Notepad++ Server Hijacking Exposed: Update Mechanism Compromised for Six Months
The developer of the popular text editor Notepad++, Don Ho, confirmed that the application's update servers were compromised between June and December 2025. Ho suggested the attack was likely orchestrated by a Chinese state-sponsored group targeting specific users. The vulnerability allowed attackers to potentially redirect users to malicious update manifests, granting remote access.