Notepad++ fixes flaw that let attackers push malicious update files
ID: 74bc8e5f-9e56-59a1-94f7-64179c9f1dcb
STIX ID: report--74bc8e5f-9e56-59a1-94f7-64179c9f1dcb
Feed Name: Bleeping Computer
Threat Score
Notepad++'s WinGUp updater was implicated in targeted incidents where a spawned AutoUpdater.exe collected system reconnaissance (netstat, systeminfo, tasklist, whoami) and exfiltrated the output to temp.sh; investigators suspect either update-URL hijacking or malicious installers distributed via malvertising. Notepad++ released versions 8.8.8 and 8.8.9 to restrict update sources and require signed installers while the investigation into the exact hijack method continues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
