Notepad++ users face security risks as Chinese hackers exploit software updates

Notepad++ users face security risks as Chinese hackers exploit software updates

In a six-month cyberattack, hackers linked to China compromised Notepad++, impacting tens of millions of users and targeting key sectors. Explore the implications for cybersecurity.

NeboAI I summarize the news with data, figures and context
IN 30 SECONDS

IN 1 SENTENCE

SENTIMENT
Neutral

𒀭
NeboAI is working, please wait...
Preparing detailed analysis
Quick summary completed
Extracting data, figures and quotes...
Identifying key players and context
DETAILED ANALYSIS
SHARE

NeboAI produces automated editions of journalistic texts in the form of summaries and analyses. Its experimental results are based on artificial intelligence. As an AI edition, texts may occasionally contain errors, omissions, incorrect data relationships and other unforeseen inaccuracies. We recommend verifying the content.

A cyberattack involving the popular open source text editor Notepad++ has been confirmed, resulting in malicious updates being distributed to users over several months in 2025. The attack, attributed to the Chinese government-affiliated group known as Lotus Blossom, targeted various sectors, including government and critical infrastructure, as noted by the security firm Rapid7.

This breach occurred between June and December 2025, with the infiltration enabled through a compromised shared hosting server used by Notepad++. Developer Don Ho explained that hackers exploited a vulnerability in the software to redirect users to their malicious server, delivering harmful updates until the issue was resolved in November.

Security researcher Kevin Beaumont highlighted that a limited number of organizations with interests in East Asia were compromised after users inadvertently installed the infected software. While the precise method of the initial breach remains under investigation, records indicate that attempts to exploit fixed vulnerabilities were made but ultimately failed.

Want to read the full article? Access the original article with all the details.
Read Original Article
TL;DR

This article is an original summary for informational purposes. Image credits and full coverage at the original source. · View Content Policy

Editorial
Editorial Staff

Our editorial team works around the clock to bring you the latest tech news, trends, and insights from the industry. We cover everything from artificial intelligence breakthroughs to startup funding rounds, gadget launches, and cybersecurity threats. Our mission is to keep you informed with accurate, timely, and relevant technology coverage.

Press Enter to search or ESC to close