logo

Notepad++ Vulnerability Let Attackers Hijack Network Traffic to Install Malware via Updates

ID: 4615660a-657c-5bca-9afa-b681249cbcff

STIX ID: report--4615660a-657c-5bca-9afa-b681249cbcff

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-11

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Security researchers observed suspicious WinGUp update traffic for Notepad++, where update requests in some cases were redirected to malicious servers and compromised installers were delivered; an integrity/validation flaw in the updater could allow attackers to substitute legitimate installers with rogue binaries. Notepad++ has hardened update verification and begun digitally signing binaries (GlobalSign) in recent releases (8.8.7+), and users are advised to upgrade to 8.8.9 and obtain installers only from the official site.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.