A Notepad++ plugin attack has targeted organisations in Ukraine with a malicious utility disguised as a legitimate plugin. The campaign bundles a real copy of the text editor with malware designed to establish persistence on Windows devices. Ukraine’s national cyber defence team, CERT-UA, linked the activity to UAC-0099, a threat cluster that has previously provided…
The developers behind the Notepad++ text editor have redesigned the program’s update mechanism to prevent future hijacking attempts. The change follows a previously disclosed incident in which attackers interfered with update delivery and attempted to distribute malicious files to selected users. The latest release introduces a multi-step verification model that checks update authenticity before installation…
A sophisticated cyber operation has put a widely used open-source tool in the spotlight. The Notepad++ state-sponsored hack involved attackers abusing the application’s update delivery process rather than exploiting a software flaw. This distinction is critical, as it shows how trusted infrastructure can become an attack vector even when the software itself remains secure. The…