concentrated on users relying on the built-in updater.
  • Rapid7’s investigation ties the incident to Lotus Blossom, a Chinese espionage group active since 2009 with operations across Asia and Central America.
Vote 49
0
#2
Notepad++ updates got hijacked for months and could have spied for China
#2 out of 236.0K est. views
technology17h ago

Notepad++ updates got hijacked for months and could have spied for China

  • Hackers hijacked Notepad++ updates for six months, redirecting targeted users to malicious manifests.
  • The breach occurred from June through December 2025, according to developer Don Ho.
  • Hackers likely belonged to a Chinese state-sponsored group and could have given remote access to keyboards.
  • Notepad++ developers terminated all attacker access by December 2, 2025.
  • Users are advised to update to version 8.8.9 or newer from the official site.
  • Independent expert Kevin Beaumont suggested monitoring for gup.exe and suspicious update.exe in TEMP.
  • The attackers targeted organizations with East Asia interests, per Don Ho’s post.
  • The updater has been updated with stronger security measures to verify updates.
  • The incident underscores risks of third‑party hosting in software supply chains.
  • Users should download updates directly from the official Notepad++ site.
Vote 3
0

Explore Your Interests

Unlimited Access
Personalized Feed
Full Experience
or
By continuing, you agree to the Privacy Policy.. You also agree to receive our newsletters, you can opt-out any time.

Explore Your Interests

Create an account and enjoy content that interests you with your personalized feed

Unlimited Access
Personalized Feed
Full Experience
or
By continuing, you agree to the Privacy Policy.. You also agree to receive our newsletters, you can opt-out any time.

Advertisement

Advertisement