Infrastructure delivering updates for Notepad++—a widely used text editor for Windows—was compromised for six months by ...
A command injection flaw in the Windows Notepad App now gives remote attackers a path to execute code over a network, turning ...
The program is a free text and code editor that's been downloaded millions of times. The compromise began in June and is likely to have involved a Chinese state-sponsored group.
TL;DR: Notepad++ was compromised for six months, but it wasn't the software itself which the exploit leveraged, but its hosting provider. An investigation into the attack has just been concluded with ...