Tools

News

Notícias

Classificados

Cursos

Broker

IPv4:

IPv6:

 

UpOrDown
Ping
MTR
Smokeping
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc
IP Extractor
Uptime Monitor

Notepad++ updater hack spans six months

Image © Arstechnica
The Notepad++ updater infrastructure was compromised for six months, enabling attackers to deliver backdoored updates to targeted users.

Notepad++’s update infrastructure was compromised for six months by suspected China-state actors, who used access to distribute backdoored updates to a targeted set of users. Developers said the incident affected a portion of Notepad++ users but did not specify numbers.

The attack began last June with an infrastructure-level compromise that allowed malicious parties to intercept and redirect update traffic destined for notepad-plus-plus.org. By doing so, they delivered tampered updates to selected targets while ordinary users received legitimate updates.

Notepad++ didn’t regain control of its update system until December. Officials with the hosting provider told incident responders that the breach persisted until September 2, and attackers retained credentials to internal services through December 2, enabling ongoing manipulation of update traffic to malicious servers.

Independent researchers including Kevin Beaumont noted that three organizations reported security incidents involving devices with Notepad++. The incidents were described as hands-on keyboard activity, implying the attackers gained direct control through a web-based interface. Beaumont said the organizations have East Asia interests, complicating attribution.

The investigation highlights how older Notepad++ versions lacked robust update verification. Notepad++ updated its updater, known as GUP or WinGUP, with version 8.8.8 in mid-November to harden it, but researchers say the risk remained. The updater system fetches the update URL via gup.xml and downloads the files to the device’s TEMP directory before executing them.

 

Arstechnica

Notícias relacionadas

TIM: tratativas com IHS permanecem não vinculantes
Lula amplia atuação da economia digital com CADE e Redata
Banda Larga B2B cresce em 2025
IoT impulsiona mercado móvel 2025
Supremo respalda políticas de proteção de dados
China planeja fábrica de máquinas no Nordeste

O ISP.Tools sobrevive graças aos anúncios.

Considere desativar seu bloqueador de anúncios.
Prometemos não ser intrusivos.

Consentimento para cookies

Utilizamos cookies para melhorar a sua experiência no nosso site.

Ao utilizar o nosso site, você concorda com o uso de cookies. Saiba mais