Notepad++ Update Mechanism Hijacked by State-Sponsored Actors for Six Months

Introduction State-sponsored attackers compromised Notepad++’s hosting infrastructure from June through December 2025, hijacking the application’s update mechanism to deliver malicious executables to selectively targeted users. The attack did not exploit a vulnerability in Notepad++ code itself but leveraged infrastructure-level access combined with insufficient update verification controls in the WinGUp updater. No CVE has been assigned. […]

The post Notepad++ Update Mechanism Hijacked by State-Sponsored Actors for Six Months appeared first on Orca Security.

原始链接: https://orca.security/resources/blog/notepad-plus-plus-supply-chain-attack/
侵权请联系站方: [email protected]

相关推荐

换一批