Chinese government-linked hackers compromised Notepad++'s update infrastructure for six months, delivering malware to targeted users through a Trojaned version. The attackers exploited insufficient update verification controls in older versions and maintained access to internal services until December 2, even after the initial compromise was fixed in September. Users should update to at least version 8.9.1 to protect against this vulnerability.
1 Impression