• emb@lemmy.world
    link
    fedilink
    arrow-up
    9
    ·
    edit-2
    25 minutes ago

    Worth noting this is not a new vulnerability, it’s an analysis of a vulnerability disclosed in December:

    Following the security disclosure published in the v8.8.9 announcement
    https://notepad-plus-plus.org/news/v889-released/
    the investigation has continued in collaboration with external experts and with the full involvement of my (now former) shared hosting provider.

    According to the analysis provided by the security experts, the attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org. The exact technical mechanism remains under investigation, though the compromise occured at the hosting provider level rather than through vulnerabilities in Notepad++ code itself.