Noti.Group RSS Feed
  • Contact Us
Sunday, March 15, 2026
Noti Group Logo
  • Home
  • World News
  • Business
  • Health
  • Sports
  • Entertainment
No Result
View All Result
  • Home
  • World News
  • Business
  • Health
  • Sports
  • Entertainment
No Result
View All Result
Noti Group
No Result
View All Result
ADVERTISEMENT

Notepad++ updates got hijacked for months and could have spied for China

in Technology
Reading Time: 2 mins read
395 16
A A
0
Two cybersecurity employees plead guilty to carrying out ransomware attacks
137
SHARES
6.9k
VIEWS
ShareShareShareShareShare

Users of the text and code editor Notepad++ may have unknowingly downloaded a malicious update for the app after its shared hosting servers were hijacked last year. On Monday, the app’s developer, Don Ho, posted an update on the attack with more details, including that the hackers were “likely a Chinese state-sponsored group” and that the app’s servers were vulnerable for roughly six months from June through December 2nd, 2025.

The post explains that the hijacking occurred on the app’s unnamed, now-former hosting provider’s end, stating that “Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests.” When victims were redirected, their app update could be replaced with a malicious executable that, according to independent cybersecurity expert Kevin Beaumont, may have given the hackers remote access to a victim’s keyboard.

Don Ho’s post also adds that the attack involved “highly selective targeting” in terms of the victims it redirected away from the legitimate Notepad++ website. Kevin Beaumont noted that the victims he spoke with “are [organizations] with interests in East Asia.” So, while this is a serious security vulnerability, it’s possible that the hackers were busy watching specific people instead of just anyone.

The developer did not specify when they became aware of the attack, but said that “all attacker access was definitively terminated” by December 2nd. The Notepad++ updater has been updated itself with stronger security measures to check for tampering and verify that updates are legitimate.

Notepad++ users should make sure they are on at least version 8.8.9, which addressed the vulnerabilities from the hijacking attack, and they should probably download that version directly from the Notepad++ website. Additionally, Kevin Beaumont suggested users double-check that they’re not using an unofficial version of Notepad++, keep a close eye on activity from “gup.exe,” the app’s updater, and check for a suspicious “update.exe” or “AutoUpdater.exe” file in their TEMP folder.

Notably, Don Ho, the developer of Notepad++, criticized the Chinese government in a 2019 app update. He called that version the “Free Uyghur” edition, and told noti.group at the time that his website had faced DDoS attacks in response.

[Notigroup Newsroom in collaboration with other media outlets, with information from the following sources]

Tags: NewssecurityTech
Previous Post

Play $5, get $75 in fantasy bonus entries for Timberwolves vs. Grizzlies

Next Post

Crunchyroll is raising prices again

Related Posts

Aether OS is computer in a browser built for the AT Protocol
Technology

Aether OS is computer in a browser built for the AT Protocol

March 15, 2026
AI Czar David Sacks wants Trump to ‘get out’ of Iran
Technology

AI Czar David Sacks wants Trump to ‘get out’ of Iran

March 15, 2026
The Samsung Galaxy Buds 4 Pro in their charging case on a white tabletop.
Technology

Samsung Galaxy Buds 4 Pro review: the top choice for your Galaxy phone

March 15, 2026
The fast rise and epic fall of Clubhouse
Technology

The fast rise and epic fall of Clubhouse

March 15, 2026
Load More
Next Post
Crunchyroll is raising prices again

Crunchyroll is raising prices again

No Result
View All Result

Recent Posts

  • Play $5, get $50 in fantasy bonus entries for Knicks vs. Warriors
  • Fanatics Sportsbook promo code NYPOST: Bet $5, get $200 FanCash for Japan vs. Venezuela
  • Odds, picks, best for World Baseball Classic semifinals
  • How to watch USA vs. Dominican Republic in the WBC 2026 semifinals for free
  • Yale chokes away March Madness bid to Penn with head-scratching decision

Recent Comments

  • Stefano on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • Van Hens on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • Ioannis K on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • Panagiotis Nikolaos on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • John Miele on UK government suggests deleting files to save water

Noti Group All rights reserved

No Result
View All Result
Noti Group

What’s New Here

  • Play $5, get $50 in fantasy bonus entries for Knicks vs. Warriors
  • Fanatics Sportsbook promo code NYPOST: Bet $5, get $200 FanCash for Japan vs. Venezuela
  • Odds, picks, best for World Baseball Classic semifinals

Topics to Cover!

  • Business (4,748)
  • Entertainment (1,862)
  • General News (326)
  • Health (327)
  • Investigative Journalism (11)
  • Lifestyle (4)
  • Sports (8,114)
  • Technology (6,066)
  • World News (1,336)
  • Contact Us
  • Terms and Conditions
  • Privacy Policy
  • RSS
  • Contact News Room
  • Code of Conduct
  • Careers
  • Values
  • Advertise
  • DMCA

© 2025 - noti.group - All rights reserved - noti.group runs on 100% green energy.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • World News
  • Business
  • Health
  • Sports
  • Entertainment

© 2025 - noti.group - All rights reserved - noti.group runs on 100% green energy.