Security News

Cybersecurity news aggregator

📦
CRITICAL Attacks Help Net Security

How state-sponsored attackers hijacked Notepad++ updates

Suspected Chinese state-sponsored attackers hijacked the Notepad++ update mechanism by compromising the software project’s shared hosting server. The attackers intercepted and redirected update traffic, potentially delivering malicious payloads to users.
Read Full Article →

Suspected Chinese state-sponsored attackers hijacked the Notepad++ update mechanism by compromising the software project’s shared hosting server and intercepting and redirecting update traffic destined for notepad-plus-plus.org, the software’s maintainer Don Ho confirmed on Monday. The attack timeline In early December 2025, security researcher Kevin Beaumont said that he knew of three organizations that have had security incidents traced back to Notepad++ processes providing the attackers initial access to the computers. “I’ve only talked to a … More → The post How state-sponsored attackers hijacked Notepad++ updates appeared first on Help Net Security .

Share this article